
Connect Rippling to AWS IAM Identity Center to automate cloud access provisioning and ensure engineering teams get the right AWS account access based on their role.
The Rippling–AWS IAM Identity Center integration automates user provisioning and SSO for AWS environments based on Rippling employment data. Engineers and technical staff are provisioned into AWS IAM Identity Center with the correct permission sets and account assignments on hire, and deprovisioned immediately at termination — removing cloud access without requiring manual IT intervention.
AWS IAM Identity Center (formerly AWS SSO) is the recommended AWS identity layer for multi-account environments. Connecting it to Rippling ensures the employee lifecycle in HR directly controls cloud access — a key requirement for SOC 2 and cloud security compliance.
Engineering teams frequently manage AWS access through ad-hoc IAM user creation rather than through IAM Identity Center, creating orphaned accounts that persist after employees leave. Centralizing AWS access through IAM Identity Center and connecting it to Rippling's offboarding workflow ensures no cloud access survives a termination event.
thePeopleStack configures SCIM provisioning between Rippling and AWS IAM Identity Center, including permission set mapping based on engineering role and the AWS accounts each team needs access to. We validate the deprovisioning trigger and permission scoping before go-live, and coordinate with your AWS admin team on account structure.

AWS IAM Identity Center integrations for thePeopleStack's Rippling clients are structured around US engineering team cloud access configurations.
Canadian and cross-border operations: for Canadian engineering staff, AWS access provisioning follows the same Rippling-driven lifecycle as US employees. Canadian data residency requirements (e.g., data stored in ca-central-1) are addressed at the AWS configuration level, not the identity provisioning layer.
AWS IAM Identity Center (formerly AWS SSO) is Amazon's centralized identity management service for multi-account AWS environments. It allows companies to manage SSO and access permissions across all AWS accounts from a single control plane.
Rippling's department and job title fields map to IAM Identity Center permission sets and account assignments. Engineering teams can be scoped to development and staging accounts, while senior engineers get production access — all based on their Rippling role.
Yes. SOC 2 requires evidence of access provisioning and deprovisioning controls. Automating AWS access through Rippling creates an auditable trail of who had access to which AWS accounts and when that access was revoked.
It provides a better alternative for human access. AWS recommends using IAM Identity Center for all human users and reserving IAM users for service accounts and programmatic access only.
Configuration takes 3–5 hours depending on the number of AWS accounts, permission sets to define, and the complexity of role-to-permission mapping.