SecurityMarkdown
Who can get in, and what they can see
People sign in without passwords, using a one-time link, an emailed code or a passkey, and owners and administrators must use a second step. Each organisation's data is kept apart in the database, and eight roles decide what each person sees. Only people the employer has authorised can complete a right to work check.
Access control answers two questions: can this person get in, and once they are in, what can they see and do? This page explains how HRHive answers both.
The facts
Getting in
No passwords. There are no passwords to steal. People sign in with a one-time link, an emailed code or a passkey. A passkey uses your device's own screen lock instead of something you type.
A second step for owners and administrators. Owners and administrators must use a second step when they sign in, either a passkey or a code from an authenticator app.
Limits on repeated attempts. Sign-in, two-step verification and document signing requests are rate limited, which limits how many attempts can be made in a short time.
Protection in the browser. A Content Security Policy tells the browser where the app may load content from. HRHive sends a strict one, and the app cannot be embedded in other websites, so another site cannot show HRHive inside its own page.
Seeing your own organisation only
Each organisation's data is kept apart in the database by row-level security, which applies to every table that holds organisation data.
One person can belong to several organisations, with a different role in each, and switch between them. An adviser can be invited into a client's organisation and given a role there, like any other member.
Seeing only what your role allows
There are eight roles: owner, admin, HR, manager, payroll, compliance, employee and a read-only auditor. Sensitive fields such as bank, salary, National Insurance and medical details are shown only to the roles that need them.
Right to work checks have an extra rule. Only people the employer has authorised can complete a check. Others can see its status, upload evidence, chase it and assign it.
Opening documents
Documents are downloaded through signed links that expire, not through public addresses.
What it means for you
- There is no HRHive password for anyone to reuse, forget or leak.
- Owners and administrators always sign in with a second step.
- Who sees sensitive details depends on each person's role.
- An adviser can help move a right to work check along, but the check itself is completed by someone the employer has authorised.
What we do not claim
- Custom roles. The eight roles are fixed. You cannot create your own.
- Single sign-on. HRHive does not offer sign-in through your own identity provider.
- A second step for everyone. The second step is required for owners and administrators. We do not claim it is required for every role.
Frequently asked questions
What can our accountant or HR adviser see?
Can another organisation using HRHive see our data?
What stops someone guessing a sign-in code?
Change history
- First published.