Access Governance & Approval · How-to guide

Apply least privilege in HRM

Use role, permission key, access level and scope together to minimise confidential HR access.

Audience: HR administrators, authorised managers and payroll staffPermission: Human Resource Management: SettingsModule v1.3.0
Exact navigation Admin Area → Human Resources → Access Governance
Code-backed scope These instructions follow Human Resource Management v1.3.0. Use only controls visible to your permission level and confirm the saved record or audit entry after every action.

What you need before you start

  • Access to Admin Area → Human Resources → Access Governance.
  • The Human Resource Management: Settings capability or administrator access.
  • The correct employee, record, period or evidence reference before making a change.

How to do it

  1. Open Admin Area → Human Resources → Access Governance.
  2. Select the exact employee, period, document, request, rule, queue item or record shown by the screen.
  3. Complete every required field and review the field descriptions below before submitting.
  4. Check the current status and any warning, duplicate, eligibility or permission message.
  5. Click Apply least privilege in HRM once and wait for the success or validation response.
  6. Return to the register and confirm the new status, reference, audit event and any generated file or downstream record.

Fields and options

Role profileDefines the named access role and its governance risk level.
Permission keyTargets a specific implemented HR area such as profiles, documents, payroll or audit.
Access level and scopeNone, read, write, approve or admin access can be limited to all HR, a team, department or specialist area.
Review statusAssignments and access reviews remain active, suspended, in progress, completed, rejected or closed as applicable.

What the module checks

  • Your assigned HRM capability must permit the action.
  • Required dates, amounts, references and reasons must pass server-side validation.
  • Approval, publishing, locking, voiding, withdrawal and deletion actions are allowed only from the states implemented by that workspace.
  • A success message is not a substitute for checking the register, audit log or generated file.

What happens next

The result remains available from Admin Area → Human Resources → Access Governance. Confirm its identifier, status, linked employee or period, dates and audit/activity record before relying on it operationally.

Troubleshooting

  • If the menu or action is missing, confirm the module is active and your HRM capability is assigned.
  • If validation fails, correct the exact field named in the message; do not bypass the rule in another workspace.
  • If a downstream email or automation does not run, check the related delivery/audit log and the host application cron or mail configuration.
HR data safety Restrict identity, right-to-work, payroll, bank, health, disciplinary and document information to authorised staff. Do not place protected values in free-text notes, email recipients or screenshots.
Browse connected topics: access governanceapproval