Enterprise integrations and access control
A managed employee store has to fit inside your IT and procurement rules, not fight them. Here is exactly how ours connects, who can access what, and how money is controlled.
Accounts that manage themselves
The store integrates with your corporate directory through SCIM 2.0, with Microsoft Entra ID as the most common source. When someone joins your organization, they get access. When they change roles, their permissions follow. When they leave, their account closes on its own. Nobody maintains a spreadsheet of users, and there are no stale accounts for an auditor to find.
Sign-in is passwordless: employees receive a one-time code at their work email. No passwords to reset, no credentials to leak, no helpdesk tickets about a merchandise store.
We don't offer SAML or OIDC single sign-on today. If that's a hard requirement, we'll tell you on the first call rather than after the contract.
Roles that match how you buy
Access is role-based: Viewers browse, Buyers order within their permissions, and Managers carry budgets they can spend on their teams. Each program track (service anniversaries, safety recognition, onboarding, corporate merchandise) shows people only the catalogue and milestones they're entitled to.
Spending limits are enforced automatically per manager, per employee, and per department, with approval workflows where a purchase needs sign-off. Claim codes let you grant one-time redemptions, useful for awards and campaigns, without opening the whole catalogue.
Procurement and reporting
- Purchase-order support alongside or instead of card checkout
- Budgets tracked per manager, employee, and department
- Order activity, budget use, and inventory reporting on the cadence you choose
- Fully bilingual operation, English and French, on every screen and email
- Payments processed on a platform holding PCI DSS Level 1 and SOC 2 Type II certifications
What this looks like in production
This isn't a feature list from a brochure; it's how our live programs run. A national transportation provider's rewards store provisions its accounts from the corporate directory, gives managers recognition budgets, and has processed more than 1,000 orders. The details are in the employee rewards case study.
If your IT or procurement team has a questionnaire, send it over. Short, direct answers are kind of our thing.
Common questions from IT and procurement
Do you support single sign-on (SSO)?
Not today, and we would rather tell you that plainly than fudge it. Store access uses passwordless one-time codes sent to the employee's work email, and accounts are provisioned and deprovisioned automatically through SCIM 2.0 from Microsoft Entra ID. In practice that means no passwords to manage, no stale accounts, and no login friction for employees.
How does account provisioning work?
The store connects to your corporate directory through SCIM 2.0. When someone joins, changes roles, or leaves, their store access updates automatically. Eligibility can also come from a data feed or manual list if your organization prefers.
Can we buy through purchase orders?
Yes. Programs can run on purchase orders alongside or instead of credit card checkout, with budgets tracked per manager, per employee, and per department.