BambooHR shipped an MCP connector: four questions to ask before you plug HR into Claude

Eduard Lupacescu
Eduard Lupacescu

3 days ago

Growee's Claude Code setup dialog showing the command that adds its MCP server

If you run a 20-person company, the question of whether your HR system should talk to an AI assistant stopped being speculative on Monday.

On 14 September 2026, BambooHR — one of the most widely used HR systems in the small and mid-market — shipped a connector that puts its people data inside Claude. Its own product update is direct about it: “AI Connectors lets you connect BambooHR to supported AI assistants, including Claude, ChatGPT, and Gemini.”

Once that vendor ships it, the buying question changes shape. It is no longer “does this HR system have MCP” — within a year most will. It is what exactly happens on the other side of that connection, and that comes down to four things you can ask in a sales call.

What BambooHR’s public pages actually say

Here is the sourced part, read from bamboohr.com on 17 September 2026, and only the sourced part.

The AI Connectors product update carries a publication date of 14 September 2026. It puts the feature under admin control: “AI Connectors is available in Settings > Apps, where administrators can enable the feature and manage access. Options are available to provide access to admins only, specific access levels, or everyone at the company.” Connection is by server URL, and the page gives its shape — “your company domain + api/mcp.”

Status is explicit, same date: “The BambooHR connector for Claude is currently available in Beta. Connections to ChatGPT and Gemini will be available in a future release.”

A companion update the same day covers permissions, and this is the sentence that matters most: “The BambooHR MCP connector lets you work with BambooHR people data from Claude using the same permissions you have in BambooHR.” Its FAQ repeats the point without hedging — “The MCP connector follows the same access model. When someone works with BambooHR data in Claude, they can only access the BambooHR data their permissions allow.” Setup is two-sided: past the admin switch, “individual users also need to enable the connector in Claude.”

Also dated 14 September 2026, and also in beta, is an Audit Trail update: “Know who, or what, made a change in BambooHR. The updated Audit Trail gives admins clearer visibility into whether activity came directly from a person or through Chat.” In practice the trail distinguishes plain human activity, activity completed with Bamboo AI (an indicator on the user’s avatar), and actions completed by Bamboo AI (a dedicated icon). BambooHR labels the caveat itself: “Functionality may change as development continues and may be removed from your account at any time without notice.”

Two limits on the above. The detailed setup guide lives in BambooHR’s customer help centre, behind a login I do not have, so I am not characterising its contents. And on the public pages I could read, no specific authentication mechanism is named. Our own roundup of which HR vendors ship MCP servers tracks every vendor we could read, quoting each one’s own documentation.

Everything past this line is my read, not BambooHR’s.

The four questions

1. Does the connector see only what my role already sees? This is the whole ballgame. One build runs each call as the person asking, inheriting their existing permissions. The other provisions a service account with broad scope and works through it — which quietly means anyone who can reach the assistant can reach whatever that account can reach, salary and contract data included. Ask which one it is, in those words. BambooHR answered it publicly on 14 September 2026, and the answer is the good one.

2. Can a headless client be scoped to specific operations? Person-level access and operation-level access are different axes, and vendors often answer the first when you ask the second. BambooHR’s 14 September 2026 update describes who may use the connector — admins only, specific access levels, or everyone. That is the first axis. The second is what a script or an unattended agent may call once it holds a credential: can you issue something that reads leave balances but cannot touch payroll records, or is a token simply you? If your plans include any automation running without a human in the chair, ask it explicitly.

3. When a change comes through an assistant, does the audit trail say so? Most buyers forget this one until the first time a record changes and nobody can explain why. An audit line reading “Maria updated this record” is technically true and practically useless when Maria asked an assistant to do it. Credit where it is due: BambooHR’s beta Audit Trail update on 14 September 2026 is a vendor building precisely this distinction, down to a separate icon for actions completed by the AI rather than with it. It may change, on their own notice — but it is the right shape, and a fair thing to require from anyone selling you an AI connector.

4. Which plan is it on? A connector gated behind the top tier is a connector your 20-person company does not have. The AI Connectors update of 14 September 2026 carries plan-type metadata listing Core, Pro and Elite, and the Audit Trail beta page says access “may be limited to specific packages if it becomes generally available” — so ask where both features land on your contract, and get the answer in the order form rather than the demo.

Where Growee fits (our own product, so read it as such)

This is the part about the thing we sell, and I would rather label it than slide it in.

Growee runs an MCP server for your tenant, reaching more than 70 areas — people, leave, hours, documents, invoices, leads, campaigns and more. On question one, the wording on our MCP page is: every call runs as your own Growee user inside your tenant, reads return only what your role can already see, and writes run the same permission checks the app applies. You sign in with OAuth and the assistant acts as you, with your role.

On question two, the alternative to an OAuth sign-in is a static MCP client token, and that token is limited to the tools on its allowlist — which is the operation-level scoping a script or headless client needs. Claude, Claude Code, ChatGPT, Codex, or any other client that speaks MCP connect to the same server URL.

On question four: MCP access is on every Growee plan, including the free one. On the free plan calls are metered at 1,000 successful tool calls a month, and on any paid plan the meter comes off.

On question three, our MCP page makes no audit-attribution claim, and I am not going to invent one in a blog post. BambooHR has shipped something there, in beta, and we have not shipped that distinction. I am publishing the question anyway, because a checklist you print only when you win it is not a checklist.

And the wider point, which cuts against us as much as for us: HiBob and several other HR vendors ship MCP servers too. The roundup linked above quotes each vendor’s own documentation, so you can check the claims rather than take mine.

The short version

BambooHR shipped an MCP connector for Claude on 14 September 2026, in beta, with permissions that mirror the user’s own and an audit trail update that flags AI-made changes, also in beta. That is a real product, and it settles whether this category matters.

If it moves you to do one thing, make it this: before you connect any HR system to an assistant, get written answers to the four questions above — whose permissions, what a headless token may call, what the audit trail records, and which plan it is on. Three of those decide your exposure. The fourth decides whether you get it at all.

Explore more articles

The copy-paste economy: why more AI tools mean more manual HR work

The copy-paste economy: why more AI tools mean more manual HR work

Workday and The Harris Poll found 82% of employees say they spend significant time copying and pasting between systems. On 20 August, Workable and Oyster shipped an integration that removes one of those handoffs. Here is the arithmetic on the rest.

Eduard Lupacescu
Eduard Lupacescu

about 1 month ago

Workday's take-private talks: what PE ownership would mean for mid-market HR buyers

Workday's take-private talks: what PE ownership would mean for mid-market HR buyers

Reuters reported that Silver Lake is in talks to take Workday private. Nothing is signed. Here is what ownership changes have meant for customers before, and the contract questions worth asking now.

Eduard Lupacescu
Eduard Lupacescu

about 1 month ago

Who is liable when the AI rejects a candidate?

Who is liable when the AI rejects a candidate?

Mobley v. Workday lets discrimination claims run against the software vendor as an agent of the employers who delegated screening to it. What that changes when you buy hiring software.

Growee

26 days ago