Skip to main content

Every exercise is indexed by name, CWE, OWASP, MITRE ATT&CK, CIS, NIST CSF, GDPR and EU AI Act reference.

Try

Rippling App Shop

Connect Rippling to RansomLeak

Let Rippling decide who gets security training. Everyone you give RansomLeak access to in Rippling gets an account, role and department changes reassign the right curriculum, leavers lose access, and your people sign in with Rippling single sign-on.

Last updated September 2026

Overview

RansomLeak installs from the Rippling App Shop and keeps your training roster in step with Rippling. The connection is a read-only pull of directory fields. RansomLeak never writes back to Rippling and never reads compensation, tax, bank, or personal identification data.

These are the moments it acts on, as they happen in Rippling:

  • People given access get an account and onboarding
  • Role and department changes reassign curricula
  • Leavers lose access
  • Sign-in with Rippling SSO

Rippling's access rules decide who is synced. Only employees with access to RansomLeak in Rippling get an account, so the people you choose there are the people who receive training.

Requirements

  • A Rippling plan with App Management
  • A RansomLeak workspace and an admin account
  • Licenses for everyone you give access

The RansomLeak admin needs permission to manage integrations. People beyond your license count are not provisioned until licenses are available. For help during setup, email support@ransomleak.com.

Install RansomLeak

You can start in either product. From RansomLeak, go to Admin → Integrations → HRIS and select Connect Rippling, which opens the same Rippling install flow.

  1. In Rippling, open the App Shop, search for RansomLeak, and select Install.

  2. Choose who gets RansomLeak with Rippling's access rules, a group or individual people.

  3. Approve the requested permissions. They are read-only directory scopes and nothing more.

  4. Rippling sends you to RansomLeak. Enter your workspace, the first part of your RansomLeak address (acme for acme.ransomleak.com), and sign in if prompted.

  5. RansomLeak connects and returns you to Rippling to finish. The first sync starts right away.

The link Rippling hands to RansomLeak in step 4 is valid for 30 minutes. If it expires, restart the installation from Rippling.

Single sign-on

During installation, or later from the app's Setups tab in Rippling, you can turn on SAML single sign-on. Enter your RansomLeak workspace when Rippling asks for it.

  • Configuration picked up automatically, nothing to copy
  • "Sign in with Rippling" on the login page
  • Password sign-in stays available

RansomLeak reads the SSO configuration from Rippling within an hour, or immediately when an admin selects Sync now on the HRIS tab. Employees can then open RansomLeak from their Rippling home screen or use Sign in with Rippling. An admin can require SSO or turn it off in Settings → SAML; if you turn it off, it stays off.

Custom domain? If your people use RansomLeak on your own domain, such as training.acme.com, use the ACS URL and Entity ID shown in RansomLeak under Settings → SAML in Rippling's SSO setup instead of the workspace field. An identity provider you already configured, such as Okta or Entra ID, is never replaced.

Configuration

Once connected, choose what training the lifecycle assigns. Both settings live on the HRIS tab.

  1. Onboarding learning path. The day-one curriculum every new hire is enrolled in. Leave it unset to turn onboarding auto-enrollment off.

  2. Role and department map. Rules such as department is Engineering → Secure Coding path. The first matching rule wins, and an optional default covers anyone the rules do not match.

How it works

RansomLeak keeps the directory current on several schedules and matches people by work email, so Rippling and RansomLeak always point at the same person.

Sync When it runs
Change notificationsAbout 5 minutes after a hire, update, access change, or termination.
Hourly syncEvery hour, catching anything a notification missed and SSO changes.
Nightly full syncOnce a day, a full reconcile including people no longer returned.
Sync nowOn demand from Admin → Integrations → HRIS.
In Rippling In RansomLeak
Someone is given access An account is created, licensed, placed on their department team, and enrolled in the onboarding curriculum.
Job title or department changes The user is enrolled in the curriculum mapped to their new role or department.
Access removed, or employee terminated Their account is disabled. Their training history is preserved.
Rehired, or access given back Their account is reactivated.
Manager changes Mirrored to RansomLeak so manager dashboards and reminders work.

The initial sync is a baseline, not a flood. People who already had RansomLeak accounts are matched by work email and linked, with no duplicates. The first sync records your existing workforce as already onboarded, so only genuinely new hires receive onboarding training.

Using HRIS alongside SCIM

If you also provision from your identity provider over SCIM, the two sources are reconciled by work email so they do not work against each other.

  • Rippling owns directory and org fields
  • SCIM owns identity and access

Rippling is authoritative for names, job title, department, and manager. Your identity provider stays authoritative for login identity and role membership, and HRIS never overwrites those.

Permissions and data handling

The app requests read-only access to Rippling's directory and uses it to read the fields that drive training. Each field maps to one job.

What RansomLeak reads Why
Name and work emailCreate the account and match the person.
Job title and departmentAssign role-based curricula and the department team.
ManagerBuild the reporting line for manager dashboards.
Employment status, start and end datesDetect joins, departures, and rehires.
SAML configurationTurn on sign-in with Rippling without copying settings.
  • Directory fields only, never pay, tax, bank, or IDs
  • Encrypted in transit and at rest
  • Never writes to Rippling

For how RansomLeak handles data, see the privacy policy and the security and compliance page.

Troubleshooting

Symptom Fix
Someone did not get an account Check that they have access to RansomLeak in Rippling, have a work email in Rippling, and that your workspace has free licenses. The HRIS tab shows the last sync status and any error.
A departure is not reflected Terminations and access removals arrive within minutes and are fully reconciled by the nightly sync. For an immediate lockout, disable the user in RansomLeak as well.
"Sign in with Rippling" does not appear Finish SSO setup in Rippling, then select Sync now on the HRIS tab. If another identity provider is already configured, Rippling SSO is not applied.
No onboarding enrollment Set an onboarding learning path on the HRIS tab. With it unset, new hires are provisioned but not enrolled.

Disconnecting. Uninstall RansomLeak in Rippling, from the app's Settings, or select Disconnect on the HRIS tab in RansomLeak. Syncing stops, SSO applied from Rippling is removed, and password sign-in is restored. Users and their training history are kept.

Next guide Provision users with SCIM If your identity provider is the source of truth, provision RansomLeak accounts from Okta or Entra over SCIM instead.

Need a hand?

Email support@ransomleak.com and we will help you connect Rippling to your tenant.

See RansomLeak in Action

Try the free exercises or book a demo to see analytics, SCORM export, SSO, and custom content in your environment.