Enterprise SSO & identity
Google, Microsoft and LDAP / Active Directory — verified employees sign in with the identity provider your organisation already runs, without auto-creating new accounts.
Keep employee workflows in HRlume while notifications, meetings and approved data access reach the systems around it.
Each integration solves a specific workflow instead of asking for broad access to unrelated data.
Google, Microsoft and LDAP / Active Directory — verified employees sign in with the identity provider your organisation already runs, without auto-creating new accounts.
Push meetings to the organiser's own calendar and invite the other participant through a separate, employee-authorised grant.
Deliver selected employee notifications through Slack (matched by email) or a linked personal Telegram chat.
Subscribe to HRlume calendar feeds from any compatible app, and connect your own careers hostname with guided DNS setup.
Read workforce data and safely create or update selected assets, recruiting, document, survey, goal and knowledge records — every key has its own purpose, lifetime and read/write scopes.
HRlume separates employee sessions, OAuth grants and API keys. Every API key has an editable purpose, lifetime, IP allowlist and independent read/write scopes. Sensitive write access is highlighted and never inherited by legacy keys.
Single sign-on does not create new employee records automatically: an administrator still controls who has an account and therefore who consumes a licensed seat.
Create personal or service keys, choose a fixed expiry or unlimited lifetime, and combine resource-specific read and write scopes. Administrators can edit access without exposing the raw token again.
