The Rippling integration is in beta. Setup takes more configuration than most connectors, so read Current limitations before you commit a close cycle to it. Contact DualEntry support if you want help with the first connection.
Prerequisites
Confirm all of the following before you start. The first two are the ones that most often block a connection on the day.- The Rippling App Management package. Your organization must have purchased it. If you do not have it, contact your Rippling Account Manager to add it. Without the package, the install does not work.
- Rippling admin permissions for whoever runs the install. Your organization may need to grant these internally first, so confirm them before you start rather than partway through.
- Permission in DualEntry to create and configure integrations.
- A vendor record in DualEntry to act as the payroll vendor, stamped on the journal entries the integration writes.
- GL accounts in your chart of accounts for payroll expense, employer tax expense, employer benefit contributions, withholding liabilities, and an accrued payroll or clearing account to use as the offset.
- A DualEntry company for each Rippling legal entity you intend to post to. Every legal entity has to be mapped before setup counts as complete.
- Optionally, a classification such as Department in DualEntry if you want journal entry lines split by Rippling department.
How to connect
Connecting redirects the browser to Rippling’s install screen, where a Rippling admin authorizes DualEntry. The authorization code comes back to DualEntry, which exchanges it for tokens and immediately runs a metadata sync so there is something to map.- Confirm both Rippling prerequisites above.
- Sign in to DualEntry as the person who holds Rippling admin permissions, since the same session authorizes both sides.
- Go to Company → Integrations → Rippling.
- Choose Connect. DualEntry sends the browser to the Rippling install screen for the DualEntry app.
- Authorize DualEntry from that screen. Rippling returns to DualEntry, which stores the tokens and marks the app installed on Rippling’s side.
- Confirm the connection shows as active.
- Complete the mapping described in the next sections, then run the first sync and check the entries it produces before you rely on the daily schedule.
What syncs
The first sync after connecting pulls reference data only, so you can finish mapping before any journal entry is written. Pay statements post once the required mappings are complete. The following table maps each kind of Rippling data to the DualEntry record it becomes:
Only pay runs in an APPROVED or PAID state sync. Runs in any other state are skipped until they are finalized.
Choose which worker types to sync
Rippling covers three kinds of worker, and each posts differently. Turn on only the ones you actually pay through Rippling, because each one you enable adds its own required mappings before setup counts as complete. The terms come from Rippling and from US payroll practice rather than from DualEntry:- W-2 employee. A direct employee of one of your legal entities, named for the US wage and tax statement filed for them. Payroll taxes are withheld and remitted on their behalf.
- 1099 contractor. A self-employed worker paid without withholding, named for the US information return filed for them.
- EOR, employer of record. A third party that legally employs a worker on your behalf, typically in a country where you have no legal entity. You direct the work; the EOR runs the employment.
- PEO, professional employer organization. A co-employment arrangement in which a third party handles payroll, taxes, and benefits for workers at your own entity.
- Sync W-2 Employees. Posts payroll journal entries for W-2 employees. Requires the W-2 pay statement item catalog to be fully mapped and a Default Offset Account (W-2).
- Sync 1099 Contractors. Posts journal entries for contractors. Requires the contractor catalog and a Contractor Offset Account.
- Sync EOR/PEO. Posts EOR and PEO payroll as a consolidated invoice-total journal entry. Requires the EOR catalog, an EOR Offset Account (the payable to Rippling) and an EOR Employment Expense account.
