Knowledge base / Brillienta HRMS / Security & data
Security
Three independent layers. SharePoint is the security boundary: what the app hides is also closed over REST unless SharePoint closes it.
Your tenant, your data
All state in your site's HRMS lists; Graph calls delegated; email only via your Power Automate flow from your HR mailbox.
SharePoint layer
Four groups (Admins, HR Team, Asset Managers, Auditors), an Employee level without delete, and a security profile per list: payroll closed to HR, reviews/recruitment closed to employees, licence keys closed to employees, config read-only except admins.
App layer
Capability matrix, record-level change rules and visibility rules checked on every mutation, whatever screen made it.
Plan layer
Features outside the plan are off whatever settings say; saving preserves locked values so upgrades restore them. No active licence → read-only.
Employee privacy
Optional own-items-only enforced by SharePoint; staff keep full access via private-list levels; auditors keep read. Records HR saves for someone are given to that person.
Tamper-resistant mail
Flow sends only rows queued by staff, to staff, or self-mails; duplicate keys stop repeats; mailbox abuse is structurally impossible.
Operating notes
- Apply security (wizard or Schema & security) after install; re-apply any time. Options: restrict other site groups, let everyone use the HRMS, let everyone read the site.
- Give a role: Roles & access → add → Save (joins the group). Remove → Save (leaves the group, becomes Employee).
- Locked out: any site collection administrator is Admin and can assign a new one.
- Payslip/review not visible: privacy must be on and the directory email must match the Microsoft 365 account.
- Audit: config rows record changed on/by; SharePoint version history; Setup log; Activity log for sync runs; Outbox delivery states.