Skip to content
  • There are no suggestions because the search field is empty.

Managing Your People Data with an HRIS Integration 🔄

Your Haystack workspace can be integrated with a range of Human Resource Information Systems (HRIS) to automate account provisioning, profile data synchronization, and group membership management.

Table of Contents:

📌 Note: HRIS integrations are an add-on service that are licensed separately than the core intranet platform. If you're eager to use an HRIS integration, please reach out to your Customer Success Manager (CSM) or support@haystackteam.com for more details. 

⚠️ Important Rules & Constraints:

  • Exclusive Integration Types: HRIS integrations cannot be used alongside a SCIM integration (e.g., Okta or Microsoft Entra ID). You must choose either SCIM or HRIS for automated people management.
  • Single Data Source: Haystack currently supports connecting to one primary people data manager at a time. You cannot manage a portion of your users via Okta and another portion via an HRIS. If you have non-HRIS personnel (e.g., contractors or seasonal workers), they can still be invited or managed manually via CSV import.
  • No SSO Support: HRIS/Merge integrations do not support Single Sign-On (SSO). SSO authentication must be handled separately (such as via Google, SAML, or Okta).

HRIS Integrations Overview

Haystack utilizes Merge.dev as a secure, specialized integration middleware that connects your HRIS directly to our platform. Think of Merge like a universal travel adapter—it connects Haystack to dozens of distinct HRIS platforms without requiring unique, purpose-built software for each one. Merge standardizes and normalizes the incoming HR data so Haystack can interpret it cleanly.

  • Silent Integration: Customers do not need a separate Merge account, nor do they ever need to log in to Merge or contact Merge support. All configuration is managed directly inside the Haystack Admin Console.
  • One-Way Data Flow: HRIS integrations are strictly one-way (HRIS $\rightarrow$ Haystack). Haystack never writes data back to your HRIS.
  • Data Security & Privacy: Haystack proactively disables and blocks highly sensitive fields by default. Confidential data points like Social Security Numbers, salary/pay rates, gender, ethnicity, or marital status are neither ingested nor stored.

Core Integration Capabilities

Capability Business Impact & Operational Detail
Automated Provisioning Onboards new accounts and deprovisions terminated employees automatically based on employment status.
Profile Data Synchronization Mirrors names, job titles, departments, work email addresses, and manager reporting structures from your HRIS.
Group Membership Management

Populates Haystack group memberships using groups/entities passed by your HRIS.

Note: Group structure is strictly governed by how your specific HRIS formats data (e.g., cost centers, departments, locations). It is less flexible than SCIM/Okta grouping.

Understanding Sync Frequency

It is important to understand how data travels from your source of truth to Haystack. This happens in two distinct stages:

  • From your HRIS to Merge: This sync occurs at least once daily, though for many modern HRIS tools, it happens much more frequently. If your organization uses an SFTP-based integration, you have the flexibility to define this frequency yourself within your HRIS settings during your integration setup.

  • From Merge to Haystack: Once the data reaches Merge, Haystack pulls those updates 4 times per day to ensure your directory and groups remain current.

Sync Stage Typical Frequency
HRIS → Merge Daily (or more frequent via API); Custom via SFTP
Merge → Haystack 4 times per day

Prerequisites for HRIS Integration

Before beginning the integration setup, please ensure you have the necessary administrative access and information ready. Having these items prepared will ensure a smooth authentication flow through the Merge.dev interface.

  • Administrative Credentials: You must have Admin level permissions for your specific HRIS (e.g., Workday, BambooHR, or UKG).

  • Data Review: Confirm that your employee records in your HRIS are up to date, specifically regarding Name, Email Address, Department, Location, and Reporting Manager fields, as these will define your Haystack group structures.


Step 1: Prepare Your HRIS for Connection

Because every HRIS (Human Resources Information System) has its own security protocols and API structures, you must first configure your specific provider to allow Merge.dev to securely access your data. This typically involves generating an API key, creating a service account, or granting specific "Read" permissions to your employee directory.

Note on Potential Provider Fees: Before proceeding with the integration, please be aware that certain HRIS platforms may require a specific subscription tier or charge a one-time "API Access" or "Marketplace" fee to enable third-party connections. We recommend consulting with your HRIS account representative to confirm if any additional costs apply to your current plan before initiating the setup.

