Skip to main content
See All Integrations

BambooHR

Import selected BambooHR workforce fields into Pomerium Enterprise policy with the example external data source and user email matching.

Customer-owned external data source example

Categories
Context, HR

Overview

BambooHR is a human resources platform. A customer-owned Pomerium datasource example can import selected workforce fields into Pomerium Enterprise policy.

Selected BambooHR data can add organization, inventory, or security context to an access decision. A small, reviewed record set is easier to understand and protect than a broad export of the source system.

Pomerium can evaluate selected BambooHR records after a customer-owned adapter maps them to supported request or user keys. Pomerium does not call the vendor API directly and does not manage the source system.

How it works

Run the Pomerium datasource example with the BambooHR subdomain, credential, and timezone. Map each selected worker record to user.email. Use a polling interval from 30 minutes to four hours.

Map only the fields that policy needs. Each imported record must use a Pomerium-supported foreign key: user.id, user.email, request.ip, or request.client_certificate.fingerprint.

Publish the records through a protected JSON, CSV, tar, or ZIP source. Configure Pomerium Enterprise to poll that source. Evaluate the imported fields with a Pomerium Policy Language record matcher.

Example

A company imports current BambooHR employment fields by user email. A Pomerium policy uses the selected record only for the routes that need an employment-state check.

Considerations

  • The example is customer-maintained and uses polling. It is not real-time directory sync.
  • The current example uses a legacy API-key flow. BambooHR now makes OAuth 2.0 the primary integration path.
  • This is a customer-owned connector pattern, not a built-in Pomerium connector.
  • External data sources need Pomerium Enterprise and update on a polling schedule.
  • A workforce record does not prove that the current requester is the person named by that record. Match it through a supported user key.

Sources and official resources

  • Use TriNet HR Platform workforce records in Pomerium Enterprise policy to check employment status and worker type before access.

  • Use selected Workday HCM workforce records in Pomerium policy through a customer-owned external data source.

  • Use selected Rippling workforce data in Pomerium policy through a custom external data source.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo