Overview

The HiBob integration syncs your HR data into LowerPlane: employee directory, departments, onboarding/offboarding status, employment history, and org structure. LowerPlane uses read-only API access to collect compliance evidence automatically.

Prerequisites

You need HiBob Admin permissions to generate an API token with the required scopes.

How to Get Your API Token

1

Log in to HiBob

Log in to your HiBob account as an administrator.
2

Navigate to API Settings

Go to Settings > Integrations > API Access (or Settings > API Token).
3

Create a Service User

Create a new service user for LowerPlane with read-only permissions. Grant access to:
  • People — Read employee profiles
  • Employment — Read employment details
  • Lifecycle — Read onboarding/offboarding events
  • Reports — Read HR reports
4

Generate API Token

Generate an API token for the service user. Copy and store it securely.

Connecting in LowerPlane

1

Navigate to Integrations

Go to Integrations from the main navigation and search for HiBob.
2

Enter Credentials

Provide the following:
  • Service User ID — The service user email or ID
  • API Token — The token generated in the previous step
3

Connect

Click Connect to establish the integration. LowerPlane will validate your credentials and begin the initial sync.

What LowerPlane Monitors

Employee Directory

Full employee list with names, emails, departments, job titles, and status.

Onboarding

New hire onboarding status, start dates, and checklist completion.

Offboarding

Employee terminations, last working day, and offboarding task status.

Departments & Teams

Organizational structure, reporting lines, and team composition.
HiBob data syncs automatically on the configured schedule. Employee status changes (new hires, terminations) trigger compliance checks for onboarding/offboarding controls.

Frameworks Supported

FrameworkWhat It Proves
SOC 2HR processes, onboarding/offboarding controls are enforced
ISO 27001Personnel security (A.6) controls are in place
HIPAAWorkforce security and authorization controls are maintained