Dayzen HRMS + Project Management System — people ops and delivery in one product family.

See all modules
Dayzen

HRMS

Who should see what in an HR system

Published 9/21/2026 · Updated 9/21/2026 · Dayzen

Who should see what in an HR system follows the job, not the org chart screenshot. Employees should see their own transactions and limited profile fields. Managers should see operational data for their team, not everyone’s salary. HR and payroll should see what they must process, with sensitive identity and bank fields more tightly held. This is operational access design, not a certification claim.

Key takeaways

  • Default to least access; add visibility when a job requires it.
  • Managers need team attendance and leave, not company-wide compensation.
  • Identity documents and bank details need a smaller audience than directory fields.
  • Dayzen security copy describes architecture controls; this article covers people-data visibility questions.

Who should see what in an HR system follows the job, not the org-chart screenshot. Employees should see their own transactions and a limited set of profile fields. Managers should see operational data for their team — attendance, leave, who reports to them — not everyone’s salary. HR and payroll should see what they must process, with identity documents and bank details held more tightly than directory fields. This is operational access design. It is not a certification claim.

Dayzen’s security page describes architecture controls for the product. That page does not claim SOC 2, ISO, GDPR, or HIPAA certification, and neither does this article. Do not treat role design as a substitute for those programmes. The commercial product home is Dayzen HRMS (hire-to-exit people operations). Dayzen PMS means Project Management System, not performance management — access to a project tool is a different conversation.

Start from least privilege, then add what the job requires

Least privilege means a login begins with almost nothing and gains views because a named role needs them. Growing teams often invert this: “give HR admin to anyone in People Ops, and manager access to anyone with a team on paper.” Over-granting is how a resigned intern still downloads the directory, or a team lead browses another department’s CTC.

Write access is stricter than read access. Seeing a leave balance is not the same as editing joining date. Seeing a payslip is not the same as running payroll calculation. Seeing a profile is not the same as changing employee ID.

  1. List roles you actually have (employee, reporting manager, HR operations, payroll, IT admin for the tool, founder/exception).
  2. For each, list the smallest set of screens and fields required to finish their weekly work.
  3. Grant that. Add exceptions with an expiry or a ticket, not a permanent “full admin” because it was faster on day one.
  4. Remove access when the job changes — transfer, exit, or “was covering payroll in March.”

The employee record those roles read must still be one identity. Permissions on a messy duplicate directory only hide the mess from some people. Authority of fields lives in the employee system of record; this page is who may look at or change them.

Employee visibility

Employees need enough to do their own month without HR: their profile (as your RACI allows), their attendance, their leave, their payslips, assigned assets, assigned SOPs. They should not see other people’s pay, other people’s documents, or the full company bank file.

  • Usually yes: own punches, own leave applications and balances, own payslips after release, own assigned assets, own SOP acknowledgements, own directory fields you have classified as non-sensitive.
  • Usually no: others’ compensation, others’ PAN/Aadhaar/bank, company-wide headcount dumps, payroll run screens, audit logs of colleagues.
  • Request, don’t edit: identity, job, status, pay-critical fields — see who updates employee profiles.

Directory search (“who is the finance manager?”) is a business choice. Many teams allow name, department, work email, and extension, and hide personal mobile numbers. Be explicit. A public org photo book is not the same as an export of identity scans.

Manager visibility

Managers need the operational slice of their team so they can approve leave, chase regularisation, and see who is in. They rarely need compensation for people they do not pay, and they almost never need bank details or ID document images.

Team operational data Usually out of scope for a line manager
Pending leave and attendance exceptions for direct reports (and, if you choose, one level down) Salary structures, bonuses, and reimbursements for the whole company
Who reports to them now (org fields from employee management) Identity document vaults, bank account numbers, family details
Team roster and shift view if they own the roster Payroll calculation, statutory worksheets, other departments’ teams
Joiners and exits on their team, with dates Ability to silently rewrite another team’s reporting line

Matrix organisations need an extra sentence in the access note: dotted-line visibility might include leave awareness without approval rights, or the reverse. Do not grant “all managers see all attendance” unless the job is genuinely site operations for the whole floor. Convenience is not a role.

