User guide › Apps › HR records
The screens, and who can open them
HR records installs as one app with a People section in the sidebar. Most of it is open to anyone who has the app; three screens need the Manage employee records permission on top, and those three are exactly the ones that write.
| Screen | What it's for | Needs |
|---|---|---|
| Directory | Everyone, searchable, as cards or a table. | App access |
| My profile | The signed-in person's own record, with the parts they may correct themselves. | App access |
| HR console | Headcount, joiners and leavers, probations lapsing, documents expiring, birthdays. | App access |
| Org chart | The reporting line drawn from the manager field. | App access |
| An employee's profile | The 360 record: personal, job, employment history, documents, assets. | App access |
| Hire someone | The one form that creates a new starter. | Manage employee records |
| Add existing members | Turning the people already in your workspace into employee records. | Manage employee records |
| HR policy | Six questions that decide what BackOffice chases and what a new starter's journey contains. | Manage employee records |
Below those sit the plain record screens the app owns — Employees, Departments, Jobs, Positions, Probation, Documents and Assets. They are ordinary tables and forms, and they follow the ordinary record permissions, which is not the same thing as having the app. That distinction is the next section, and it is the one worth reading twice.
Two kinds of permission, and you usually need both
BackOffice has two separate access systems and there is no automatic bridge between them:
- App access — granted per person under Settings → Module Access. It decides which apps appear in the sidebar and which of the app's own actions are unlocked. HR records is restricted by default, so nobody but an admin sees it until you grant it.
- Record permissions — granted per entity, the same way as for any other table in your workspace. They decide who may read, create, change or delete rows of Employees, Documents, Assets and the rest. Background in Permissions & access.
Granting somebody the HR records app does not by itself let them read employee rows through the generic record machinery. The screens that work on app access alone — the directory, the console, My profile, the hire form, the activation triage and the HR policy — work because they are served by the app's own procedures, which do their own checking and hand back only what that person is entitled to see.
The org chart and the full 360 profile are built from the workspace's record data rather than from those procedures. A person who has the app but no read permission on the Employees entity gets an empty chart, and clicking a colleague in the directory shows Employee not found. If that's what you're seeing, the fix is a view grant on Employees — not more app access.
For an HR manager who should genuinely run the app, grant both: the HR records app (plus Manage employee records), and read access to the Employees, Departments, Jobs and Positions entities. For an ordinary employee who only needs their own profile, grant the app and nothing else — My profile works with no record permissions at all.
Three ways a person gets an employee record
Which one applies matters, because two of them start an onboarding journey and one of them never does. The record remembers which it was.
| Origin | How it happens | Onboards? |
|---|---|---|
| HR hire | Somebody filled in the hire form. | Yes — the full journey |
| Joined without HR | A member joined the workspace and had no employee record, so a draft one was raised for them. | Yes |
| Backfilled | Created on the Add existing members screen, for people who were already here when you switched HR records on. | Never |
Hiring someone
People → Hire someone. One form; the order the server does things in is the point of the screen.
- Fill in what you know Full name is the only required field. Work email, Position, Department, Reports to, Work type, Start date and Salary are all optional — HR data arrives late and a half-filled record is better than no record.
- Pick the seat, not the job title Choosing a Position fills the Department in for you and shows the job behind that seat. The job is what decides which onboarding journey they get. A seat somebody already holds is marked already held — the hire still works, because a handover legitimately overlaps, and the current holder is left alone.
- Decide whether they sign in Invite them to sign in is on by default and needs a work email. Turn it off for people who never sign in — retail, warehouse and kitchen staff are employees with contracts and documents and no login.
- Press Hire The employee record is created first, from what you typed. Then the employment record that carries the salary, then the position is marked filled, then the onboarding journey, and only then the invite.
Because the record exists before the person does, a journey step dated before day one works — that's how "send the contract three days before they start" is possible. When the invite is eventually accepted, the new account links to that same record; it never creates a second one. The form also refuses a second record for an email address that already has one.
Salary is stored as a dated employment change rather than a field on the employee, so a later raise doesn't overwrite the hire figure and "what were they on in March" keeps one answer.
Switching HR records on at a company that already has staff
People → Add existing members is the screen you use once. It lists every member of your workspace who has an account but no employee record, and makes you say what each one is.
- Read the proposals Obvious staff are pre-selected as Staff. Anything that looks like an integration or a robot is pre-selected as Not staff and carries a Looks automated badge, so the careless path is the safe one.
- Correct the exceptions Per person, choose Staff, External (agency / third party), Former staff or Not staff. All are staff and None are staff set every row at once if that's faster.
