Connecting BambooHR to Drata allows for automated checks and evidence collection to provide details on personnel hire and separation dates as well as their employment status.
Prerequisite
Ensure you have admin access to your company's BambooHR account. Drata offers two connection methods: OAuth tied directly to a user account or a BambooHR API Key.
Drata highly recommends creating a separate service account for the read-only administrator permissions needed in this connection.
For OAuth:
(Optional) If you prefer to connect through OAuth with a separate user account, you can create one with proper with read-only administrator permissions.
Have the username and password ready to log in to BambooHR when prompted.
For API Key:
To generate a BambooHR API Key, you need to access the BambooHR console with administrator permissions.
On the Home page, select Account and then API Keys.
Select Add New Key.
Enter a name for the API key in the API Key Name field and select Generate Key.
Copy the API key so that you can paste it into Drata.
Select Done.
Customize application permissions
BambooHR allows you to define specific admin permissions for a connection by creating a custom access level.
To create a custom access level, navigate to
{domain}.bamboohr.com/access_levels/custom/create
to set up this access level.Configure the access level with the following settings:
Navigate to the data table to begin selecting access level permissions for the following data:
Grant Access to Company Files containing the company policies and test you wish to sync to Drata. If view access is not given to the folders containing the policies, you will not be able to import or link them in Drata.
This access level will then need to be assigned to the account making the BambooHR connection in Drata. Drata highly recommends this to be a service account, not one of your main administrator accounts.
Connect BambooHR to Drata
Select Connections on the side navigation menu.
Select the Available connections tab, search for BambooHR, and select Connect.
The drawer provides step-by-step instructions for you to connect.
You may be able to switch between OAuth and API Key with the green button at the bottom of the connection modal.