Skip to main content

SAP SuccessFactors Write-Back Integration

Send data collected in Enboarder forms straight back to SAP SuccessFactors Employee Central, with no re-keying.

Written by Chris Jones

Note on Availability: SAP SuccessFactors Write-Back is an add-on product and is set up with the help of our team. Reach out to your account team if you'd like to learn more.


Your new hires already give you their details during onboarding: contact information, addresses, emergency contacts, bank details and more. With SAP SuccessFactors Write-Back, that data flows straight from your Enboarder forms into SAP SuccessFactors Employee Central, so nobody has to re-key it. 🙌

Before you begin: You'll need a SuccessFactors administrator with the Manage Integration Tools and Manage Permission Roles permissions. The SuccessFactors setup takes around 20–30 minutes. We recommend setting up and testing in your SuccessFactors sandbox first. Nothing goes live until you approve it.

Write-back builds on our standard SAP SuccessFactors Integration, which sends new hires from SuccessFactors into Enboarder.


How write-back works

  1. You add a Form Module to your workflow and map its fields to SuccessFactors fields.

  2. The employee fills in and submits the form.

  3. Enboarder finds the employee in SuccessFactors using their office email address and updates their Employee Central record with the mapped values.

  4. The result of each field (written back, failed or skipped) is recorded in the form's activity log.

Important:

  • Write-back updates employees who already exist in SuccessFactors. It doesn't create new employee records.

  • The employee profile in Enboarder must have an office email address. If your workflow only captures a personal email at first, use an Update Value module to update the profile to the office email before the write-back form is sent.

  • Write-back happens once, when the form is submitted. Editing a form after it's been submitted doesn't send the changes again.


What data can be written back?

Data

Examples

Personal information

First, middle, last and preferred name, salutation, gender, marital status

Email

Business and personal email, email type, primary flag

Phone

Number, country code, phone type, extension

Address

Address lines, city, state/province, postal code, country

National ID

ID number, ID type, issuing country

Work permit

Permit type, issuing country, issue and expiry date

Emergency contacts

Name, relationship, address, country, mobile number, primary flag

Bank details

Bank and account details (routing number/BSB and BIC are taken from the SuccessFactors bank record)

Attachments

Files uploaded in the form, attached to the employee's person record

Dropdowns in your forms can use picklists from SuccessFactors, including dependent picklists (for example Country → State → City), so the values your new hires choose always match your SuccessFactors setup.

Our team activates the fields available to your account during setup. Only activated fields appear when you map a form. Want to add a field? Contact your account team.

Not included: compensation and payroll history, performance reviews and goals, time-off and leave balances, or anything outside the fields your SuccessFactors admin grants access to.


Step 1: Set up SuccessFactors

Your SuccessFactors admin will need to complete these steps and share five values with you: API Server URL, Company ID, API User ID, API Key (Client ID) and Client Secret (Private Key).

1.1 Find your API Server URL

Look up your data center on SAP's List of SAP SuccessFactors API Servers page, filtered to your environment (usually Production).

TIP: If you log in at https://hcm12.successfactors.com, your API server is likely https://api12.successfactors.com.

1.2 Find your Company ID

Click your profile image (top right), select Show Version Information, and copy the Company ID.

1.3 Create an API user

Go to Admin Center → Manage Users and create a dedicated user, e.g. ENBOARDER_API. Set the status to Active. The password isn't used for authentication, but should still be strong.

1.4 Register an OAuth2 client

  1. Go to Admin Center → Manage OAuth2 Client Applications → Register Client Application.

  2. Enter Application Name: Enboarder, and Application URL: https://app.enboarder.com.

  3. Click Generate X.509 Certificate, enter any Common Name, and click Generate.

  4. Download Certificate.pem. Open it in a text editor and copy the text between BEGIN ENCRYPTED PRIVATE KEY and END ENCRYPTED PRIVATE KEY. This is your Client Secret.

  5. Click Register. Then go back to Manage OAuth2 Client Applications, click Edit on the Enboarder application and copy the API Key. This is your Client ID.

Please store the Client Secret securely, as it gives access to your SuccessFactors data.

