Overview
The GreytHR integration syncs your employee roster into LowerPlane and automates HR compliance evidence: each employee’s role, reporting manager, and date of joining, plus your organizational structure. LowerPlane uses read-only API User credentials to collect this evidence automatically.LowerPlane collects only the organizational data needed for compliance — names, work email, role, reporting manager, joining date, and employment status. It does not collect payroll, salary, attendance, biometric, or government-ID (PAN/Aadhaar) data.
Prerequisites
How to Create an API User in GreytHR
Log in to the GreytHR admin console
Sign in to your GreytHR account at
https://<your-subdomain>.greythr.com using your admin credentials.Copy your account subdomain
Copy your GreytHR subdomain from the browser’s address bar — you’ll enter it as your Client Domain in LowerPlane. For example, if the URL is
https://example.greythr.com/, your subdomain is example.greythr.com.Create the API User
Click Create API User. Enter
LowerPlane as the username and add a short description (e.g. “LowerPlane compliance evidence”).Select the required roles
Under Select Roles, choose the following read-only roles, then click Next:
- Employee API Read Access
- Employee API
- User API
Connecting in LowerPlane
Enter your credentials
Provide the following:
- Client Username — the API User username you created
- Client Password — the API User password
- Client Domain — your GreytHR subdomain (e.g.,
example.greythr.com)
What LowerPlane Monitors
Employee Directory
Names, work email, role/designation, and employment status for every active employee.
Reporting Structure
Each employee’s reporting manager, resolved to the manager’s email for segregation-of-duties evidence.
Joining Dates
Date of joining for onboarding, probation, and access-provisioning timelines.
Organizational Structure
Roles and reporting lines that establish authorities and responsibilities.
Automated Checks
Once connected, LowerPlane runs these checks against every employee on each sync:| Check | Passes when |
|---|---|
| Staff role should be assigned | Every employee has a role/designation |
| Reporting manager should be assigned | Every employee has a reporting manager |
| Date of joining should be provided | Every employee has a recorded joining date |
Frameworks Supported
| Framework | What It Proves |
|---|---|
| SOC 2 | The organization maintains a defined structure with clear authorities, segregation of duties, and communicated responsibilities (CC1.3, CC1.4, CC2.2) |
| ISO 27001 | Information security roles, responsibilities, and segregation of duties are defined and enforced (A.6.1.1, A.6.1.2, A.7.1.1, A.7.1.2) |