Connect Personio to review people and upcoming departures in Flamekeeper. HR and Admin users can see confirmed terminations and contract-end warnings, add selected people to the organization, and create a prefilled handover case.
This setup uses a Personio custom integration with customer-managed API credentials. It reads data from Personio but does not change anything there.
Before you begin
You need:
- a Flamekeeper HR or Admin account;
- a Personio user with edit rights for Marketplace Integration and API;
- a Personio plan that supports custom integrations; and
- permission from your organization to share the selected employee fields with Flamekeeper.
Personio currently makes Create custom integration available on its Core Pro plan. If the control is missing, check Settings → Account & support → Subscription & billing or contact your Personio account owner.
1. Create a custom integration in Personio
In Personio:
- Go to Marketplace → Connected Integrations.
- Select Create custom integration.
- Name it something recognizable, such as Flamekeeper read-only.
- Under access rights, enable Read for Employees.
- Do not enable Write access or access to Attendances, Time off, Documents, Compensation, Recruiting, or Custom Reports.
Write permission does not include Read permission in Personio, and Flamekeeper does not need Write permission.
See Personio's guide to generating and managing API credentials for the latest location and labels.
2. Select the readable employee attributes
In the custom integration's Readable employee attributes section, select:
| Purpose | Personio attribute |
|---|---|
| Match the employee | ID |
| Display the employee | First name, Last name, Preferred name |
| Add or invite the employee | |
| Show their current state | Status |
| Prefill the handover case | Position, Department |
| Identify a confirmed departure | Termination date |
| Suggest the handover deadline | Last working day |
| Flag an expiry that HR must verify | Contract end date |
| Provide context | Termination type |
Personio displays attribute names in English in this selector even if your account uses another language.
Do not add salary, compensation, bank details, home addresses, birth dates, identity information, performance records, absence details, documents, or other fields Flamekeeper does not use.
Personio API access is not limited by normal employee-role permissions in the Personio interface. The credential can retrieve the employee attributes granted to it, so keep this list minimal and share the credentials only with trusted people.
3. Copy the credentials
Finish creating the integration and copy its:
- Client ID
- Client Secret or API secret
Store them temporarily in your approved password or secrets manager. Do not send them by email or in a support request. If the secret is lost or exposed, reset it in Personio and replace the connection in Flamekeeper.
4. Connect Personio in Flamekeeper
In Flamekeeper:
- Open Admin → Integrations.
- Open Connection, then select the Personio card.
- Review the integration details and select Configure integration.
- Enter the Personio Client ID and Client secret in the overlay.
- Select Connect Personio.
Flamekeeper authenticates with Personio and makes a small employee-data request before saving the connection. The client secret is encrypted and is never displayed again. Personio configuration and synchronized Personio data are available only to Flamekeeper HR and Admin users.
If validation fails, recheck the credentials, the Employees Read permission, and the readable attributes.
5. Run the first synchronization
Select Sync now. Flamekeeper reads all accessible employees in pages and stores only the fields listed above.
After it finishes:
- Next 3 months shows confirmed terminations whose termination date falls in the next three months;
- it also shows contract-end dates as Contract end — verify warnings when there is no confirmed termination date;
- People shows the accessible Personio directory and whether each person has been added to Flamekeeper; and
- Connection shows the connected Personio card. Open it to see the last successful sync and a safe error code when attention is needed.
Flamekeeper reconciles the connection daily. Synchronization does not update Personio, add Flamekeeper users, create handover cases, or send invitations automatically.
Understand what counts as a departure
A Personio Termination date is treated as a confirmed departure. If Last working day is present, Flamekeeper suggests it as the handover case deadline; otherwise it suggests the termination date.
A Contract end date is only a warning. A fixed-term contract may be extended, so confirm the employee is actually departing before creating a case.
Personio's employee status Leave represents a temporary or long-term absence. Flamekeeper does not treat that status as a departure. Add a long-leave case manually when your organization needs a handover for an absence.
Add a person or create a case
In People, select Add person to create or link that person as a pending Flamekeeper employee. A work email is required. Adding a person does not send an invitation.
In Next 3 months, select Create case. Confirm the job title, case type, role template, and actual last working day. For a contract-end warning, first confirm with HR that the person will leave.
You can choose whether to send the employee invitation while creating the case. Repeated submissions for the same Personio departure return the existing case rather than creating a duplicate.
Troubleshooting
| What you see | What to check |
|---|---|
| Personio rejects the credentials | Copy the current Client ID and Client Secret. Reset the secret if it was rotated or exposed. |
| Permission denied | Enable Employees Read access and save the integration. Write access alone is not enough. |
| People are missing | Confirm the employees are available to the credential and run another sync. |
| Names appear but role or departure details are blank | Add the missing readable employee attributes, save in Personio, and sync again. |
| No upcoming departures appear | Confirm a termination date or contract end date falls inside the next three months. A status of Leave alone does not appear. |
| A date differs from the expected final day | Personio's termination date and last working day have different meanings. Confirm the last working day in the case dialog. |
| A person cannot be added | Confirm the person has a valid work email. The email may already belong to another Flamekeeper organization. |
Personio can return a successful response while omitting attributes that were not selected as readable. When the connection works but data is incomplete, review the attribute list before replacing the credentials.
Rotate credentials or disconnect
To rotate a secret, reset it in Marketplace → Connected Integrations, then open Admin → Integrations → Connection → Personio in Flamekeeper and select Update credentials. Enter the Client ID and new secret in the overlay, select Replace connection, then run Sync now and confirm a successful result.
Select Disconnect to delete the saved credential and cached Personio directory data from Flamekeeper. Previously added Flamekeeper users and existing handover cases remain available.
For help, contact Flamekeeper support without including API credentials or employee data.