If a user is missing, has an incorrect name, or shows an unexpected employment status in Drata, the cause is usually within your identity provider (IdP), your HRIS, or a manual change made in Drata. Use the checks below to identify and resolve the issue.
Before You Start
Allow up to 24 hours for scheduled updates to sync from connected systems.
Compare the user’s work email, name, account status, group membership, employment status, start date, and separation date across the IdP, HRIS, and Drata.
In Personnel, check the Sync status for manual updates or a disabled sync.
Correct the source system first, then run an ad-hoc identity and account resync.
Common Issues and Fixes
The user is missing or not updating
Confirm that the user is active in the IdP and belongs to an in-scope group.
Confirm that the user’s email domain is included in the connection configuration.
Verify that the user’s work email matches in the IdP and HRIS.
Confirm the HRIS record includes the user’s name, email, employment status, and relevant dates.
Check whether the record was manually changed in Drata. Manual changes pause automated syncing for that user.
ⓘ The steps to re-enable syncing depend on your interface version. Customers who joined Drata on or after February 24, 2026 are on the New Experience. |
Re-enable syncing — New Experience
One person: open Personnel, select the user, choose the ellipsis menu, select Re-enable IdP/HRIS sync, and confirm.
Multiple people: select them, then choose More > Re-enable IdP/HRIS sync.
Re-enable syncing — Classic Experience
One person: open the user’s Personnel detail drawer and select the re-enable icon next to Updated via Drata, then confirm.
Multiple people: select them, then choose Actions > Re-enable IdP/HRIS Sync.
The user’s name is incorrect or does not match
When an HRIS is connected, it is the source of truth for the user’s name and employment details. Compare the first name, last name, preferred name, spelling, and work email in both systems. Correct the source record instead of repeatedly editing the name in Drata, then resync.
If multiple HRIS connections are configured, review their priority. The connection order determines which HRIS supplies the user’s name, email, start date, and employment status.
The user appears as Unknown, Former, or Future Hire
Unknown: Drata cannot confidently match the HRIS record to an IdP-created personnel record. Align the work email and remove duplicate or conflicting records.
Former: Check the HRIS separation date and status, IdP group scope, manual updates in Drata, and whether the latest change has synced.
Future Hire: Confirm the start date in the HRIS. If the person has started, update the HRIS first and resync.
The HRIS is the source of truth for employment status, start dates, and separation dates. If no HRIS is connected, Drata uses IdP activation and deactivation data to infer Current or Former status.
ⓘ For detailed causes and step-by-step fixes for each status, see Troubleshoot employment status issues in Drata. |
Safe Offboarding Practices
Update the HRIS with the official separation date and employment status.
Disable the user in the IdP and remove them from in-scope groups. If immediate access removal is required, disable the IdP account first and update the HRIS immediately afterward.
Do not delete the personnel record in Drata. Keeping it preserves historical compliance and offboarding evidence.
Wait for the next sync or run an ad-hoc resync, then verify the user’s status, separation date, Sync status, and offboarding evidence.
Do not reuse the former employee’s work email until the records are separated. Use a unique placeholder address for the former employee before assigning the original address to a new hire.
Deleting version control or infrastructure accounts does not remove their historical record from Drata; Drata records an Access Revoked timestamp for auditability.
Contact Drata Support
If the issue persists, contact Drata Support and provide the affected user’s work email, IdP and HRIS providers, status and email in each source, Drata employment status and Sync status, configured group and domain scope, the time of the source change, and the result of any resync attempts.
