Skip to main content
See All Integrations

Rippling

Use selected Rippling workforce data in Pomerium policy through a custom external data source.

Custom customer-owned connector

Categories
Context Data Sources, HR

Overview

Rippling is a workforce management platform. Its REST API can expose selected worker and employment records when the application has the required scopes. A customer-owned adapter can map reviewed fields to Pomerium Enterprise external data.

Selected Rippling data can add organization, inventory, or security context to an access decision. A small, reviewed record set is easier to understand and protect than a broad export of the source system.

Pomerium can evaluate selected Rippling records after a customer-owned adapter maps them to supported request or user keys. Pomerium does not call the vendor API directly and does not manage the source system.

How it works

Create a Rippling API application with the minimum worker read scopes. Read selected worker records through the REST API and handle cursor pagination and field redaction.

Map only the fields that policy needs. Each imported record must use a Pomerium-supported foreign key: user.id, user.email, request.ip, or request.client_certificate.fingerprint.

Publish the records through a protected JSON, CSV, tar, or ZIP source. Configure Pomerium Enterprise to poll that source. Evaluate the imported fields with a Pomerium Policy Language record matcher.

Example

An adapter maps an active worker record to a verified work email. A Pomerium policy requires the imported employment state for a selected route. Employment changes reach Pomerium on the polling schedule, not at the time of the change.

Considerations

  • Worker data needs workers.read and can need more scopes for selected fields.
  • Application permissions can redact fields. Map a stable work email or user ID and handle missing data explicitly.
  • This is a customer-owned connector pattern, not a built-in Pomerium connector.
  • External data sources need Pomerium Enterprise and update on a polling schedule.
  • A workforce record does not prove that the current requester is the person named by that record. Match it through a supported user key.

Sources and official resources

  • Use selected Workday HCM workforce records in Pomerium policy through a customer-owned external data source.

  • Use selected ServiceNow CMDB records in Pomerium policy through a custom external data source.

  • Use JumpCloud as the identity provider for Pomerium through OpenID Connect.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo