What Oleria discovers
Once connected, Oleria continuously discovers and maps the following from GreytHR:- Employees - the full worker population, including personal details and work details.
- Departure records - when an employee leaves, Oleria picks up their end date and marks them inactive, so former employees who still have access in other connected applications stay visible in Oleria.
- Departments - the department each employee belongs to, used to build organizational context within Oleria.
GreytHR tracks who your workers are, not what they can access in your applications. GreytHR does not include group memberships, application roles, MFA status, SSO enrollment, or audit activity. Access and activity data comes from your identity provider and other connected application integrations.
Prerequisites
- Access to the GreytHR Admin portal, to create a dedicated API user for Oleria
- Your GreytHR subdomain (the part before
.greythr.comin your login URL, for exampleacmefromhttps://acme.greythr.com)
Use a dedicated API user rather than a personal employee account for the integration to ensure continuity if the employee leaves or changes roles.
Create an API user in GreytHR
To connect Oleria, you need to create a dedicated API user in GreytHR and copy the credentials it generates. Follow these two steps in order.1
Enable the API User Provisioning role (if not already enabled)
In GreytHR, navigate to Settings → System Settings → User Administration → User Roles. Find the role you plan to assign to the API user and confirm the API User Provisioning checkbox is enabled.
For new GreytHR accounts, this option may not be enabled by default - it is typically set up by the GreytHR implementation team during onboarding. If you do not see the checkbox or cannot enable it, contact GreytHR support before proceeding.
2
Create the API user and copy credentials
Navigate to Settings → My Account → API Users and select Create API User. Enter a username and description, for example
Oleria Integration, and assign the appropriate role.After saving, GreytHR displays a Client ID and Password. Copy both values immediately and store them securely.Connect GreytHR to Oleria
1
Open the integration
Go to your Oleria workspace, select Integrations → select GreytHR.
2
Complete the connection form
Select Continue and fill in the connection form:
Oleria labels this field “Client Secret” - enter the API user password from GreytHR here.
3
Save the integration
Select Authenticate to validate and save the integration. Oleria checks the credentials against GreytHR before saving.
Verify the integration
Confirm the GreytHR instance appears in your Oleria workspace connected integrations. After the first sync completes, you can review the discovered employees and departments in your Oleria workspace.If you reset the API user password in GreytHR, update the Client Secret in Oleria by editing the integration. Outdated credentials will cause the sync to stop.
Known limitations
- No application access data - GreytHR tracks worker identity, not application access. Group memberships, application roles, MFA status, and SSO enrollment come from your identity provider and other connected applications.
- No audit log - GreytHR does not provide audit activity through this integration.
- No disable or suspend state - GreytHR does not have a concept of a disabled or suspended employee. Oleria uses departure records to identify employees who have left the organization.
- Cost center and employment type are not available - GreytHR’s API does not expose these fields. They will not populate in Oleria for any employee record.
- Flat department structure - GreytHR does not expose parent/child department relationships. Oleria shows which department each employee belongs to, but nested department hierarchy is not available.

