Just finished onboarding our second international subsidiary into Sprinto, and wow, the process is... different. Not bad, just very specific to their compliance-centric model. Coming from a background of more sales-focused CRMs, the emphasis here is squarely on control and audit trails, which makes sense.
I wanted to document the concrete steps we took, partly for my own notes and partly to see if others have smoother methods. Our parent company already had a mature Sprinto instance for GRC, so this was about extending that.
Our major steps were:
* **Pre-flight in the parent instance:** Created a separate "Organization" for the subsidiary. This is crucial—it's not just a new workspace. You have to map all the parent-level controls you want to inherit or modify.
* **User provisioning nightmare (the tricky bit):** We had to add the subsidiary's employees manually via CSV. Bulk upload worked, but assigning them to the correct new organization and control frameworks took a couple of tries. No slick invite flow like in HubSpot here—it's very admin-heavy.
* **Control Inheritance & Customization:** This is where Sprinto shines. We could clone our parent's InfoSec policy controls but had to de-scope the ones that didn't apply locally (like specific data residency rules). The UI for this is powerful but requires a solid understanding of your own compliance framework.
Biggest surprise? The API for this seems limited. A lot of this setup feels manual compared to automating sales team creation in Salesforce. I'm curious if anyone has automated subsidiary onboarding via their APIs or if it's all intended to be a deliberate, manual process for compliance reasons.
Integration with our HR system (BambooHR) for user sync worked flawlessly for the parent org, but we had to create a separate sync configuration for the subsidiary's employees. Took some back-and-forth with support to get the filters right.
Still looking for the perfect one