Skip to content
CogniYukti

Lifecycle

Every HR system stores a bank account. Almost none can say who has looked at it.

Which is the question that arrives after a payroll fraud, an employment tribunal or a data request — and the one where "our HR team is trustworthy" is not an answer, because it was never about trust.

The identity vault

Masked by default, and revealing one is an act with a reason attached.

Tax identifiers, bank accounts, passport and licence numbers are held encrypted and shown masked — the last four digits, the bank name, whether a number is on file at all. That is what the everyday screen shows, to everybody.

Seeing the actual value is a separate permission again, and it requires a typed reason and a stated purpose from a fixed list. The audit row is written in the same breath as the decrypt, so there is no sampling, no exception, and no way to look without leaving a trace.

Who looked, at what, and whyevery single time
  • Bank accountPayroll operator · Payroll run
    Bank file rejected this account — checking the digits
  • Tax identifierFinance · Statutory return
    Quarterly return flagged a mismatch against the register
  • Bank accountHR operations · Display
    Employee called to confirm which account salary goes to
The reason is typed by a person, and the purpose comes off a fixed list — because an auditor filters on the purpose and reads the reason. The default view shows the last four digits and nothing else.
Illustrative

The document vault

Types you define, review you can see, and a replacement that says what it replaced.

Documents belong to types your company sets up — with a category, whether one is required before somebody can start, whether there can be more than one, what file formats are accepted and how long it is kept.

Each document carries its own fingerprint, who uploaded it and whether that was the employee or an administrator, and a review state. Re-uploading supersedes rather than overwrites, so the chain of what replaced what survives. And an employee cannot be made active while any of their documents is unreviewed or rejected.

  • A review queue, oldest first

    Verifying documents is a job somebody does, not a thing they remember. Rejecting one pushes that person back into onboarding and reopens their form.

  • Purging leaves a tombstone

    The bytes go; the record that a document existed and was removed stays, because a vault that can be emptied silently is not a vault.

  • Employees see their own

    By type, with expiry flagged — which is also the cheapest way to find out that a licence lapsed last month.

  • Your own fields, properly typed

    Text with a length and a pattern, numbers with a range, dates with bounds, single-select with defined options. A definition, not a notes box.

Getting one document out

A bank needs a document. A bank does not want a login.

So a single document can be shared as a link that works without an account — issued for that one file, for a stated purpose, to a named recipient, and short-lived by default. It is single-use, it is revocable, and it records when it was first and last opened and from where.

Compare that to what companies actually do, which is email the PDF. A copy in somebody's mailbox is a copy you cannot withdraw, sent to an address you did not verify, that will still be there when that person changes jobs.

Questions about the boring thing

Which are all questions about access.

Who can see an employee's bank account or tax identifier?

Almost nobody, by default — the everyday view is masked. Revealing the real value needs its own permission, a stated purpose and a typed reason, and every reveal is recorded.

Can we find out who looked at somebody's details last March?

Yes. That is the point of the audit row: who, which field, which employee, the purpose they chose and the reason they wrote.

What stops a document being quietly replaced?

A re-upload supersedes rather than overwrites, and the chain shows what replaced what. Each document carries its own fingerprint.

How do we send a document to a bank or a verifier?

Issue a link for that one file, with the purpose recorded. No account on their side, short-lived, single-use, revocable — and you can see when it was opened.

Can an employee update their own address or bank details?

Not today. They can see them; changing them goes through HR. Worth knowing if your workforce moves around a lot.

Can somebody be made active with documents outstanding?

No. Anything unreviewed or rejected blocks it, which is deliberate — the gap otherwise shows up at the first payroll run.

Book a demo

Reveal a bank account, then go and find the trace.

The third step is the one your auditor will ask about, and the one most HR systems cannot answer at all.

  • Open an employee and see what the default view shows
  • Reveal the account — you will be asked why
  • Find that reveal in the audit, with your reason on it
  • Issue a share link for a document, then revoke it