1.5 Set up role-based permissions

  1. Go to Admin Center → Manage Permission Roles → Create New, and name the role Enboarder Integration.

  2. Set the Target Population to All Active Employees, or narrow it to a specific group (e.g. new hires only, or one country).

  3. Grant Read + Write access to: Personal Information, Email Information, Phone Information, Address Information, National ID Information, Emergency Contacts, Employment Information and Job Information.

  4. If they're in scope for you, also grant: Payment Information and Attachments (Read, Write, Create, Delete), Work Permit and User Management.

  5. Grant read-only access to Foundation Objects, Picklists and Position.

  6. Turn on field-level permissions for each field you plan to write back.

  7. Click Grant This Role, select your API user and confirm.

TIP: Field-level permissions are the most commonly missed step. If a field isn't permitted, SuccessFactors can accept the update but quietly skip that field. Commonly missed fields include date of birth, gender, nationality, national ID, phone number, email address and bank account details.


Step 2: Connect Enboarder

  • Log in as an admin and navigate to Settings → Apps & Integration → App center.

  • Click the SAP SuccessFactors tile. If you see two tiles with the same name, choose the native one (the tile without the HRIS crown label).

  • Click Add Integration. In the Outbound section, enter the five values from Step 1: API Server URL, Company ID, API User ID, API Key (Client ID) and Client Secret (Private Key).

  • Save. Enboarder will test the connection and run a permission check to see which SuccessFactors data it can access, and let you know about any gaps.

  • Fix any gaps with your SuccessFactors admin. Once all checks pass, the tile shows as active. ✅


Step 3: Add in your form fields

  • Navigate to the Form you wish to use to write-back data to SuccessFactors

  • Click the + icon

  • Select the System as SuccessFactors and choose whether you wish to push to the Sandbox or Production account

  • Select the Update function

  • Select all of the fields that you wish to have data write-back from

  • Rename the labels and re-order the fields as needed


Step 4: Map your form fields

  • Click the Form Settings dropdown at the bottom of the form and turn on Write back to HRIS.

  • For each form field, choose the matching SuccessFactors field. Fields are shown as Entity - Property.

  • Save your mapping.

  • Click Test mapping, enter a test employee's email and click Fetch employee. You'll see the mapped fields with their current SuccessFactors values. Make a change, submit, and check the success or failure message.

Note - Test mapping sends a real update to the SuccessFactors record you choose. Use your sandbox or a dedicated test employee.


Troubleshooting

  • Check the activity log: open the submitted form's activity log. Each mapping shows the form field, the SuccessFactors field, the value sent and a status: Written back, Failed or Skipped.

Success example:

Failure example:

  • Check the integration logs: go to Settings → Integrations → Integration logs to view the full API response.

  • Data looks synced but isn't there? This is usually a missing field-level permission in SuccessFactors. Check the role from Step 1.5, then retest with a test employee.

  • Change waiting in SuccessFactors? Updates to things like job information, bank details, date of birth or legal name may go into a pending approval state, depending on your SuccessFactors workflow setup. Talk to your SuccessFactors admin about whether the API user should be exempt from those workflows.

  • Employee not found? Check the employee profile in Enboarder has the same office email address as in SuccessFactors.


FAQs

Does Enboarder need access to compensation data?
No. Enboarder does not require access to compensation, performance or time-off data.

Can we limit which employees Enboarder can update?
Yes. Narrow the Target Population on the Enboarder Integration permission role in SuccessFactors.

Is the connection secure?
Yes. Enboarder connects using OAuth2 with a certificate (SAML bearer assertion), with no user login involved. All communication uses HTTPS/TLS 1.2+, and the private key is stored encrypted at rest.

Can write-back create new employees in SuccessFactors?
Not currently. Write-back updates employees who already exist in SuccessFactors. Employee creation is on the roadmap.

Do I need the inbound integration too?
The inbound integration launches new hires from SuccessFactors into Enboarder, and write-back sends their data back. Both are set up on the same native SAP SuccessFactors tile.


Got questions? Click on the '?' button at the top right of any Enboarder page to start a chat with us. Alternatively, email us! support@enboarder.com ✌

Did this answer your question?