Understand encrypted Employee Record Centre storage
Understand the protected v1.3.0 payload, IV, authentication tag and hash used for authoritative employee records and change requests.
Exact navigation Admin Area → Human Resources → Employee Record Centre
Code-backed scope These instructions follow Human Resource Management v1.3.0. Use only controls visible to your permission level and confirm the saved record or audit entry after every action.
What you need before you start
- Access to Admin Area → Human Resources → Employee Record Centre.
- The Human Resource Management: View capability or administrator access.
- The correct employee, record, period or authorised evidence.
How to do it
- Use the normal Employee Record Centre forms; do not read or edit encrypted database values manually.
- Confirm the application encryption key and onboarding encryption dependency are available.
- Review Change History and Automation logs rather than exposing plaintext in technical logs.
What the module checks
- Authoritative payloads and controlled change payloads use the onboarding encryption service.
- Ciphertext, IV, authentication tag and payload hash are stored separately.
- Protected values are not intended for email or ordinary audit-message content.
What happens next
The module saves the permitted change and records the resulting status, version, delivery or synchronisation evidence. Reopen the relevant register and verify it.
Troubleshooting
- If the control is missing, confirm the required HRM permission and module version 1.3.0.
- If saving fails, correct the exact field or state named in the validation message.
- If an email/automation is missing, review the module delivery/audit log and host cron/mail settings.
HR data safety Restrict identity, right-to-work, payroll, bank, health, disciplinary and document information to authorised staff. Do not place protected values in free-text notes, email recipients or screenshots.
Browse connected topics: employee record centrehrm automation
