Overview
RansomLeak installs from the Rippling App Shop and keeps your training roster in step with Rippling. The connection is a read-only pull of directory fields. RansomLeak never writes back to Rippling and never reads compensation, tax, bank, or personal identification data.
These are the moments it acts on, as they happen in Rippling:
- People given access get an account and onboarding
- Role and department changes reassign curricula
- Leavers lose access
- Sign-in with Rippling SSO
Rippling's access rules decide who is synced. Only employees with access to RansomLeak in Rippling get an account, so the people you choose there are the people who receive training.
Requirements
- A Rippling plan with App Management
- A RansomLeak workspace and an admin account
- Licenses for everyone you give access
The RansomLeak admin needs permission to manage integrations. People beyond your license count are not provisioned until licenses are available. For help during setup, email support@ransomleak.com.
Install RansomLeak
You can start in either product. From RansomLeak, go to Admin → Integrations → HRIS and select Connect Rippling, which opens the same Rippling install flow.
-
In Rippling, open the App Shop, search for RansomLeak, and select Install.
-
Choose who gets RansomLeak with Rippling's access rules, a group or individual people.
-
Approve the requested permissions. They are read-only directory scopes and nothing more.
-
Rippling sends you to RansomLeak. Enter your workspace, the first part of your RansomLeak address (
acmeforacme.ransomleak.com), and sign in if prompted. -
RansomLeak connects and returns you to Rippling to finish. The first sync starts right away.
The link Rippling hands to RansomLeak in step 4 is valid for 30 minutes. If it expires, restart the installation from Rippling.
Single sign-on
During installation, or later from the app's Setups tab in Rippling, you can turn on SAML single sign-on. Enter your RansomLeak workspace when Rippling asks for it.
- Configuration picked up automatically, nothing to copy
- "Sign in with Rippling" on the login page
- Password sign-in stays available
RansomLeak reads the SSO configuration from Rippling within an hour, or immediately when an admin selects Sync now on the HRIS tab. Employees can then open RansomLeak from their Rippling home screen or use Sign in with Rippling. An admin can require SSO or turn it off in Settings → SAML; if you turn it off, it stays off.
Custom domain? If your people use RansomLeak on your own domain, such as
training.acme.com, use the ACS URL and Entity ID shown in RansomLeak under
Settings → SAML in Rippling's SSO setup instead of the workspace field.
An identity provider you already configured, such as Okta or Entra ID, is never replaced.
Configuration
Once connected, choose what training the lifecycle assigns. Both settings live on the HRIS tab.
-
Onboarding learning path. The day-one curriculum every new hire is enrolled in. Leave it unset to turn onboarding auto-enrollment off.
-
Role and department map. Rules such as department is Engineering → Secure Coding path. The first matching rule wins, and an optional default covers anyone the rules do not match.
How it works
RansomLeak keeps the directory current on several schedules and matches people by work email, so Rippling and RansomLeak always point at the same person.
| Sync | When it runs |
|---|---|
| Change notifications | About 5 minutes after a hire, update, access change, or termination. |
| Hourly sync | Every hour, catching anything a notification missed and SSO changes. |
| Nightly full sync | Once a day, a full reconcile including people no longer returned. |
| Sync now | On demand from Admin → Integrations → HRIS. |
| In Rippling | In RansomLeak |
|---|---|
| Someone is given access | An account is created, licensed, placed on their department team, and enrolled in the onboarding curriculum. |
| Job title or department changes | The user is enrolled in the curriculum mapped to their new role or department. |
| Access removed, or employee terminated | Their account is disabled. Their training history is preserved. |
| Rehired, or access given back | Their account is reactivated. |
| Manager changes | Mirrored to RansomLeak so manager dashboards and reminders work. |
The initial sync is a baseline, not a flood. People who already had RansomLeak accounts are matched by work email and linked, with no duplicates. The first sync records your existing workforce as already onboarded, so only genuinely new hires receive onboarding training.
Using HRIS alongside SCIM
If you also provision from your identity provider over SCIM, the two sources are reconciled by work email so they do not work against each other.
- Rippling owns directory and org fields
- SCIM owns identity and access
Rippling is authoritative for names, job title, department, and manager. Your identity provider stays authoritative for login identity and role membership, and HRIS never overwrites those.
Permissions and data handling
The app requests read-only access to Rippling's directory and uses it to read the fields that drive training. Each field maps to one job.
| What RansomLeak reads | Why |
|---|---|
| Name and work email | Create the account and match the person. |
| Job title and department | Assign role-based curricula and the department team. |
| Manager | Build the reporting line for manager dashboards. |
| Employment status, start and end dates | Detect joins, departures, and rehires. |
| SAML configuration | Turn on sign-in with Rippling without copying settings. |
- Directory fields only, never pay, tax, bank, or IDs
- Encrypted in transit and at rest
- Never writes to Rippling
For how RansomLeak handles data, see the privacy policy and the security and compliance page.
Troubleshooting
| Symptom | Fix |
|---|---|
| Someone did not get an account | Check that they have access to RansomLeak in Rippling, have a work email in Rippling, and that your workspace has free licenses. The HRIS tab shows the last sync status and any error. |
| A departure is not reflected | Terminations and access removals arrive within minutes and are fully reconciled by the nightly sync. For an immediate lockout, disable the user in RansomLeak as well. |
| "Sign in with Rippling" does not appear | Finish SSO setup in Rippling, then select Sync now on the HRIS tab. If another identity provider is already configured, Rippling SSO is not applied. |
| No onboarding enrollment | Set an onboarding learning path on the HRIS tab. With it unset, new hires are provisioned but not enrolled. |
Disconnecting. Uninstall RansomLeak in Rippling, from the app's Settings, or select Disconnect on the HRIS tab in RansomLeak. Syncing stops, SSO applied from Rippling is removed, and password sign-in is restored. Users and their training history are kept.
Need a hand?
Email support@ransomleak.com and we will help you connect Rippling to your tenant.