.png)
Cornerstone OnDemand Integration Guide
Connect Cornerstone OnDemand with HR, identity, learning, compliance, and reporting systems through REST APIs, OAuth 2.0, scheduled workflows, and verified event mechanisms.
Cornerstone OnDemand integration options at a glance
Cornerstone OnDemand primarily supports REST API integration through its developer portal, with tenant-, module-, and API-version-dependent endpoint availability. API clients generally use OAuth 2.0, bearer tokens, configured scopes, and tenant-specific environments. Selected products or events may provide webhook-style notifications or callbacks, but coverage must be verified for each object and event. Bulk, asynchronous, export, file, and attachment capabilities may also vary by endpoint. Martini can consume the REST APIs, manage secure environment configuration, schedule incremental synchronization, receive supported callbacks, transform Cornerstone Users, Learning objects, Assignments, and Transcripts, and expose controlled APIs for downstream systems.
Common Cornerstone OnDemand integration patterns
Common Cornerstone OnDemand data objects used in integrations
Authentication and security considerations
OAuth 2.0 and tenant permissions
Cornerstone API access generally uses a registered application, OAuth 2.0 credentials, bearer access tokens, and tenant-configured scopes or roles. API availability and administrative approval can vary by module and tenant.
Secure Martini configuration
Store client secrets, tokens, tenant URLs, and environment-specific settings in Martini secrets or secure configuration rather than workflow definitions or mappings.
Data protection
- Minimize employee, learning, performance, and compliance data transferred between systems.
- Restrict Cornerstone API permissions to required objects and operations.
- Do not write access tokens or secrets to logs.
- Keep identity-provider authentication distinct from Cornerstone API authorization.
Operational considerations for Cornerstone OnDemand integrations
Pagination and rate limits
Treat Cornerstone collections as paginated unless endpoint documentation states otherwise. Confirm tenant limits and use bounded batches, throttling, exponential backoff for 429 and transient 5xx responses, and controlled concurrency.
Incremental synchronization
Prefer documented update filters, date ranges, status filters, or change mechanisms. If these are unavailable, use checkpoints and bounded lookback reconciliation to account for late updates and transcript corrections.
Idempotency and errors
Use stable Cornerstone identifiers or agreed employee keys to make updates repeatable. Categorize authentication, validation, rate-limit, tenant-configuration, duplicate, and transport failures, and retain sanitized source identifiers and correlation information.
Schema and testing
Cornerstone schemas vary by product module, API version, and tenant configuration. Test representative Users, Organizations, Learning objects, Assignments, and Transcripts before deployment and validate mappings after API or configuration changes.
Why use Martini instead of scripts or point-to-point integrations?
Orchestration beyond point-to-point calls
Martini coordinates Cornerstone API calls with HR, identity, workflow, CRM, and reporting systems in reusable workflows rather than scattering logic across scripts.
Reliable data movement
Workflows can combine pagination, checkpoints, mapping, validation, business rules, retries, idempotency, and monitoring for repeatable enterprise synchronization.
Controlled API access
Martini can expose normalized APIs for downstream applications while keeping Cornerstone authentication, tenant configuration, and source-specific data handling behind a controlled integration boundary.
Maintainable implementation
Explicit mappings and reusable workflow logic make module-specific Cornerstone behavior easier to test, troubleshoot, extend, and deploy than isolated point-to-point scripts.