Set the accounting basis
The Accounting Basis setting decides how many journal entries a W-2 pay run produces and what they are dated. Set it once, before the first sync, because it changes the shape of every entry the integration writes. On Accrual, a W-2 pay run produces two journal entries: an accrual entry dated the end of the pay period, and a payment entry dated the check date. The payment entry is only written when the two dates differ, so a run whose period ends on the check date produces a single entry. On Cash, a W-2 pay run produces one journal entry dated the check date. Contractor and EOR entries follow the same basis, and settle differently depending on one more setting. Leave Cash / Bank Account empty to post the accrual and settle the payable through Accounts Payable. Set it, and the cash or bank account is credited when a contractor or EOR payable is settled on a later payment date. Changing the basis does not restate journal entries that already posted. Set it before the first sync and treat a later change as a decision that applies from that point forward.Map your Rippling data
After connecting, DualEntry shows you what needs mapping. Until every required mapping is filled in, the integration reports itself as not yet set up and no pay statement posts. Setup is complete when all of this is true: every Rippling legal entity maps to a DualEntry company, the payroll vendor is mapped, the pay statement item catalog for each enabled worker type is fully mapped, and every employee resolves to a company.Map legal entities and the payroll vendor
Map each Rippling legal entity to the DualEntry company its payroll should post to. This mapping decides where the journal entries land, and unlike some payroll connectors, Rippling supports more than one entity: each legal entity gets its own row and its own company. Map the payroll vendor to your DualEntry vendor record. That vendor is stamped on every payroll journal entry the integration writes, which is what makes the entries traceable back to the connector during close.Map pay statement items to GL accounts
Rippling pay data maps onto three fixed catalogs rather than a list of earning codes built from your own payroll configuration, so the mapping work is bounded and the same for every organization. The W-2 catalog holds fifteen items: regular pay, overtime, bonus, commission, reimbursement, employer payroll taxes, employer benefit contributions, payroll tax withholding, benefits withholding, 401(k) withholding, deductions, accrued payroll (net pay), employer payroll taxes payable, employer contributions payable, and garnishments payable. The contractor catalog holds contract labor and reimbursement. The EOR catalog holds a single EOR payroll expense item. Each item carries a fixed debit or credit direction, so you choose the account and the integration decides the side. Assign a GL account to every item in each catalog you enabled. At posting time, DualEntry routes each line from Rippling by its earning code, tax code and payer, deduction code, or garnishment code. Codes that do not match the catalog directly fall back to keyword classification:Map departments to classifications
Rippling departments are matched against the classification you named in settings and applied to the journal entry lines. This step is optional, and a department with no matching classification line is left off the entry rather than treated as an error.How pay runs become journal entries
Once setup is complete, each finalized pay run becomes journal entries grouped by worker type, not one entry per employee. W-2 payroll produces one set of entries per company and currency, so a pay run covering three legal entities produces three sets. Contractor payroll produces one journal entry per contractor, in that contractor’s own currency. EOR and PEO payroll produces one consolidated invoice-total entry for the whole run. Tax lines are consolidated by target account by default, which keeps an entry compact when several tax types share an account. Turn Consolidate Payroll Taxes off to get one line per tax type instead, for tax-type-level reporting. Every entry is checked for balance before it is written. Sub-cent drift across many workers is absorbed by a rounding adjustment line, tolerated at one cent per line with a five-cent floor. An entry that is out of balance by more than that is reported as an error rather than posted, so an unbalanced entry never reaches your ledger. Review the resulting entries in Journal Entries.Provision DualEntry users from Rippling
DualEntry reconciles Rippling’s provisioning group into DualEntry seats, so the people your Rippling admin provisions get DualEntry access without a separate invite. This is what the App Management package buys you, and the reason it is a prerequisite rather than a nice-to-have. DualEntry reads the members of the Rippling supergroup named PROVISIONING and reconciles them into DualEntry seats. A member who has no DualEntry user gets one created with the view-only role, which an admin can then raise. Members are matched by work email. Rippling then keeps the two in step. DualEntry receives webhooks when an employee is created, updated, deleted, hired, or terminated, and when a group is created, updated, or deleted, and re-runs the reconciliation shortly afterwards rather than waiting for the daily sync. Users the integration created are marked as Rippling-managed. An admin who changes one by hand in DualEntry marks it as a manual override, which the reconciliation then leaves alone. If the connection was authorized without the supergroups scope, provisioning is skipped quietly and the rest of the integration runs normally. The connection shows a warning to that effect, and reconnecting with the scope granted turns provisioning on. Signing in to DualEntry through Rippling is a separate capability, and an optional one. You can skip it when you connect the app, and the payroll integration works either way. Setting it up is not self-service, because it needs SAML details exchanged between the two sides: you configure Rippling, DualEntry configures its identity provider. Contact DualEntry to start that exchange rather than expecting the connect flow to cover it. Once SSO is configured for your email domain, people sign in at the Rippling sign-in page, which asks for a work email and sends them to Rippling to authenticate.Sync cadence and history
The integration syncs once a day. You can also run it by hand from the integration page when you need a pay run in the ledger sooner. On the first sync, DualEntry imports pay runs whose period ended within the last twelve months. Setting a cutoff date on the integration reaches further back than that, and the earlier of the two dates wins. Later syncs do less work. A PAID run whose journal entries all posted cleanly is skipped, so sync cost tracks new activity rather than the age of the connection. An APPROVED run is always re-checked, because it can still change before it is paid, and any run with a posting error is retried.Current limitations
The Rippling integration is in beta and has the following limitations today:- Setup takes longer than most connectors. The scope, IAM package, and mapping requirements mean the first connection is a working session rather than a few-minute install.
- No retroactive remapping. Journal entries that already posted do not change when you later remap a pay statement item or change the accounting basis. Resync the affected runs to apply new mappings.
- Departments match by name. A Rippling department whose name does not match a classification line is omitted from the entry, with no fallback and no auto-create.
- Read-only toward Rippling. DualEntry pulls payroll and worker data and does not push your chart of accounts, journal entries, or vendor records back.
- Only finalized runs sync. Draft and in-progress pay runs are invisible to DualEntry until they reach APPROVED or PAID.
