BambooHR governance & compliance security checks
Policy, ownership, financial and data-quality controls that regulators and auditors expect to see evidenced, not just declared.
On BambooHR, Black Cat runs 3 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the BambooHR connector needs.
Checks (3)
severity: low Active Employee Without Manager fix difficulty: easy #
Assign a manager to this employee for accurate org/blast-radius data
- Open the employee's profile in BambooHR
- Set the Manager field under Job > Reporting
Satisfies: NIS2 Directive NIS2-21.i.2 DORA (SaaS Security) DORA-9.6
severity: low Active Employee Without Department fix difficulty: easy #
Set the department on this employee record
- Open the employee's profile in BambooHR
- Set the Department field under Job
Satisfies: NIS2 Directive NIS2-21.i.2 DORA (SaaS Security) DORA-9.6
severity: low Active Employee Without Work Email fix difficulty: easy #
Add a work email so the identity correlates across SaaS connectors
- Open the employee's profile in BambooHR
- Set the Work Email field under Contact
Satisfies: NIS2 Directive NIS2-21.i.2 DORA (SaaS Security) DORA-9.6