Frontline access driven by your Sona employee records

Connect Frontline reads employee records from Sona and turns them into secure, email-free SSO for every workplace platform your teams use. Access follows the record by role and site, opening on day one and closing on exit.

Flow-Sona
Category
Workforce Management
Integration Type
API
Direction of flow
To Connect Frontline
Sync frequency
Automatic

Access that manages itself, from first shift to last

icon-blue-personkey

Sona as the access record

For many frontline organisations Sona is the employee record. Connect Frontline reads it and turns it into secure platform access.
icon-blue-people

Ready to work on day one

A new starter in Sona arrives with access already assigned by role, site or brand. No ticket, no manual account creation, no waiting on a corporate email address that frontline workers never get.

icon-blue-refresh

Automatic leaver removal

A termination in Sona closes access across every connected platform in the same event, with the change logged and available in the Admin Console for future reference.

What the integration can and won’t do

Connect Frontline reads employee records from Sona and provisions access from them. It doesn't write back, and it doesn't touch payroll data.

  • ISO 27001
  • GDPR
  • Cyber Essentials
  • Independently pen-tested
More on Security
  • Read employee records from Sona

    Read-only access to employee name, role, site, brand and employment status.

    Granted
  • Detect joiner, mover and leaver changes

    Changes in Sona drive access changes automatically, without manual export.

    Granted
  • Provision accounts in your workplace platforms

    Create, modify or remove accounts across your various platform integrations.

    Granted
  • Write back to Sona

    Sona stays the source of truth. Nothing Connect Frontline does changes your employee records.

    Not granted
  • Read pay, banking or sensitive personal data

    Connect Frontline only reads the fields needed to determine access to each of your workplace platforms.

    Not granted
  • Shared or generic logins

    Not supported by design. Each login belongs to one person and is traceable to their HR record in Sona.

    Not supported

Why IT teams choose Connect Frontline with Sona

Identity tools are built for people with corporate email. Connect Frontline is built for everyone else, turning your Sona record into automatic platform access.

key-round-1

Connect Sona once

Connect Sona once and every platform behind Connect Frontline works from the same employee data. No separate integration to build and maintain for each tool your teams use.
personaldata

Frontline and desk-based

Frontline teams are assigned a ConnectID, which acts as their SSO access to your workplace platforms, verified against their Sona record. Desk-based staff keep their existing Entra ID if they have one.
visiblity

Every login and event accounted for

Each sign-in is verified against an HR record. Every identity change is logged, visible in the Admin Console and exportable for compliance reviews.
FAQ

Common questions

How does Connect Frontline read employee data from Sona?
Through Sona's API, read-only. Connect Frontline pulls the fields it needs to determine access: name, role, site, brand and employment status. Pay, banking and sensitive personal data stay where they are. Nothing is written back, so Sona remains the source of truth.
What happens when someone joins, moves or leaves in Sona?

Joiners are provisioned before their first shift, with access assigned by role, brand or location. Movers pick up the right access when their record changes. Leavers are closed across every connected platform in the same event, and the change is logged in the Admin Console.

Our frontline workers are in Sona but have no company email. Does that matter?
No. That's the case Connect Frontline is built for. Each frontline worker gets a ConnectID, with their account activated by a self-serve QR code and verified against their Sona record. No inbox, no personal email address, no shared logins.
Does access follow someone who works across multiple sites or brands?

Yes. Access is driven by what the Sona record says, so someone working across several sites or brands gets the access each of those requires, and loses it when the record changes. Multi-site and floating staff are handled by the same rules as everyone else, without a manual step.

Can it handle seasonal hiring?
Yes. Seasonal peaks are where manual provisioning breaks down: a large intake arrives at once, and the same volume needs closing off weeks later. Connect Frontline provisions and closes from the Sona record either way, so a seasonal intake doesn't leave a tail of live, orphaned accounts behind it once the peak passes.
We use Sona for our frontline and a separate HR system for head office. Can we use both?
Yes, this is common. Connect Frontline reads from more than one HR system at once and applies the same access rules across all of them, so you get one access layer rather than one per source.
How long does rollout take?
Connecting Sona and going live can be done in as little as two weeks. Once live, workers activate their own account via the QR code process, with setup taking less than two minutes. The Admin Console tracks claim rates by site as you roll out, so you can see who is and isn't onboarded.
What does IT have to maintain?
Once Sona is connected, very little. We'll help set the access rules at the start so the right roles get the right access. After that the lifecycle runs on its own and the audit trail builds itself, with every sign-in and access change recorded and exportable whenever a compliance review comes up.

Discover more integrations

Connect Frontline brings the same secure identity and access, HR sync and admin controls for all of the workplace platforms your teams rely on.

Browse all integrations →