- Note why, then apply The optional note is stored against the people you exclude. The button counts what you're about to do — Create N · exclude M.
Records created here get the member link, the person's name and their work address — and deliberately no hire date, because nobody knows when these people started and an invented one becomes a work anniversary. A Former staff row is created as Terminated rather than skipped, so your turnover history starts from day one instead of from today.
Nothing created on this screen raises an onboarding journey: no contract goes out for signature, no laptop handover is raised, no manager gets day-one tasks for someone they have worked with for three years. That is enforced twice over on the server, not by remembering to untick something. Somebody you add later through the hire form onboards normally.
Not staff is remembered. Those members drop off this list permanently and are never proposed again — including if they sign in again later. It is reversible: they appear under Marked as not staff with an Undo button.
The directory
People → Directory is the app's front door and the surface that works for the most people, because it carries no personal data by construction — work contact details only.
- Search matches name, job title, department, work email and employee code.
- Filter by department and by employment status.
- Card view and Table view are the two icon buttons on the right of the filter bar. The table shows Name, Job title, Department, Status, Work email and Phone.
- Badges tell you two different things. The status badge is employment — Active, Probation, Intern, On leave, Notice period, Terminated. Invite pending and No account are about their workspace login. Somebody can be employment-Active and have never opened their invite; that used to be invisible.
- Missing details appears as a filter and as an amber badge only once you have answered the HR policy questionnaire. Nothing is missing until you've said what you want.
With the Onboarding app installed and the right permission, each row also gets a tick box and a Start a journey for selected button — Onboarding covers what happens next. Select all respects whatever filters are on, so "everyone in Retail who is still missing details" is three clicks.
An employee's profile
Clicking anyone opens their 360 profile: a header with photo, name, employment status and contact line, then a tab strip. Which tabs you see depends on which apps are installed.
| Tab | What's on it |
|---|---|
| Overview | Personal details, contact, bank details, emergency contact, notes. The sensitive rows are filled in or show a padlock and Withheld. |
| Job & org | Position → job → grade, work type, hire and termination dates, department, who they report to, and their direct reports. |
| Employment | The change timeline — hire, promotion, transfer, salary change, termination — plus probation, internship and fixed-term periods with their outcome. |
| Documents | The per-employee vault, soonest expiry first, with Add document. |
| Assets | Equipment currently out, and what has been returned. |
| Time | Contributed by Leave & attendance when it's installed. |
| Onboarding | Contributed by Onboarding when it's installed. |
Direct reports are derived, never typed. They come from the same Reports to field the org chart walks, so a manager who is missing someone from their team has an employee whose Reports to hasn't been set.
Chasing an invite that never arrived
An employee with no linked workspace account carries a No workspace account badge in the header. If an invite is outstanding, admins get Copy invite link and Resend invite right there, plus a durable line reading Email sent 2m ago or Email never sent — the thing you actually want after refreshing to check the mail went. Resend is disabled with a reason when your workspace has no email sender configured, so it can never silently do nothing.
Documents and expiry
Add document opens the normal record form with the employee already filled in — the same write path as the Documents table, not a second one, so it obeys the same permissions. A document can carry a type, a number, an issuer, issued and expiry dates and a Confidential flag. Expiry is colour-coded in the list: red once past, amber inside 30 days.
A daily check chases what's about to lapse, and notifies the people who can act on it:
- Probation, internship and fixed-term periods — the evaluator and the employee's manager, by default 7 days before the end date. Extending a period genuinely moves the deadline rather than leaving two competing dates. This is the reminder that costs money to miss: in most places an un-actioned probation converts to permanent employment by default.
- Documents nearing expiry — both the employee (renew it) and their manager (chase it), by default 30 days out. The person holding the document usually isn't the person who has to act.
Assets
The Assets tab is a read view. Issuing and returning equipment happen through the app's own actions, gated on Issue & return assets, because both have to be atomic: an asset that isn't in stock can't be issued, and two people can't be handed the same laptop by clicking at the same time. The condition equipment comes back in becomes the asset's condition.
What an employee sees of their own record
People → My profile resolves the signed-in person to their own employee record and shows it in full — including the fields that are withheld from everyone else. Nobody needs a permission to read their own bank account.
