LATTICE_API_KEY), plus LATTICE_BASE_URL if your Lattice data is hosted in Europe.
Scope of this integration today. ConfigView uses Lattice as the HR record of who works at the company: everyone’s status (active, invited, not yet invited, deactivated), manager, department, job title and start date, who is a Lattice admin, and the employee ID your HR system gave them. It compares that record with Okta and Google Workspace to find leavers whose accounts are still on, starters who have no accounts yet, and people with no manager. ConfigView only reads. It never reads reviews, feedback, goals, updates, custom fields or pay, and never stores birth dates or gender.
Step 1: Open the Lattice page in ConfigView
Open ConfigView in a second browser tab and leave it open:https://{companyname}.configview.com/admin/integrations/lattice
Lattice shows the key once, when you create it, so paste it straight into ConfigView instead of keeping it in a notes file.
Step 2: Create an API key in Lattice
You need to be a Lattice admin. A Lattice API key has the same rights as the person who creates it, so a non-admin’s key would not see everyone.- In Lattice, click Admin at the bottom of the left sidebar
- Go to Settings → Platform → API keys
- Click Generate API key
- Click Copy. Lattice shows the key in full only once
- Paste it into
LATTICE_API_KEYin ConfigView and click the save icon
request-api-access@lattice.com with what it is for (“read-only user directory sync to ConfigView, our IT inventory tool”). After that, admins can create and revoke keys themselves.
Europe-hosted Lattice. If your company’s Lattice data is hosted in the EU/EMEA region, also save LATTICE_BASE_URL as https://api.emea.latticehq.com. Leave it empty for US hosting. If you are not sure, Lattice customer care can tell you.
Who owns the key matters. The key stops working if the admin who created it leaves Lattice, and sees less if they stop being an admin. Create it as a long-lived admin (or a dedicated admin account if your company uses one). To revoke ConfigView’s access, click Revoke next to the key on the same page.
Step 3: Connect and verify
- Back on
https://{companyname}.configview.com/admin/integrations/lattice, confirm the credential shows as saved - Click Connect. ConfigView creates its tables and schedules every collector at your default run time. Stop any you don’t want under Collectors:
- Click Verify now. The health check confirms the secret, checks whose key it is and that they are a Lattice admin, then reads one page of people and departments.
- 401. The key is wrong or was revoked, the admin who created it has left Lattice, or your company is hosted in Europe and
LATTICE_BASE_URLis not set. Generate a new key, or set the EMEA host. - “NOT a Lattice admin”. The key belongs to someone without admin rights. Have an admin generate a new one.
- 429. Lattice’s limit of 240 requests a minute is spent for now, usually by another integration. The next run will be fine.
Data Tables
Once the scripts run, these tables are created in your database. Each includes arun_at column and keeps only the newest run.
status is Lattice’s lifecycle status: ACTIVE, INVITED (sent an invitation, not yet signed in), CREATED (added but not invited yet) or DEACTIVATED (left, or removed by an admin).
external_user_id is the person’s ID in the HR system that feeds Lattice (BambooHR, Rippling, Workday and others). People without one were usually added to Lattice by hand. Lattice’s API does not say which HR system it is connected to.
manager_email and manager_name come from the manager’s own Lattice record in the same run, so a manager who is not in Lattice leaves them empty while manager_id stays filled.
Things worth knowing
Lattice does not report a leaving date. When someone is deactivated, the API showsstatus = DEACTIVATED and moves updated_at, but gives no termination date. ConfigView’s leaver checks use updated_at as the closest thing.
Deactivated people are collected on purpose. Lattice’s API returns only active people unless asked, so ConfigView asks once per status. That is what lets it spot a leaver whose Okta or Google account is still on.
The API is small and changes. Lattice describes its public API as still being updated, with no audit log, no list of admins’ permissions beyond the admin flag, and no list of connected integrations (HR system, Slack). ConfigView collects what is there.
What isn’t collected
- Reviews, review cycles, feedback, goals, updates, one-on-ones and tasks
- Custom attributes (they often hold pay, performance or personal fields)
- Compensation of any kind
- Birth dates and gender, which Lattice includes in its user records; ConfigView drops them before storing anything