BambooHR - User Guide

In this article, you will understand step by step how to easily integrate with BambooHR


Integrating with BambooHR enables Scytale to collect all employee information in one centralized location, ensuring that only authorized users have access and that terminated employees have their access removed from relevant systems, a key criterion when testing logical access. This automated process saves time and effort that would otherwise be spent manually collecting this evidence, especially when proving to auditors that HR listings are complete and accurate.

Automating the collection of HR listings through this integration streamlines the audit's sampling process and provides increased assurance of the accuracy and completeness of evidence collected. The elimination of human intervention further assures auditors that the evidence can be relied upon. By using this integration, you can meet regulatory and compliance standards more efficiently, while ensuring a more streamlined and reliable auditing process.

How to connect BambooHR integration?

Step 1: Generate an API key in BambooHR

  • Log in to BambooHR
  • Click on the settings icon in the upper right corner. 
  • Click on "Access Levels" and select the "Full Admin" tab. 
  • Ensure that your user has full admin access. 
  • Then, in the upper right corner, click your avatar name.
  • Select "API Keys".
  • Click on "Add New Key".
  • Add a name for this key.
  • Click on "Generate Key".
  • Click on "COPY KEY".

Non-Full Admin Access Levels:

There is also an option not to use full admin access:

  • Go to Settings and select "Access Levels".
  • Under custom levels, select IT.
  • Click on the dropdown settings on the right corner. 
  • Select "Add a Non-Employee BambooHR User".
  • Select Integration Level on the left menu. 
  • Select Access Level Settings.
  • You should set your Access Level to view "All Employees" defined as follows: "This Access Level can access the information below for All Employees".
  • Add view only permissions:
    • Pernonal tab:
      • Basic Info
      • Address
      • Contact
      • Education
    • Jobs tab: 
      • Hire Date
      • Original Hire Date
      • Employment Status
      •  Job Information


Step 2: Log in to the Scytale web app

  • Click on the "Integrations" menu screen on the left-hand side.
  • Click on the Connect button under the BambooHR icon.
  • Enter your subdomain for your BambooHR account as the following:
    • If you sign in with "", your subdomain is "Scytale".
  • Paste the API key you copied in step 1. 
  • Connection Name - is used to differentiate between your connections.
    For instance, if you manage multiple accounts or would like to connect multiple times to the integration. It's automatically titled (Connection 1,2,3 etc), but you can change it to a custom name to make it easier to identify.
  • Click "Connect".

Permissions for the integration with BambooHR:

Scytale uses read-only permissions to collect employee information relevant to the audit. Scytale will have access to employee details, but not perform any actions.

  • Basic Info
  • Address
  • Contact
  • Education
  • Hire Date
  • Original Hire Date
  • Employment Status
  •  Job Information