Cornerstone · Portal Health Check
The Cornerstone portal health check nobody schedules (until audit season)
Module activation, dormant users, orphaned learning, config drift, access – what a real portal audit covers, and why the answers are so hard to get from inside the platform.
By Robert Bucher · July 24, 2026 · 6 min read
Nobody schedules a Cornerstone OnDemand (CSOD) portal health check. It gets scheduled for you – by an auditor asking who still has admin rights, by a finance review asking why you are paying for modules nobody switched on, or by a works council asking exactly what data the system holds. By then it is a fire drill.
We have run these for a lot of portals, and the findings rhyme. Here is what a real health check looks at, and why the answers are so hard to get from inside the platform.
What actually needs checking
A portal drifts quietly. Every release, every reorg, every "just turn this on for the pilot" leaves a trace, and after a few years the gap between what the portal is and what anyone thinks it is gets wide. The things worth auditing:
- Module activation. Which modules and features are actually switched on, versus what you are licensed for and what anyone still uses. This is where the "we're paying for what?" conversations start.
- Dormant and inactive users. Accounts that have not logged in for months, users who left but were never deactivated, duplicates. Cornerstone deliberately does not hard-delete users via the API – deactivation is the offboarding path, for compliance reasons – which is correct, and which means dormant accounts pile up unless someone is watching.
- Orphaned and stale learning. Learning objects nobody is assigned to, versions left inactive, curricula pointing at retired content. Clutter that makes every catalogue and report noisier.
- Configuration drift. The gap between your configuration workbook and the live portal. Cornerstone ships three releases a year, and the well-run advice is to review and update your system documentation at every one – which almost nobody does, so the workbook and reality quietly diverge.
- Security roles and access. Who can see and do what, and whether that still matches who those people are. The question an auditor opens with.
- Data quality. Missing manager links, blank required fields, org units that do not resolve. The small gaps that break reports and org charts downstream.
Why it is hard to just see
Every one of those answers exists in your Cornerstone data. The trouble is that they live in different corners of the platform, none of them assembled into a single "state of the portal" view. Module activation is one screen, user status another, learning inventory another, security roles another. To get the whole picture you either click through all of them and take notes, or you export each and stitch them together – the same manual, limited, export-and-reconcile grind that eats analyst afternoons.
So the health check tends to happen the way fire drills happen: never, until it must, and then all at once under pressure. What is missing is not the data. It is a way to see the whole portal's state on one screen, on an ordinary Tuesday, before anyone is asking.
The value of the boring version
The boring, scheduled version is worth far more than the panicked one. A standing inventory of activation, users, learning, config, and access tells you three useful things at a glance: what you are paying for and not using, what has drifted from how it was set up, and what an auditor or works council would find before they find it. It turns portal governance from an event into a habit.
The honest bit
This is exactly what octo.taxi's Portal Health Check is: a single screen with a full inventory and module-activation map of your Cornerstone portal, built from your synced data – the data-backed companion to a consulting health check, without the consulting timeline. Because it runs on the same continuous sync as the rest of the platform, it is current every day, not just the day someone panicked.
And because the whole thing is your own data in a portable, EU-hosted home, the answers you need for an audit or a works-council conversation are a screen away instead of a project. If you want the mechanics of how that data gets out of Cornerstone in the first place, start with getting data out of Cornerstone.
Your data should move freely, from A to B, in style.
Sources. Cornerstone Bulk API – Quick Start (user reconcile / deactivation) · Cornerstone's thrice-yearly release cadence and configuration-documentation governance are standard administrator practice.
Robert Bucher is the founder of Octily, a creative studio dedicated to Cornerstone OnDemand, and the maker of octo.taxi. Octily has delivered 300+ Cornerstone projects for 100+ clients.
Your Cornerstone data, without the rate-limit wall
Dashboards, org chart, plain-language queries, and a REST API of your own – synced and kept current for you.
Get started →Related articles
-
Cornerstone · APIs
Getting data out of Cornerstone: REST, Reporting API, or Data Exporter?
Cornerstone has more ways out than almost any HR system – REST, RAPI, the Data Exporter, and Bulk. Here's the whole map, and a three-question way to pick.
-
Cornerstone · Dashboards & KPIs
The Cornerstone dashboards and KPIs that actually matter
The handful of HR and L&D numbers worth putting on one screen – and why Cornerstone makes assembling them current and board-ready harder than it should be.
-
Cornerstone · Reporting 2.0
Cornerstone Reporting 2.0: the limits nobody mentions until you hit one
The 200,000-row default, the one-million-record ceiling, the schedules that switch themselves off, and why Cornerstone itself is moving past the reporting screen.