Compliance — ChordHR
Compliance

Permission-based access. Multi-level approvals. Every decision permanently recorded.

Role-scoped permissions, multi-level approval chains, biometric hardware integration, and a complete audit trail — built into the same system your HR team already runs.

Custom roles available
Granular permission setup
No data leakage
ChordHR Compliance — roles, permissions and audit trail in one place

Access that's earned, not assumed.
Records that stay sealed.

Most HRMS platforms treat compliance as a permission toggle. ChordHR builds it into the data model " every query is filtered by what the caller is authorised to see, and every decision is permanently recorded.

Default-deny permissions
Access is withheld unless explicitly granted. Roles see only what they're authorised to see " no accidental exposure of salary data, performance ratings, or personal records.
Immutable approval records
Every approval, rejection, and escalation is timestamped and attributed " permanently. No editing, no overwriting, no 'I approved that verbally' without a trace.
One engine for every request type
Leave, OT, advances, shift swaps, resignations " all routed through the same configurable approval engine. No separate workflow tool, no parallel process in chat.
Biometric sync without the CSV
Punch data comes in through our own device agent in real time " no nightly export from the biometric device, no manual import, no mismatch between clock-in and attendance.

Four modules. One compliance layer.

Every module in the Compliance collection enforces the same access rules, writes to the same audit log, and connects to the same employee record.

ChordHR Roles and Permissions — granular access control
Roles & Permissions

Access that's granted, never assumed.

Every query in ChordHR is filtered by what the caller is authorised to see. Roles define visibility at the field level " not just the page level " so sensitive data never surfaces to the wrong person.

  • Schema-isolated, role-scoped access " every query filtered by authorisation
  • Custom role creation with field-level visibility control
  • Department and branch-scoped access for regional managers
  • Access changes take effect immediately with no cache window
Approval Workflows

One engine for every request. Every decision on record.

Leave, overtime, salary advances, resignations " all 12 request types pass through the same routing engine. Build sequential or parallel chains, set escalation rules, and know that every approval and rejection is permanently attributed.

  • One routing engine for all 12 request types
  • Multi-level chains " sequential or parallel
  • Escalation rules for overdue approvals
  • Immutable decision records " every approval and rejection timestamped and attributed, permanently
ChordHR Approval Workflows — every decision on record
ChordHR Biometric Integration — real-time punch data in attendance
Biometric Integration

Punch data in attendance. No CSV, no batch job.

ChordHR connects to biometric hardware through its own device agent. Clock-ins appear in attendance in real time, discrepancies are flagged automatically, and there's no manual export step between your device and your data.

  • Native sync via our own device agent " no CSV, no nightly batch job
  • Supports ZKTeco and compatible hardware
  • Punch data appears in attendance in real time
  • Discrepancy flagging for late punches and missed check-outs
Organisation Setup

Your structure, reflected exactly.

Model your legal entities, branches, departments, cost centres, and calendar cycles in ChordHR. The structure you define here drives role scoping, payroll mapping, and approval routing across every other module.

  • Legal entity, branch, and department hierarchy
  • Cost centre mapping
  • Probation, notice period, and contract type configuration
  • Calendar and shift cycle management
ChordHR Organisation Setup — legal entity, department and hierarchy configuration

Compliance gaps that surface
at the worst possible moment

These aren't theoretical risks. They're the situations that come up in every compliance conversation " usually when someone is leaving or an audit is scheduled.

Approval recorded and timestamped Role-based access — scoped to department Biometric data — real-time attendance sync Organisation hierarchy — updated automatically
Approval recorded & timestamped
Immutable — cannot be edited

An employee was approved for overtime. A shift was swapped. An advance was agreed in a WhatsApp message. When HR or finance needs the record, the paper trail is a screenshot of a chat.

ChordHR fix
Every request in ChordHR produces an immutable approval record " timestamped, attributed, and permanently stored. The conversation is still in WhatsApp. The decision is in the system.

A role was set up years ago with broad access. Nobody reviewed it. Now a mid-level manager can see the full salary register. It only becomes visible when they mention a number they weren't supposed to know.

ChordHR fix
ChordHR uses a default-deny model. Access is granted explicitly to each role, scoped to the data that role needs. The salary register is not visible unless the role specifically has that permission.

The device accumulates punches overnight. HR downloads the CSV at 9am, cleans it, and imports it into the HRMS. If they're busy, it waits. If they miss a day, attendance data is a day behind.

ChordHR fix
ChordHR's device agent syncs punch data in real time. The data is in attendance the moment it leaves the device " no CSV, no manual import, no 24-hour lag.

Roles changed six months ago. Someone left. A new team was created. The HRMS still reflects the old structure. New hires get the wrong access, old roles have permissions that shouldn't exist anymore.

ChordHR fix
When a role, department, or reporting line changes in ChordHR, permissions update immediately. There is no sync delay and no manual permission review needed after every restructure.

Compliance built in. Not bolted on.

Manual processes leave gaps. Generic HRMS tools add access control as an afterthought. ChordHR builds compliance into every layer of the system from the start.

"
Capability
Risky
Manual processes
Incomplete
Generic HRMS
Role-scoped access
Shared spreadsheets with no access control
Default-deny, field-level role scoping
Page-level only " not field-level
Approval audit trail
Email threads, no permanent record
Immutable " every decision timestamped and attributed
Partial " approvals logged but not rejections
Biometric hardware sync
Manual CSV export from device
Native agent " real-time, no CSV
Third-party middleware required
Unified request engine
Separate process per request type
All 12 types through one engine
Leave only " other types unsupported
Organisation hierarchy
Static org chart in a document
Live hierarchy driving scoping and routing
Supported but not connected to approvals
Real-time access changes
Manual updates with a time lag
Immediate " no cache window
Up to 24-hour propagation delay

Compliance is one collection. ChordHR is all of them.

sales@chordhr.com copied to clipboard