The page is split deliberately. One card is theirs to change:
| Yours to edit | Read-only on this page |
|---|---|
| Phone · Personal email · Address · Emergency contact (contact, phone, relation) · Bank · Bank account (IBAN) · Birth date | Gender · Marital status · Personal ID (TIN) · Job · Department · Reports to · Work type · Hire date · Work email · employment status |
The editable list is the server's, not the page's. A save that named the employment status, the manager or the position is silently ignored — self-service is not a way to promote yourself or un-terminate yourself. Every self-update is written to the audit log as a list of which fields changed, never the new values.
If the HR policy asks for details this person can supply, those fields are pulled to the front of the form and marked Needed. Anything the policy wants that only HR can write — a hire date, a personal ID — is named separately as HR fills these in, because "fill this in" is useless advice for a field they can't touch.
Somebody whose account isn't linked to an employee record sees You don't have an employee record yet instead.
Giving someone access to their own profile
- Make sure they have a workspace account Either they were invited from the hire form, or they were already a member — see Members, teams & seats.
- Make sure the account is linked to their record An accepted invite links itself, matching on the invited email address. For anyone else, the link is the System member field on their employee record — that field is the join between HR, attendance and onboarding, so it has to be right. The No workspace account badge on the profile is how you spot a missing link.
- Grant them the HR records app Settings → Module Access. Plain access is enough — no capability, and no record permissions.
An employee who only ever needs the HR apps can be put on a restricted seat covering exactly those, plus the personal baseline — signing in, their own profile, notifications, language and theme. A restricted seat opens straight onto their own profile, answers Not part of your access anywhere outside it rather than a permission error, and cannot be granted anything the seat doesn't cover. Seats are covered in Members, teams & seats.
Sensitive fields
The most sensitive fields on an employee record are stripped by the server before the data ever reaches the browser — they are not hidden by the page. Through the ordinary record screens, tables, record drawers and CSV exports, these are admin-only:
| Withheld | Where |
|---|---|
| Personal ID (TIN) · Birth date · Personal email · Address | Employees |
| Bank · Bank account (IBAN) | Employees |
| Salary | Employment records |
| Salary band (min and max) | Jobs |
| File · Number · Notes | Documents flagged Confidential — title, type and expiry stay visible, so the vault list and the expiry chase still work |
Two grantable permissions re-open that data on this app's own screens: See compensation (salary, salary bands, bank details) and See personal data (personal ID, date of birth, personal email, home address). Every time someone reveals another person's data this way, an entry is written to the audit log. Reading your own record is not an event and is never gated.
Someone holding See compensation sees salaries on the employee profile and on My profile — and not in the generic Employees table, the record drawer or a CSV export, where the admins-only floor still applies. That floor is deliberate: it is what stops a scheduled report or an export quietly carrying every employee's bank account to a recipient list.
A consequence worth knowing: because a view denial implies an edit denial, only admins can write those fields through the ordinary record screens. Employees supply their own bank details and birth date through My profile instead. A non-admin saving an employee record they can partly see does not wipe the hidden fields — the stored values survive the save, and a value smuggled into a hidden field is ignored rather than stored.
The org chart
People → Org chart is a view of a structure you already maintain, never a second one. Its edges are the Reports to field on each employee, so changing someone's manager moves them here and there is nothing to keep in sync.
- Reporting line and Departments are the two modes — the second draws the department tree from each department's parent instead.
- Search dims everyone who doesn't match and opens the branches leading to each hit, so a match deep in a collapsed branch is still reachable.
- Each card with reports has a collapse toggle showing the child count. Anyone with no manager is a root, and several roots are normal.
- Print prints the chart. Wide charts scroll sideways rather than being squashed.
Nothing stops you saving A reports to B reports to A. When that happens the page shows an amber banner counting the records that loop and draws them as roots so the rest of the chart still renders. Fix the Reports to field on one of them and the banner goes.
The HR console
People → HR console is the daily read. Every tile and every row clicks through to the records behind it, so the number and the list can't disagree.
- Tiles — Missing details, Headcount, New this month, Leaving this month, Probation ending, Documents expiring, Open positions, Assets out, Birthdays. Headcount excludes terminated people.
- Breakdowns — by department, by status and by work type, as bars.
- Lists — Joined this month, Leaving this month, Probation ending soon, Documents expiring soon, Unfilled positions, Assets currently out, Upcoming birthdays and Work anniversaries.
- Missing details only appears once the HR policy has been answered. With no policy, the console says so and links to the questionnaire rather than reporting a reassuring "0 incomplete" against a standard nobody set.
Birthdays are matched on day and month, so a 1990 birthday still lands in this year's window. For anyone without See personal data the year is withheld and the page says so — the console needs the day; the year is the part that identifies a person.
