Knowledge base / Brillienta HRMS / How it works
How it works
One SharePoint Framework web part runs in each user's browser on your HR site page. It reads and writes only your site's lists through SharePoint's own REST API, calls Microsoft Graph with delegated permissions for directory and device sync, and queues email in an Outbox list for a Power Automate flow to send.
Brillienta-HRMS web part
Runs in the user's browser on a SharePoint page, as the signed-in user. Fills the window with sidebar, top bar and apps.
SharePoint Online: your HR site
33 hidden lists with the prefix HRMS: employees, leave, tickets, tasks, recruitment, performance, learning, payroll, expenses, assets, announcements and more, plus Settings, Workspace, Outbox and Setup log.
Microsoft Graph (delegated)
Directory users, managers, photos, Teams presence and Intune devices — only with the signed-in admin's permissions, run from an admin's open page.
Power Automate email flow
Watches HRMS Outbox and sends each queued email from your HR mailbox, then marks it Sent, Rejected or Failed.
Key ideas
- No servers. Business rules run in the browser; several people can work at once with record-level saves and version-checked reference numbers (HD-1001, JOB-1001, PAY-1001).
- Background work without a server. Directory and device sync plus daily reminders run in an administrator's open page, with locks and run logs.
- Schema as code. Setup creates all lists and columns; each upgrade only adds. Your data and custom columns survive every release.
- Live updates. Other people's changes arrive within seconds (configurable 5 s – 2 min) without reloading; open Settings drafts merge instead of overwriting.
- Deep links. Hash routes (
#/leave/<id>,#/leave/new, tab links like#/performance/goals) open records, forms and tabs from email and bookmarks.
Microsoft Graph permissions
Needed only for directory sync, Teams presence and Intune device sync. A SharePoint or global administrator approves them once, in the SharePoint admin center under API access.
| Permission | Used for | If it is not approved |
|---|---|---|
| User.Read.All | Directory sync: users, managers, photos | No sync. The directory still works with people added by hand or CSV. |
| Presence.Read.All | Teams status badges on profiles | Status badges simply do not appear |
| DeviceManagementManagedDevices.Read.All | Intune device sync into the asset register (Enterprise) | No device sync; assets still managed by hand |