
How the Integration Works
Risotto connects to BambooHR through BambooHR’s OAuth 2.0 authorization flow. Each Risotto org installs against a single BambooHR tenant identified by your company subdomain (theacme in acme.bamboohr.com). After install, Risotto stores access and refresh tokens scoped to that tenant and uses them to call the BambooHR REST API on your behalf.
When an employee asks Risotto something that needs HRIS data (i.e. “What’s my PTO balance?”), Risotto resolves their BambooHR employee record by matching their work email, then calls only the BambooHR endpoints required to answer that request.
Install from BambooHR
You must be a BambooHR admin to approve the install.1
Start the install from Risotto
In the dashboard, go to Settings > People > Connect and click Connect next to BambooHR. Enter your BambooHR company subdomain (
acme portion of acme.bamboohr.com) and click Continue.2
Approve the install in BambooHR
You’ll be redirected to your BambooHR tenant (
acme.bamboohr.com) to
sign in and approve the requested OAuth scopes for the Risotto app. BambooHR
redirects you back to the Risotto dashboard once the install is complete.3
Confirm the connection
The BambooHR row in People Connect updates to show the integration is connected.
The subdomain accepts lowercase letters, numbers, and hyphens only. If you’re
unsure of your subdomain, check the URL you use to sign in to BambooHR.
Requested OAuth Scopes
During install, Risotto requests the following BambooHR OAuth scopes:Data Fields That Sync
Risotto reads only the fields it needs to fulfill an active request. Nothing is written back to BambooHR unless the matching People Action is enabled.Employee profile (read)
Pulled fromGET /api/v1/employees/{id}:
Home address (read and write)
Pulled fromGET /api/v1/employees/{id} when address access is needed, and written back via POST /api/v1/employees/{id} when Update Home Address is enabled:
Time off (read and write)
Discretionary and manual BambooHR policies don’t track a running balance, so
Risotto surfaces those as “no tracked balance” rather than a literal
0.Supported Actions
BambooHR supports the following People Actions:Get Employee Info
Look up the requesting employee’s profile, title, department, work location,
manager, and start date.
Get Home Address
View the home address on file for the requesting employee.
Update Home Address
Update the home address on file for the requesting employee.
Get PTO Balance
Retrieve balances for each policy type the employee is assigned to.
Request PTO
Submit a time off request for the requesting employee. Requests are created
with status
requested and follow your BambooHR approval flow.Terminated Employees
Risotto checks theemploymentHistoryStatus field on every BambooHR lookup. When the field indicates the employee is no longer active, People Actions stop running for that employee and requests are escalated, even if their Slack account is still active.