Flamekeeper documentation

Connect HiBob

Connect HiBob to Flamekeeper with a read-only API Service User, synchronize people and upcoming leave, and start handover cases safely.

Connect HiBob to review people and lifecycle changes in Flamekeeper. HR and Admin users can see upcoming departures and leave, add selected people to the organization, and create a prefilled handover case.

This setup uses a Bob API Service User. You do not need to join the HiBob partner program or configure OAuth for a connection to your own Bob account.

Before you begin

You need:

  • a Flamekeeper HR or Admin account;
  • a Bob Admin who can create API Service Users and permission groups; and
  • permission to decide which employees the integration may read.

Use a dedicated Service User for Flamekeeper. Do not reuse a personal account or give the Service User Edit access.

1. Create a Bob API Service User

In Bob, open the Service Users configuration and create a user named something recognizable, such as Flamekeeper read-only.

Copy both values when Bob creates the user:

  • Service User ID
  • Token

Bob only displays the token when it is generated. Store it in your approved password or secrets manager until you enter it in Flamekeeper. If it is lost, generate a replacement token rather than sharing credentials in email or support messages.

See HiBob's API Service User guide for the current Bob controls.

2. Create a dedicated permission group

New Service Users have no permissions. Create a permission group specifically for Flamekeeper and add only the new Service User to it.

Under People's data → People's fields, grant View for the fields below. Bob may show a field under a different category if your organization has customized its employee profile, so use the field itself rather than relying only on the category name.

Data Flamekeeper uses Bob field ID
Employee identifier root.id
Work email root.email
First name root.firstName
Surname root.surname
Job title work.title
Department work.department
Account status internal.status
Lifecycle status internal.lifecycleStatus

For Lifecycle (Table):

  1. Grant View for the table or the status and effective-date columns.
  2. Grant View history on the Lifecycle category. Bob makes this permission available on the category rather than individual fields.

Flamekeeper does not need Edit access, payroll, salary, bank details, home addresses, birth dates, identity data, performance records, documents, or termination reasons.

3. Choose which people Flamekeeper can read

Open the permission group's People's data → Access data for settings and include the employees who should appear in Flamekeeper.

Bob commonly limits access to employed people. To include scheduled departures, inactive employees, or employees on leave, use Select people by condition and remove a restriction that only allows Lifecycle status equals Employed. Apply any other conditions your organization needs.

This audience controls what Flamekeeper can synchronize. A person outside it will not appear even if the individual field permissions are correct. See HiBob's employee-data permission guidance.

4. Connect Bob in Flamekeeper

In Flamekeeper:

  1. Open Admin → HiBob.
  2. Select the Connection tab.
  3. Enter the Service User ID and Service User token.
  4. Select Connect HiBob.

Flamekeeper validates the credentials against Bob before saving them. The token is encrypted and is never displayed again. If validation fails, recheck the ID, token, permission-group membership, and employee-data permissions.

5. Run the first synchronization

Select Sync now. A complete synchronization can take longer for a large organization because Flamekeeper reads employee details in batches and follows every page of accessible lifecycle history.

After it finishes:

  • Next 3 months shows future Terminated, Garden leave, Leave, and Parental leave lifecycle entries;
  • People shows the accessible Bob directory and whether each person has already been added to Flamekeeper; and
  • Connection shows the last successful sync and a safe error code when attention is needed.

Flamekeeper also reconciles the connection daily. Syncing is read-only: it does not change Bob, create handover cases, add Flamekeeper users, or send email automatically.

Add a person or create a handover case

In People, select Add person to create or link that person as a pending Flamekeeper employee. A work email is required. Adding a person does not send an invitation.

In Next 3 months, select Create case next to a lifecycle event. Confirm the job title, case type, role template, and final working day before creating the case. Bob's lifecycle effective date is used as a starting value, but it may not be the person's actual final working day.

You can choose whether to send the employee invitation while creating the case. Repeated submissions for the same Bob lifecycle event return the existing case instead of creating another one.

Troubleshooting

What you see What to check
Bob rejects the credentials Copy the current Service User ID and token. Generate a new token if the original was lost or rotated.
Permission denied Confirm the Service User belongs to the dedicated group and has View plus Lifecycle View history.
People are missing Check Access data for, especially restrictions to employed people, and verify the required field categories.
Names appear but role details are blank Grant View on the actual categories containing job title and department, then sync again.
No upcoming events appear Confirm Bob has future Lifecycle rows inside the next three calendar months and that View history is enabled.
The connection shows an error after previously working Check whether the token was rotated, the Service User was deleted, or its group permissions changed.
A person cannot be added Confirm the person has a valid work email. The email may already belong to another Flamekeeper organization.

HiBob can return a successful API response while omitting fields the Service User is not allowed to read. When the connection works but data is incomplete, review permissions before reconnecting.

Rotate credentials or disconnect

To rotate a token, generate a replacement in Bob, then open Admin → HiBob → Connection and select Replace connection after entering the Service User ID and new token. Run Sync now and confirm a successful result before retiring old credentials.

Select Disconnect to remove the saved credentials and cached Bob directory data from Flamekeeper. Previously added Flamekeeper users and existing handover cases remain available.

For help, contact Flamekeeper support without including Service User credentials or employee data.

Keep the knowledge. Carry on with the work.

Open Flamekeeper