TriNet HR Platform
Use TriNet HR Platform workforce records in Pomerium Enterprise policy to check employment status and worker type before access.
Overview
TriNet HR Platform is the current name for the product formerly called TriNet Zenefits. A Pomerium datasource example can import selected workforce records for Enterprise policy.
Selected TriNet HR Platform data can add organization, inventory, or security context to an access decision. A small, reviewed record set is easier to understand and protect than a broad export of the source system.
Pomerium can evaluate selected TriNet HR Platform records after a customer-owned adapter maps them to supported request or user keys. Pomerium does not call the vendor API directly and does not manage the source system.
How it works
The current example uses a Zenefits API credential, timezone, datasource command, employee endpoint, pomerium.io/Zenefits records, user.email matching, and a polling interval from one to four hours.
Map only the fields that policy needs. Each imported record must use a Pomerium-supported foreign key: user.id, user.email, request.ip, or request.client_certificate.fingerprint.
Publish the records through a protected JSON, CSV, tar, or ZIP source. Configure Pomerium Enterprise to poll that source. Evaluate the imported fields with a Pomerium Policy Language record matcher.
Example
A company imports selected employment status and worker type fields by user email. A sensitive route checks the external record as one part of its access policy.
Considerations
- Pomerium identifies this connector as an unmaintained example.
- The current example still uses the legacy Zenefits API address and API-key flow. Current TriNet developer documentation uses a different API and OAuth 2.0.
- Validate and update the connector before production use. The data is polled and is not real time.
- This is a customer-owned connector pattern, not a built-in Pomerium connector.
- External data sources need Pomerium Enterprise and update on a polling schedule.
- A workforce record does not prove that the current requester is the person named by that record. Match it through a supported user key.
Sources and official resources
- TriNet HR PlatformOfficial website
- TriNet developer documentationOfficial documentation
- Legacy Zenefits API guidePrimary source
- Legacy Zenefits authenticationPrimary source
- Pomerium Zenefits data examplePomerium documentation
- Pomerium datasource repositoryOfficial repository
- Pomerium external data sourcesPomerium documentation
- Pomerium external record matcherPomerium documentation
