Granular permissions
By group, by module, by document folder - and by scope group (team, site, department) to limit what a manager sees to their own scope.
View, edit and export rights set by group and by module, 2FA, SSO, login audit trail - every sensitive HR record stays where it belongs, in the hands of the people authorised to handle it.
By group, by module, by document folder - and by scope group (team, site, department) to limit what a manager sees to their own scope.
TOTP two-factor authentication on every account. SSO with Azure AD, OIDC or CTIE eAccess (Luxembourg) - three providers to choose from, included from your very first account.
Every login logged with timestamp, IP and authentication type. Sensitive changes (address, IBAN, banking details) are recorded with before and after values.
Enterprise-grade controls on every myHR account, even the smallest - no paid add-on, no "enterprise tier" to unlock.
Create the groups that match your organisation - HR Admin, HR Manager, Manager, Employee, External.
Leave, payroll, records, scheduling, training - each module has its own rights, assignable by group.
Differentiated access to document folders - a manager doesn't see medical records, payslips stay private.
A group can be limited to a team, a site or a department - the manager only sees their own scope.
Two-factor authentication via app (Google Authenticator, Authy, 1Password) - enabled per account or enforced company-wide.
Azure AD, generic OIDC, CTIE eAccess (Luxembourg) - three ready-made integrations, configurable without development.
Automatic logout after 8 hours of inactivity - configurable password policies (length, complexity, characters).
Full login history (date, time, IP, authentication type) and log of sensitive changes with before and after values.
Our security documentation, the DPA and our compliance posture - ready to forward to your legal team on request.