Your HRIS just became an AI platform. Turn it on without turning it loose.
Rippling AI and Bob Companion are live. We activate them safely — permissions, governance, training — on a clean build.
Most teams will get it wrong.
Rippling and HiBob now ship serious AI — agents that answer employees, stage payroll, draft reporting.
The AI answers from whatever your system lets it see. On a clean build, that’s leverage. On a messy one, it’s a liability with a chat interface. We build the clean version, then turn the AI on.
Platform capabilities described on this page were last reviewed July 2026.
The boundary is set before anything is switched on. The agent answers self-service questions; pay and performance stay closed.
Nobody set a boundary, so there isn’t one. The same agent reads pay and performance because nothing stopped it.
The AI layer inherits whatever permission structure sits beneath it: where permissions are designed with per-feature toggles, the agent’s reach stops at self-service records while pay and performance stay behind a closed gate; where they are defaulted to a master switch, the same agent inherits reach across the whole record.
Three ways this lands on your desk.
The toggles are already on
Someone enabled the assistant to try it, and now it answers whatever the permission model lets it see. Nobody has checked what that is.
Counsel asked for a policy
The board or a customer asked how AI use is governed, and the honest answer today is a shrug. You need posture on paper, not a ban.
The team is already using chatbots
Employee data is going into unsanctioned tools because the sanctioned ones are worse. A memo will not fix that. A better tool with designed permissions will.
Four modules, in this order.
The order matters more than the list. Enablement before an audit is how the mistake gets a chat interface.
Permission & data audit
The AI answers from whatever it can see, so we decide what it sees. Every role, every field, every report, mapped and corrected before a single agent is switched on.
Phased agent enablement
Which agents, in what order, with per-feature toggles rather than a master switch. Some are worth turning on in week one. Some are not worth turning on this year.
Policy & governance
An AI usage policy, an audit trail, and the rollout communications. Posture and process, not legal advice: we draft what your counsel reviews and signs.
Training
Admin prompt fluency and manager sessions. These tools only pay off when the people using them know what to trust, what to verify, and where an answer came from.
Documents, not a summary of documents.
- 01Scope and definitions
- 02Approved tools and access
- 03Data that never goes in a prompt
- 04Human review requirements
- 05Audit trail and retention
- 06Escalation and exceptions
- Permission and data audit findings
- Phased agent enablement plan
- AI usage policy draft
- Audit-trail configuration
- Rollout communications pack
- Admin and manager training
Every one of these is a file you keep. If you end the engagement, the policy, the audit findings, and the enablement plan stay with you and still make sense to whoever reads them next.
The part most vendors skip.
AI will not fix a broken process
It will run the broken one faster and with more confidence. If onboarding is guesswork today, an agent makes it guesswork at scale.
Some agents are not worth enabling yet
A few are genuinely good. Several are demos with a roadmap attached. We will tell you which is which, including when the answer is none of them.
If the data is not clean, this is the wrong project
Activation on a messy build is how a permission mistake becomes a chat interface. We would rather fix the build first and bill you less this quarter.
AI activation, a sprint from $12k.
Ongoing governance sits inside the Operator tier. Every tier and every number, shared in full on our first call. See pricing
The ones counsel asks first.
Does our data train the models?
That depends on the platform and the plan you are on, and it is the first thing we check rather than the last. We document what each vendor does with your data, what we can turn off, and what remains true after we leave. Our own handling is written up separately. How we handle your data
What does activation actually include?
A permission and data audit, a phased enablement plan, an AI usage policy your counsel can sign, audit-trail configuration, rollout communications, and training for admins and managers. You get the documents, not a summary of them, and they stay yours afterwards.
Can you do this on a system someone else implemented?
Yes, and it is a large part of this work. We audit first, because activating on a build we have not inspected is how you inherit somebody else's permission mistake. Sometimes the audit says fix the foundation before switching anything on.
Which agents do you turn on first?
The ones where a wrong answer is cheap and a right answer saves real time, which usually means employee self-service questions before anything touching pay or performance. The order is set by your permission structure and your risk appetite, not by a vendor release note.
Is this legal advice?
No. We handle posture and process: what the policy needs to cover, how the audit trail is configured, and how the rollout is communicated. Your counsel reviews and signs the policy. We have never met a lawyer who wanted a consultancy to skip that step.
Our team is already pasting employee data into chatbots. Now what?
You are not unusual, and a memo banning it will not work. The fix is to give people a sanctioned tool that is better than the unsanctioned one, with permissions that make the risky version unnecessary. We start by finding out what is actually happening.
20 minutes. No deck. No pitch.
You talk. We map what you’re running and where to start. The fixed quote follows the call, in writing.