
Why connect Rippling
Deflect repetitive HR tickets
Keep your roster current
Stop serving former employees
No new surface for employees
Prerequisites
Have these in place before you start:- A Rippling admin account. Only Rippling admins can install App Shop apps.
- A Risotto admin account. Installing, syncing, and disconnecting all require permission to manage the org.
- Account provisioning configured for Risotto in Rippling. Rippling’s provisioning rules determine which employees are in scope for Risotto. These rules populate the
PROVISIONINGgroup that Risotto’s roster sync reads; without it, the sync has nothing to reconcile and reports a failure. - The Rippling company is not connected to another Risotto org. One Rippling company maps to exactly one Risotto org.
Install from the Rippling App Shop
Risotto connects to Rippling through the Rippling App Shop. The App Shop handles authentication and Risotto persists OAuth tokens automatically.Start the install
Approve the install in Rippling
Confirm the connection
Enable the actions you want
Requested Permissions
During install, Risotto requests access to the following Rippling data through the App Shop integration:Data Flows
The integration runs four distinct flows. Two keep your roster current in the background; two run only when an employee asks for something.Employee roster sync
Risotto reads thePROVISIONING group from Rippling and reconciles its own roster against it. Employees in the group are added or updated; Rippling-sourced identities no longer in the group are marked inactive with an audit entry.
This flow runs at three moments:
- Once on install, so a new connection is populated immediately.
- Once a day, in an overnight sweep (around 08:20 UTC).
- On demand, when an admin clicks Sync now.
Provisioning webhooks
Rippling notifies Risotto of employee lifecycle changes as they happen, so terminations don’t wait for the overnight sync:Employee data lookup
When an employee asks Risotto for their own HR data, Risotto calls Rippling live and reads only the fields that request needs. To find the employee, Risotto matches their email against Rippling’swork_email. The resolved Rippling worker ID is stored on the employee’s Risotto identity so later requests skip the lookup.
Time off request
The only flow that writes to Rippling. When an employee asks for time off, Risotto confirms the details with them first, then creates the request in Rippling with statuspending, where it enters your normal approval flow. Risotto never approves anything.
Trigger a sync manually
To force an immediate roster sync without waiting for the overnight run, go to Settings → People → Connect, open the menu on the Rippling row, and click Sync now. The Rippling row reports the result inline:Data Fields That Sync
Risotto resolves the requesting employee’s Rippling worker record by matching their work email, then reads only the fields required to answer that request.Employee profile (read)
Pulled from the Ripplingworkers endpoint:
work_email only. personal_email is used as a
fallback when the roster sync encounters a worker with no work email — so an
employee whose Slack email matches neither field won’t resolve.Home address (read only)
Read from the worker’sHOME-typed address record:
Time off (read and write)
Rippling stores leave amounts in minutes; Risotto surfaces them in hours.Supported Actions
Rippling supports the following People Actions:Get Employee Info
Get Home Address
Get PTO Balance
Request PTO
pending and follow your Rippling approval flow.Terminated employees and rehires
When Rippling marks an employee as terminated or deleted, Risotto receives a webhook and immediately stops People Actions from running for that employee. Requests from former employees are escalated, even if their Slack account is still active. The daily roster sync catches anyone a missed webhook left behind. Rehires are handled automatically. Rippling issues a new worker ID when someone returns, so Risotto re-resolves them on their next request or on the next roster sync and reactivates their record.Disconnecting
Rippling stays installed on your org until an admin removes it in Rippling. Disconnect on the Rippling row sends you to the Rippling App Shop to uninstall Risotto there. Uninstalling in Rippling triggers acompany.deleted webhook, and Risotto then deletes its stored access and refresh tokens and marks every Rippling-sourced employee record inactive.
FAQs
Can employees look up other people's information?
Can employees look up other people's information?
Can Risotto approve time off, or change anything else in Rippling?
Can Risotto approve time off, or change anything else in Rippling?
pending, which then follows your existing Rippling approval
flow. Risotto cannot approve requests, edit profiles, change addresses, or
modify payroll.Does the employee get asked before Risotto submits a PTO request?
Does the employee get asked before Risotto submits a PTO request?
Should we enable Get Home Address?
Should we enable Get Home Address?
How fresh is the data Risotto reports?
How fresh is the data Risotto reports?
How long after a termination does Risotto stop responding?
How long after a termination does Risotto stop responding?
Can we connect Rippling to more than one Risotto org?
Can we connect Rippling to more than one Risotto org?
What about contractors and international workers?
What about contractors and international workers?
Are half-days and part-time schedules supported?
Are half-days and part-time schedules supported?
Is there an audit trail?
Is there an audit trail?
Troubleshooting
Install fails: “Please disconnect Rippling from your other Risotto org”
Install fails: “Please disconnect Rippling from your other Risotto org”
Install fails: “The Rippling install session expired”
Install fails: “The Rippling install session expired”
Install fails: “Could not complete the Rippling install”
Install fails: “Could not complete the Rippling install”
Sync failed: no PROVISIONING supergroup found in Rippling
Sync failed: no PROVISIONING supergroup found in Rippling
Sync failed: Rippling connection needs to be reconnected
Sync failed: Rippling connection needs to be reconnected
Sync failed: Rippling API request failed, or timed out
Sync failed: Rippling API request failed, or timed out
An employee is told they aren't found in the HR system
An employee is told they aren't found in the HR system
- Their Slack email matches their Rippling
work_email. - Rippling’s provisioning rules include them, so they’re in the group Risotto reads.
- They aren’t marked terminated in Rippling.
- A roster sync has run since they were added — click Sync now.
Risotto isn't taking any HR actions at all
Risotto isn't taking any HR actions at all
An employee's PTO request was rejected by Rippling
An employee's PTO request was rejected by Rippling