Please locate your provider in the list below and follow the link to the specific technical requirements for that platform. 

Finding Supported Providers & Setup Guides
  • Supported Platforms: Before starting, check the Haystack Integrations Page or consult the Merge Help Center (filtering by the HRIS category). Merge regularly adds new connectors, including some available in beta upon request.
  • SFTP vs. API Guidance: For larger enterprise platforms (such as Workday, ADP, or UKG) that feature complex API protocols, always choose the SFTP integration option if available. SFTP setups are significantly easier to establish and maintain than complex API configurations.

Turnaround Times & Potential Provider Fees
  • Setup Timelines: Setup duration varies by tool. Simple integrations take minutes, but complex providers like ADP can take 3 to 4 weeks because API/integration access requests must be manually approved and provisioned by the provider's team.
  • Provider Fees: Certain HRIS vendors (notably ADP, Workday, and UKG) may require specific subscription tiers or charge one-time "API Access" or "Marketplace" connection fees. Consult your HRIS account representative prior to starting.

If you do not see your provider in the list below, please reach out to your Haystack contact. As mentioned, Merge.dev adds additional supported platforms regularly—not all supported platforms are listed below. 

Core Data Scopes Required

Ensure the following Read-Only scopes are enabled during setup:

  • Employees: Read access to names, employee IDs, work emails, and employment status.
  • Groups/Teams: Read access to departments, teams, or cost centers.
  • Employment: Read access to job titles and manager/reporting lines.

You do not need to enable access to any highly confidential data like social security number or salary. Haystack does not need and will not ingest this data. HRIS integrations are one-way, HRIS->Haystack. This integration does not require or use write access.


Step 2: Authenticate and Finalize the Integration Link

Once API keys or service account credentials have been generated in your HRIS, complete the secure "handshake" inside Haystack.

How to Link 
  1. Enable Feature: Your Haystack CSM will toggle on the Merge.dev feature flag in your workspace settings.
  2. Access Admin Console: Log in to Haystack and go to Admin Console > User Provision and Login.
  3. Initiate Link: Scroll down to the Merge.dev Settings section at the bottom of the page and click New Link.
Complete Handshake Modal: Select your HRIS provider from the interactive setup modal, paste the API keys or connection credentials generated in Step 1, and authorize.
 

đź”’ Connection vs. Provisioning: Completing this handshake establishes the technical link, but no user accounts are imported or modified yet. Your existing directory remains unchanged until you complete Step 3.



Step 3: Provisioning Your Users

Provisioning imports user data from your HRIS and creates their active Haystack accounts.

⚠️  Pre-Launch Checklist (Global Notifications)

Haystack sends automated welcome notifications to newly provisioned users by default. If you are setting up pre-launch and do not want early notifications sent:

  1. Navigate to Admin Console > Security Settings.
  2. Toggle Notifications to OFF globally.
  3. Re-enable notifications once you are officially ready for company launch.

How to Provision Your Users

Follow these steps to select which employees should be added to Haystack:

  1. Navigate to Provisioning: Log into your Haystack workspace and visit the Admin Console > User Provision & Login page. 

  2. Access the Group List: Scroll to the bottom of the page. Locate the HRIS logo and click the caret (arrow) button next to it to fly open your list of synced groups. This may take some time to load if you have a large number of groups. 

  3. Select Your Groups: Next to the employee group(s) you would like to provision, click the three-dot button and select Provision.

    Note on Group Structure: Because group structures are determined by your specific HRIS tool's API, the names and types of groups you see may vary. If the group list does not look as expected or you are unsure which to select, please reach out to your Customer Success Manager (CSM) for guided assistance.

    • To provision all staff: Look for a group titled "All Company" or "All Employees."

    • Alternative: If a single "All Company" group isn't available, provision all groups of a specific type (e.g., select all Department groups or all Location groups).

  4. Confirm and Sync: Once you've selected Provision on your groups, Haystack will begin importing the users within those specific groups. You'll see them appear on your Admin Console > Manage People page shortly. 

Ongoing Automation

Once provisioning steps are completed, your integration is fully "live." From this point forward, all provisioning (adding new hires), deprovisioning (removing terminated employees), and profile mapping (updating titles, managers, and departments) will occur automatically. These updates will follow the sync frequencies detailed at the top of this article in the Overview section, ensuring your Haystack environment remains a real-time reflection of your HR records with no further manual intervention required.


