Staffwell: setup and user guide
What Staffwell does
Staffwell shows the requester's employee record from HiBob, Deel or BambooHR in the Zendesk ticket sidebar (and on user profiles): employment status, job title, department, manager, location, start date, employment type, work phone, time zone, time off today and in the next two weeks, and the equipment the HR system has on record. It warns first when someone has left, is leaving, is on leave, has not started yet or is out today. You choose which fields every agent sees and which only HR roles see. Staffwell only reads: it never changes anything in your HR systems.
What Staffwell never shows
Pay and compensation, bank details, national ID, tax, SSN and passport numbers, birth dates, gender, ethnicity, marital status, home addresses and personal contact details, dependents, benefits, and health data. There is no setting that turns them on: Staffwell has no way to request them. Leave always reads "On leave", and time off reads "Time off" unless you allow ordinary types (Vacation, Training); sick, medical, parental and other personal leave are never named.
1. Create a read-only credential
Create one for each HR system you use. Give it access to the fields you will show and nothing more: the credential's own permissions are the outer limit of what anyone can read through it.
HiBob
- In Bob, go to Settings > Integrations > Service users and create a service user named "Staffwell for Zendesk". Copy the ID and the token (shown once).
- Create a permission group, add the service user, and grant View on:
| HiBob area | Fields | For |
|---|---|---|
| People's data > Basic info | Display name, first name, surname, email | Matching and the name (always) |
| People's data > Work | Title, department, site, start date, reports to | Job title, department, location, start date, manager |
| People's data > Lifecycle / internal | Status, lifecycle status, termination date | Employment status and the warnings |
| People's data > Employment | Employment type | Employment type |
| Time off | Who's out | Time off |
- Under Access data for, choose Select people by condition and remove "Lifecycle status equals Employed" so Staffwell can warn about people who have left.
- HiBob's API has no equipment table, and no work phone or time zone field Staffwell can read.
Deel
- In Deel, go to More > Developer > Access tokens > Generate new token and choose an Organization token.
- Scopes:
people:read(required),time-off:read(time off),it-assets:read(equipment from Deel IT). Leave sensitive data access off. - Copy the token. Deel has no work phone field and no record link Staffwell can build.
BambooHR
- In BambooHR, create (or pick) a user whose access level covers only the fields you will show: job information, employment status, hire and termination dates, work contact and the Assets tab. The API key sees exactly what that user sees.
- Signed in as that user, click your name > API Keys > Add New Key, name it "Staffwell for Zendesk" and copy it.
- Your subdomain is the part before .bamboohr.com in your BambooHR address (for
https://acme.bamboohr.com, enter
acme).
2. Install and connect
- In the Zendesk Marketplace, open Staffwell and choose Install on the Standard plan ($499 per month per Zendesk account, any number of agents). The 14-day trial starts and Zendesk asks for a card. Billing starts when the trial ends unless you uninstall.
- Fill in the systems you use: HiBob service user ID and token; tick Use Deel and paste the Deel token; BambooHR subdomain and API key. Credentials are secure settings: agents never see them, and Zendesk sends each one only to its own HR system.
- Optional: also limit which roles and groups have the app at all, under Admin Center > Apps and integrations > Zendesk Support apps > Staffwell > Settings > Enable role restrictions.
3. Choose who sees what
| Setting | Default | What it does |
|---|---|---|
| Who can see the panel | agent | Everyone else sees a short notice. Admins always see the panel. Comma separated: agent, admin, custom role ids, group:<id> |
| Fields every agent sees | status, title, department, manager, location, time_off | Shown to everyone who sees the panel |
| Extra fields for HR roles | start_date, employment_type, work_phone, timezone, equipment | Shown only to the roles below, on top of the first list |
| Who sees the HR fields | admin | For example admin, group:360001234 for your People team group |
| Show the type of time off | off | On: Vacation or Training are named; sick, medical, parental and personal leave still read "Time off" |
| Allow internal notes | on | Agents can add the fields they see to the ticket as an internal note |
Field names: status, title, department, manager, location, start_date,
employment_type, work_phone, timezone, time_off, equipment. Staffwell asks the HR
system only for the fields the agent in front of it may see, so hidden fields never reach that
agent's browser. Admins see a short list in the panel of anything to fix (an unknown field name, a
field the HR system cannot supply).
4. Using it
- Open a ticket. Staffwell matches the requester by every email address on their Zendesk profile and shows their record, warnings first.
- Connected to more than one HR system? Each match shows as a button; pick one.
- No match (an external customer, or a personal address the HR system does not hold)? Type their work email in Employee email and press Find. Lookup is by exact email only.
- Add to ticket as internal note: tick the fields to include, read the confirmation, then
Add note. The note is internal (agents only) and the ticket gets the
staffwell_notetag. - Refresh reads everything again. Nothing is kept after the panel closes.
5. Troubleshooting
| Message | Fix |
|---|---|
| "did not accept the service user ID and token / API token / API key" | The credential was deleted, rotated or mistyped. Paste the current one. BambooHR also pauses a key after repeated bad attempts; wait and try again |
| "refused the request" | The credential lacks a permission. Deel names the missing scope |
| Status reads "Not shared by HiBob" | Grant the service user's group View on the lifecycle and status fields |
| A leaver is not found in HiBob | Remove "Lifecycle status equals Employed" from the group's access |
| A field is empty | The HR system has no value, the credential cannot see it, or the HR system does not offer it (see the admin list in the panel) |
| BambooHR subdomain refused | Enter only the part before .bamboohr.com |
| "Your role cannot see employee records" | Add the role or group to Who can see the panel |
6. Data and privacy
Staffwell runs in the agent's browser inside Zendesk. It has no Great Work server, sends nothing to Great Work or anyone else, uses no AI and keeps no copies. HR data is read live while the sidebar is open. HiBob answers "who's out" for everyone the service user can see; Staffwell keeps only the requester's entries and discards the rest immediately. Full details: https://greatwork.company/apps/staffwell/privacy.
Support
hello@greatwork.company, reply within one business day. Never send employee data, tokens or keys.