Skip to main content

HR tech, IT & security

Identity, provisioning, learning standards and security terms your IT, HR and procurement teams will ask about.

35 terms

Admin console

The control center where administrators manage users, groups, permissions, content and reporting for an organization.

API

Application programming interface. A defined way for software systems to exchange data and trigger actions in each other.

Audit log

A record of who did what and when inside a system, used for security, compliance and troubleshooting.

CRM

Customer relationship management software that tracks accounts, contacts, opportunities and activity.

Data residency

Requirements about the geographic location where customer data is stored and processed.

Deprovisioning

Automatically removing a user's access when they leave the company or change roles.

GDPR

The EU's General Data Protection Regulation, which governs how the personal data of people in the EU is collected, used and protected.

HIPAA

The Health Insurance Portability and Accountability Act, a US law that sets standards for protecting health information.

HRIS

Human resources information system. The system of record for employee data such as role, department, manager and start date. Syncing it keeps training assignments and groups current automatically.

Identity provider (IdP)

The service that authenticates users and manages their identities across apps, such as Okta, Microsoft Entra ID or Google Workspace.

ISO 27001

An international standard for information security management systems.

LTI

Learning Tools Interoperability. A standard that lets external learning tools launch securely inside an LMS without a separate login.

OAuth

An open standard that lets one app access another app's data on a user's behalf without sharing the user's password.

OpenID Connect (OIDC)

An identity layer built on OAuth that lets apps verify who a user is through an identity provider.

Penetration test

An authorized simulated attack on a system to find security weaknesses before attackers do.

Provisioning

Automatically creating user accounts and assigning access when someone joins or changes roles.

SAML

Security Assertion Markup Language. An open standard that passes authentication from an identity provider to an app to enable single sign-on.

SCIM

System for Cross-domain Identity Management. An open standard for automatically provisioning, updating and deprovisioning users and groups between an identity provider and an app.

SCORM

Sharable Content Object Reference Model. A long-standing standard for packaging e-learning so it runs and reports completion inside any compliant LMS.

Security questionnaire

A set of questions a buyer's security team sends a vendor to assess risk before purchase. Common formats include SIG and CAIQ.

Single sign-on (SSO)

Letting users log in once with their company credentials to access multiple applications.

SOC 2

An audit framework that evaluates a service provider's controls for security, availability, processing integrity, confidentiality and privacy.

User groups

Collections of users, organized by team, region or role, used to assign content, permissions and reporting.

Webhook

An automated message one app sends another when an event happens, such as a completed assessment.

xAPI

Experience API, also called Tin Can. A standard for recording learning experiences anywhere, including outside an LMS, as statements like "Jane completed a roleplay."