Step 4: Linking HRIS Groups to Haystack Groups

You can map specific HRIS groups directly to Haystack groups (such as department channels or office location groups) to automate ongoing group memberships.

This step is independent of user provisioning and can be completed at any time after initial provisioning (Step 3)—whether you are still in your pre-launch phase or already live.

Key Linking Rules
  • 1:1 Mapping Limit: Group syncing supports a strict 1:1 relationship. You cannot map multiple HRIS groups to a single Haystack group.
  • Exact Matching: Mapping relies on exact string matching. Copy the exact group name directly from the list under your HRIS caret menu in the Admin Console.
How to Link a Group
  1. Go to Admin Console > Manage Groups.
  2. Find the target Haystack group, click the three-dot menu (...), and select Link with HRIS Group.
  3. Search for and select the exact corresponding HRIS group name.
  4. Configure Cleanup Setting (Remove members not in HRIS group):
    • Toggle ON: Automatically removes any user from the Haystack group if they leave or transfer out of that group in your HRIS.
    • Toggle OFF: Adds new members from your HRIS while preserving any members who were added to the Haystack group manually.
  5. Click Save. Initial group population occurs within 10 to 15 minutes. 

Once linked, this connection is live and persistent. Haystack will monitor your HRIS groups for any changes; as employees are added to or move between departments or offices in your source system, they will be automatically added to or removed from their corresponding Haystack groups. This ensures your internal communication channels and resource groups always reach the correct, up-to-date audience without any manual maintenance.


HRIS Integration FAQs

1. How frequently does my people data sync to Haystack?
Data travels in two stages. First, your HRIS syncs with Merge (our integration partner) at least once daily, though often much more frequently depending on your provider. Second, Haystack pulls data from Merge 4 times per day. This ensures that updates made in your HRIS are reflected in Haystack within a few hours.

2. If I need to make changes to employee data, where should I make that change?
Always make changes in your HRIS. Since the HRIS is your "Source of Truth," any edits made directly in Haystack will be overwritten the next time the system syncs. Updating your HRIS ensures the data remains accurate across all your connected company tools.

3. What do I do if not all of my employees have work emails?
Haystack requires a unique email address to provision an account. If certain employees (such as frontline or seasonal staff) do not have company emails, you may use a unique personal email or a formatted placeholder email in your HRIS, provided it is unique to that individual. If only a percentage of your workforce has work emails, reach out to your Haystack Customer Success Manager (CSM) for support and custom config for your use case. 

4. Can I sync multiple HRIS groups to a single Haystack group?
Currently, the "Link with HRIS Group" feature supports a 1:1 relationship. To include members from multiple HRIS groups into one Haystack group, you can either create a parent group in your HRIS or manually add additional members in Haystack.

5. What happens to a user in Haystack when they are terminated in our HRIS?
Once an employee is marked as terminated or inactive in your HRIS, they will be automatically deprovisioned from Haystack during the next scheduled sync. This ensures they lose access to company information immediately upon departure.

6. Can I exclude certain departments or individuals from syncing?
Yes. During the Provisioning step (Step 3), you choose exactly which groups to sync. If a group is not selected, the users within it will not be added to Haystack. Additionally, you can use the "Manage Groups" settings to further refine who is included in specific platform areas.

7. One of my fields is not syncing the data I'd expect (like business title instead of job title, or first name instead of preferred name)—how can I update this?
Because every HRIS labels data differently, Haystack & Merge.dev uses "Common Models" to try and match your data automatically. If you find that the wrong field is being pulled (e.g., you want "Preferred Name" to show up instead of "Legal First Name"), please reach out to your Customer Success Manager (CSM). We can work with you to create custom mappings that ensure the exact data points you want are being surfaced in your employee profiles.

Support & Assistance

Have questions or need help setting up your integration? We're here to help!

  • Email: support@haystackteam.com
  • Support Hours: Monday – Friday, 9:00 AM – 5:00 PM MST. Someone from our support team will respond to your query during these standard business hours.

Keywords: HRIS, Merge.dev, Provisioning, Deprovisioning, User Sync, Profile Data, Group Mapping, Workday, ADP, UKG, BambooHR, Paychex, Paylocity, SFTP, API Setup, Single Sign-On, SCIM, Automated Onboarding, Directory Sync, Employee Directory