HR records
HR document management and employee records
HR document management holds a complete personnel file per employee while keeping each record visible only to the roles entitled to see it. DocumentMS separates contracts, right-to-work evidence, appraisals and disciplinary records, applies a different retention period to each, and warns before expiry dates pass.
What goes wrong without controlled employee records
An employee file is not one record with one sensitivity. It contains a contract that HR and payroll both need, a right-to-work document with a statutory expiry, an appraisal the line manager should see, and a grievance investigation that almost nobody should. Applying one permission level across the file either exposes the investigation or blocks payroll from the contract.
The second problem is expiry. Right-to-work documents, professional registrations, driving licences and visa permissions all lapse, and an employee working past an expiry is a compliance breach that occurred through inattention rather than decision. Nothing about a folder of PDFs surfaces that an expiry is approaching.
The third is retention, which in HR is unusually contentious because the same file contains records with periods ranging from months to decades. Recruitment records for unsuccessful candidates should be disposed of relatively quickly; occupational exposure records may be kept for forty years. A single retention period applied to "HR files" is wrong in both directions at once.
The symptoms you will recognise
- One folder per employee with uniform permissions, so a grievance file is visible to anyone who can see the contract
- Right-to-work or registration expiries tracked in a spreadsheet, or not at all
- Unsuccessful candidate CVs retained indefinitely because nobody owns their disposal
- A subject access request from a former employee requiring a canvass of managers
- Signed contract variations existing only as email attachments
- No record of who accessed a disciplinary file during an investigation
Configuration
Folder structure
Employee file
- Contract and variations
- Right to work and identity (restricted)
- Qualifications and registrations with expiry
- Payroll and benefits instructions
- Appraisal and development
Employee relations (restricted)
- Disciplinary records
- Grievance records
- Occupational health referrals and reports
- Settlement agreements
Recruitment
- Job descriptions and adverts
- Applications — appointed candidates
- Applications — unsuccessful candidates (short retention)
- Interview notes and scoring
Organisation-wide
- Policies requiring acknowledgement
- Training records
- Collective agreements
Configuration
Metadata that makes an employee file governable
| Field | Type | Mandatory | Why it exists |
|---|---|---|---|
| Employee | Text or user reference | Mandatory | The retrieval key for a subject access request, which is when the file is really tested. |
| Record class | Single-select | Mandatory | Drives both the retention rule and the permission set. This is the most consequential field on the page. |
| Sensitivity | Single-select (standard / restricted) | Mandatory | Separates the employee-relations material from the routine file at document level, not folder level. |
| Expiry date | Date | Optional | Mandatory for right-to-work, registrations and licences. Reported before it lapses, not after. |
| Employment start / end date | Date | Mandatory | End of employment is the retention trigger for most of the file, so it has to be a field rather than a lookup. |
| Entity or location | Single-select | Mandatory | Retention and employment law differ by jurisdiction; a multi-country employer needs this to apply the right rule. |
Configuration
Approval chain: a contract variation
Step 1: Capture the change
An e-form captures the employee, the change, the effective date and the new terms. The values become metadata rather than only appearing in the letter.
Step 2: Generate from the approved template
The variation letter is produced from the current approved template, so a superseded clause cannot reappear. The template version used is recorded.
Step 3: Approve
The line manager and, above a configured threshold or for a protected change, HR and finance approve. Approval is recorded against named individuals.
Step 4: Sign and file
A signature request goes to the employee, and the signed variation is filed in the employee file as a new version of the contractual record with its request history.
Configuration
Retention rule
What starts the clock
For most classes the trigger is the end of employment, which is why employment end date must be a real field. For recruitment records it is the date the appointment decision was made. For exposure records it is the date of last exposure, not the end of employment — those differ, and conflating them can shorten a forty-year period to seven.
Outcomes
What changes
- Employee-relations material is restricted at document level, so payroll access to a contract does not imply access to a grievance
- Expiring right-to-work documents and registrations appear on a report before they lapse
- Unsuccessful candidate records have an owner and a disposal date rather than accumulating indefinitely
- A subject access request from a former employee is answered from a search across the whole repository
- Contract variations exist as signed versions of the contractual record, not as email attachments
- Access to a disciplinary file during an investigation is recorded, which protects the investigator as much as the employee
FAQ
HR & employee records: common questions
Does this replace our HRIS?
No. The HRIS holds structured employee data — roles, salary, absence, org structure. DocumentMS holds the documents: contracts, right-to-work evidence, appraisals, employee-relations files. The integration point is the employee reference, and the reason to separate them is that document permissions need to be finer than HRIS record permissions usually allow.
How do we keep a grievance file away from a line manager who can see the contract?
By treating sensitivity as a document-level field rather than relying on folder structure alone. Employee-relations material sits in its own restricted branch with its own permission set, and per-document overrides are visible in the shared-access overview so an exception cannot be granted quietly.
Can we get alerted before a right-to-work document expires?
Expiry is an enforced metadata field on those document types and is reported by what lapses next, reinforced by scheduled workflow reminders. Working past an expiry is a breach that happens through inattention, so surfacing it early is the entire control.
What retention period should we apply to unsuccessful applications?
Short — commonly six to twelve months, long enough to defend a discrimination claim and no longer. The practical problem is not the period but the ownership: unsuccessful applications accumulate because nobody is tasked with disposing of them. Attaching the rule to the record class makes disposal a review task rather than a decision.
How do we handle an erasure request from a former employee?
Carefully, and with the conflict visible. Much of an employment record is retained under statutory or limitation-based obligations that survive an erasure request. DocumentMS surfaces the retention rule and any hold at the point of deletion, and records the decision and its reasoning — which is what you will need if the request is escalated to a regulator.
Dernière revue: 2026-09-01. See all seven use cases.