SecurityMarkdown

Who can get in, and what they can see

People sign in without passwords, using a one-time link, an emailed code or a passkey, and owners and administrators must use a second step. Each organisation's data is kept apart in the database, and eight roles decide what each person sees. Only people the employer has authorised can complete a right to work check.

Access control answers two questions: can this person get in, and once they are in, what can they see and do? This page explains how HRHive answers both.

The facts

  • There are no passwords to steal. People sign in with a one-time link, an emailed code or a passkey.
  • Owners and administrators must use a second step when they sign in, either a passkey or an authenticator-app code.
  • Sign-in, two-step verification and document signing requests are rate limited.
  • The app sends a strict Content Security Policy and cannot be embedded in other websites.
  • Each organisation's data is kept apart in the database by row-level security, which applies to every table that holds organisation data.
  • One person can belong to several organisations with a different role in each, and switch between them. An adviser can be invited into a client's organisation.
  • There are eight roles (owner, admin, HR, manager, payroll, compliance, employee and a read-only auditor), and sensitive fields such as bank, salary, National Insurance and medical details are shown only to the roles that need them.
  • Only people the employer has authorised can complete a right to work check. Others can see status, upload evidence, chase and assign the check.
  • Documents are downloaded through signed links that expire, not through public addresses.

Getting in

No passwords. There are no passwords to steal. People sign in with a one-time link, an emailed code or a passkey. A passkey uses your device's own screen lock instead of something you type.

A second step for owners and administrators. Owners and administrators must use a second step when they sign in, either a passkey or a code from an authenticator app.

Limits on repeated attempts. Sign-in, two-step verification and document signing requests are rate limited, which limits how many attempts can be made in a short time.

Protection in the browser. A Content Security Policy tells the browser where the app may load content from. HRHive sends a strict one, and the app cannot be embedded in other websites, so another site cannot show HRHive inside its own page.

Seeing your own organisation only

Each organisation's data is kept apart in the database by row-level security, which applies to every table that holds organisation data.

One person can belong to several organisations, with a different role in each, and switch between them. An adviser can be invited into a client's organisation and given a role there, like any other member.

Seeing only what your role allows

There are eight roles: owner, admin, HR, manager, payroll, compliance, employee and a read-only auditor. Sensitive fields such as bank, salary, National Insurance and medical details are shown only to the roles that need them.

Right to work checks have an extra rule. Only people the employer has authorised can complete a check. Others can see its status, upload evidence, chase it and assign it.

Opening documents

Documents are downloaded through signed links that expire, not through public addresses.

What it means for you

  • There is no HRHive password for anyone to reuse, forget or leak.
  • Owners and administrators always sign in with a second step.
  • Who sees sensitive details depends on each person's role.
  • An adviser can help move a right to work check along, but the check itself is completed by someone the employer has authorised.

What we do not claim

  • Custom roles. The eight roles are fixed. You cannot create your own.
  • Single sign-on. HRHive does not offer sign-in through your own identity provider.
  • A second step for everyone. The second step is required for owners and administrators. We do not claim it is required for every role.

Frequently asked questions

What can our accountant or HR adviser see?
What their role allows. One person can belong to several organisations with a different role in each, and an adviser can be invited into a client's organisation. Right to work checks can only be completed by people the employer has authorised.
Can another organisation using HRHive see our data?
Each organisation's data is kept apart in the database by row-level security, which applies to every table that holds organisation data.
What stops someone guessing a sign-in code?
Sign-in and two-step verification requests are rate limited, which limits how many attempts can be made in a short time. Owners and administrators must also use a second step when they sign in.

Change history

  1. First published.