brillientaKnowledge base

Knowledge base / Brillienta HRMS / Security & data

Security

2 min read · Brillienta HRMS 2.1.0

Three independent layers. SharePoint is the security boundary: what the app hides is also closed over REST unless SharePoint closes it.

Your tenant, your data

All state in your site's HRMS lists; Graph calls delegated; email only via your Power Automate flow from your HR mailbox.

SharePoint layer

Four groups (Admins, HR Team, Asset Managers, Auditors), an Employee level without delete, and a security profile per list: payroll closed to HR, reviews/recruitment closed to employees, licence keys closed to employees, config read-only except admins.

App layer

Capability matrix, record-level change rules and visibility rules checked on every mutation, whatever screen made it.

Plan layer

Features outside the plan are off whatever settings say; saving preserves locked values so upgrades restore them. No active licence → read-only.

Employee privacy

Optional own-items-only enforced by SharePoint; staff keep full access via private-list levels; auditors keep read. Records HR saves for someone are given to that person.

Tamper-resistant mail

Flow sends only rows queued by staff, to staff, or self-mails; duplicate keys stop repeats; mailbox abuse is structurally impossible.

Operating notes

  • Apply security (wizard or Schema & security) after install; re-apply any time. Options: restrict other site groups, let everyone use the HRMS, let everyone read the site.
  • Give a role: Roles & access → add → Save (joins the group). Remove → Save (leaves the group, becomes Employee).
  • Locked out: any site collection administrator is Admin and can assign a new one.
  • Payslip/review not visible: privacy must be on and the directory email must match the Microsoft 365 account.
  • Audit: config rows record changed on/by; SharePoint version history; Setup log; Activity log for sync runs; Outbox delivery states.
Service account for emailRun the flow as a dedicated account in Admins/HR Team with Send As on the HR mailbox, so mail does not stop when a person leaves.
This article is about Brillienta HRMS.See the productView plansBook a demo
Still need help?Our team answers product questions by email, and we can walk you through it on a call.
Open in the full guideContact support