Admins get a Schedule monthly report button, which creates a monthly headcount and turnover report on the normal reports engine, delivered to you. Add more recipients in Reports afterwards. Pressing it twice reuses what's already there rather than stacking duplicates.
HR policy
People → HR policy is a questionnaire, not a required-fields matrix. It asks about outcomes you have an opinion about, and works out the rest — which details to chase, what a new starter's journey contains, and which apps you need.
| Question | What answering it does |
|---|---|
| Do you mark employees' birthdays? | Makes Birth date a detail to chase. |
| Do you mark work anniversaries? | Makes Hire date a detail to chase. |
| How are employment contracts signed? | Picks the contract step every new starter gets. Only the electronic answer needs the e-signature app; answering "on paper" never forces an install. |
| Do you issue company equipment? | Yes adds the handover step to onboarding; no removes it. |
| Do you pay salaries from here? | Makes Bank account (IBAN) a detail to chase. |
| Should employees be registered with rs.ge automatically? | Georgia only. Needs the rs.ge app installed and signed in, and adds the identity fields rs.ge checks. |
Where you employ people sits above the questions and decides which of them apply. Changing it clears the answers it hides rather than merely hiding them, so moving off Georgia actually stops the rs.ge requirement instead of leaving it switched on where nobody can see the switch.
A missing detail is shown, never enforced: as an amber badge in the directory, a banner on the profile and on My profile, and a tile on the console. Creating an employee with every one of them blank still succeeds — which is the point, because the people most likely to be missing data are the ones who were here before HR records was.
Each requirement travels with its reason — Personal ID (TIN) — because you sync employees to rs.ge — with a link back to the answer that decided it, rather than a red asterisk nobody can argue with. Your answers also become a journey template that stacks on top of whatever you have built in the journey builder; that template is maintained from this screen and is read-only in the builder, because it is rebuilt from these answers every time you save.
If an answer needs an app you don't have, the screen offers the install through the normal path — so the admin check and your plan's entitlements apply exactly as they would from the Apps page.
Who can do what
All four are granted per person or per role under Settings → Module Access. Admins pass everything.
| Permission | Unlocks |
|---|---|
| (app access) | The directory, My profile, the HR console, the org chart and an employee's profile. |
| Manage employee records | Hire someone, Add existing members, HR policy. |
| Issue & return assets | Handing equipment to employees and taking it back. |
| See compensation | Salary, salary bands and bank details on other people's records, on this app's screens. Every reveal is audited. |
| See personal data | Personal ID, date of birth, personal email and home address on other people's records, on this app's screens. Every reveal is audited. |
Whoever holds Manage employee records is also who the Onboarding app treats as "HR" when a journey step is assigned to the HR function rather than to a named person. If nobody holds it, that falls back to workspace admins. Terminated people are skipped either way — the whole point of the rule is that it survives the HR manager leaving.
When something goes wrong
| What you see | What it means |
|---|---|
| No access to this app | They haven't been granted HR records. Settings → Module Access. |
| A manager can't see their team | Three separate causes, in order of likelihood: nobody set Reports to on those employees (direct reports and the org chart are both derived from it); the manager has the app but no read permission on the Employees entity, so the profile and chart come back empty; or they're on a restricted seat that doesn't cover this app. |
| Employee not found | Either the record was deleted, or the person opening it has no read permission on Employees. The directory works without one; the full profile doesn't. |
| Nothing to chart yet | No employees are visible to you, or nobody has a manager set. Set Reports to and the chart draws itself. |
| You don't have an employee record yet | Their account isn't linked to one. Find them in the directory and set the System member field on their record, or add them through Add existing members. |
| No account / Invite pending badge | An employment fact and a login fact are different things. Invite pending means they were invited and haven't accepted; No account means there's no login and no outstanding invite. Both are fixed from the profile header, not from the employment status. |
| A padlock and Withheld on a field | The server didn't send you that value. Grant See compensation or See personal data — and note those only apply on this app's screens. |
| An employee has two records | Shouldn't happen through the supported paths — the hire form refuses a duplicate email and an accepted invite links to the existing row. Two records usually means somebody added a second one by hand in the Employees table. |
What HR records feeds
- Leave & attendance reads hire date, department and manager straight from the employee record, so there is one answer to "how much leave do they have" — Leave & attendance.
- Onboarding & offboarding raises a journey the moment an employee record is created, and an offboarding journey when someone moves to Notice period or Terminated — Onboarding.
- Scheduling & bookings uses the same people as bookable resources — Scheduling & bookings.
- The whole arc, from an open seat to a leaver's last day, is in Employee lifecycle.