Access and security

Only the right people should see HR and payroll data

BaanHR separates access by role, protects payroll information, records important activity and requires human confirmation before sensitive actions take effect.

Data access settings

Access by role

Every role sees only what it needs

Keep payroll separate from general HR data

Require human confirmation for important actions

HR administrator

Employee data + documents

Full

Payroll team

Payroll + payslips

Protected

Manager

Team requests

Team only

Employee

Own information

Private

Activity history

Important actions stay available for review

Confirmed payroll export

Payroll team · 09:14

Approved leave request

Manager · 10:22

AI prepared a policy answer

Employee · 11:08

BaanHR demo consultation with HR implementation roadmap

Demo context

Next step is ready

The team sees which HR step should start first.

Trust starts before launch

A trusted HR system starts with clear access decisions

Before launch, the team should know who can see each type of data, who confirms sensitive actions and how payroll information stays protected.

Security principles

Security that HR can explain clearly to the business

BaanHR keeps security grounded in practical questions: who should see each type of data, who should approve an action and whether the team can review it later.

Access by responsibility

HR, managers, employees and executives see only the information their work requires.

Protected payroll data

Payroll records and payslips stay separate from general HR information.

Activity history

Important actions show who did what and when, so teams can review them later.

Human confirmation

Requests, approvals and important actions still require confirmation by an authorized person.

AI within clear limits

AI answers from permitted information and never approves an action on a person's behalf.

Team and branch boundaries

Managers and branches see only the information relevant to their own teams.

Sensitive-data scenarios

Access should stay clear in everyday situations

Not all HR data has the same sensitivity. Payroll, documents and important requests need boundaries the whole team can trust.

Managers see only their teams

Review requests, attendance and team status without opening company-wide employee data.

Employees see their own information

Access personal profiles, leave balances, request status and payslips according to permission.

Payroll teams see relevant records

Only authorized people can access payroll items, payslips and data prepared for payroll review.

People confirm important actions

AI can prepare the work, but an authorized person still confirms it

BaanHR security is not only about hiding data. It also makes sure the right person reviews and confirms an action before it affects real HR work.

01

Check access before showing data

The system and AI use each person's role and never reveal information beyond that role.

02

Summarize or prepare the action

AI can explain policy, prepare a request or summarize context so an authorized person can review it.

03

An authorized person confirms

Important actions take effect only after confirmation by HR, a manager or the payroll team.

Ready before launch

HR is easier to launch when access is clear from day one

Before launch, decide who can see employee data and payroll, who approves each action and who can review the history.

Set up before launch

HR, manager and employee roles

Team and branch boundaries

People allowed to view payroll and payslips

Keep visible after launch

Request status and approvers

History of important actions

Work prepared by AI and confirmed by a person

Want to define HR and payroll access before you launch?

Talk with BaanHR about how roles, managers, branches, payroll teams and AI should be limited to the right information in your company.