When someone transfers, manager access should follow the effective date of the reporting line — not remain on the old manager “because they still mentor.” Past approvals remain historically theirs; current queues should not.

HR operations visibility

HR generalists who run join-to-exit need broad read on employment fields: status, department, manager, documents required to complete a file, leave and attendance when they must chase a freeze. They may not all need payroll calculation or bank numbers.

Split HR if you can:

  • People operations: records, onboarding activation, lifecycle events, SOP assignment, asset coordination.
  • Payroll HR or finance payroll: pay components, LOP inputs, payslip release, liaison with filing (filing itself may sit outside the HRMS).
  • Recruitment: candidates until conversion; not automatically every employee’s salary history.

A five-person HR team in a growing company may wear all three hats. Still name the hats. Shared “super admin” because the instance was set up on a laptop is how access outlives the intern who configured it.

Collecting PAN, Aadhaar, and bank details should already be purpose-limited. Fewer people should see those fields than see designation. Operating guidance (not legal advice) is in collecting identity fields with a stated purpose.

Payroll visibility

Payroll needs inputs and outputs for the people in the pay run: attendance-derived LOP, leave without pay, pay structures they are allowed to process, and the ability to calculate and issue payslips. They do not automatically need recruitment interview notes or SOP draft editing.

If a consultant runs payroll, treat them as a named role with a contract and an off-boarding date, not as “email the Excel to whoever answered the phone.” Their access should match the month they are engaged for. Calculation remains distinct from statutory filing and bank payment; seeing calculated amounts is not permission to impersonate the company’s EPFO login.

IT and tool administrators

Someone must create logins, reset MFA, and configure roles. That person should not quietly become a second HR head with unrestricted people data unless that is an explicit dual-hat decision. Prefer: IT administers the tenant; HR administers employee master data; payroll administers pay runs.

Architecture and platform controls — encryption, hosting, session design, and similar — belong on Dayzen security. Use that page for how the product is built. Use this page for who inside your company should be allowed to open which people screens. Neither page is a SOC 2 report, an ISO certificate, or a GDPR/HIPAA attestation.

Sensitive fields versus directory fields

Group fields before you argue about roles:

  1. Directory: name, employee ID, department, designation, work email, reporting manager, work location.
  2. Operational time: attendance, leave, roster.
  3. Compensation: CTC, components, reimbursements, loans if you track them.
  4. Statutory and bank: PAN, Aadhaar where used, bank account, IFSC, family or nominee details if stored.
  5. Documents: scans and letters sitting on the file.

Each group can have a different audience. Directory might be wide. Compensation might be payroll plus a compensation partner. Documents might be HR only. If everything is in one “view employee” permission, you cannot do least privilege.

Joiner, mover, leaver — access as a lifecycle event

Grant employee self-service when the record is activated, not when an offer is signed if they should not yet see internal payslips. Change manager queues on the transfer effective date. On exit, remove manager and HR admin rights the same day you change employment status, even if FNF continues — FNF can be a restricted payroll/HR task, not leftover full access.

Contractors and interns often need a thinner employee role. Do not copy “full employee” because the template was handy.


A RACI you can actually maintain

Paste and fill:

Employees see self (transactions + agreed profile fields). Managers see team operational time and structure, not company compensation. HR ops sees employment records they process. Payroll sees pay runs they process. Statutory/bank fields are limited to [named roles]. Tool admin is [named person]. We review access at every transfer and exit. We do not treat this matrix as a security certification.

Review quarterly if you hire quickly. Compare actual admins in the tenant to the matrix. Orphan admin accounts are more common than clever attackers in a fifty-person company.

Related operating pages: what should not need an HR ticket, how hire-to-exit modules connect, and how to evaluate an HRMS (ask vendors to show role examples, not a logo wall of certificates they may not have). Labels in HRMS vs HRIS do not decide access; jobs do.

Keep security as the control summary. Keep employee management as the record. Keep this article as the visibility conversation those two do not replace.

See Dayzen in a walkthrough

Book a demo to evaluate Dayzen HRMS with your own processes.