Skip to main content
BizzFieldHRMS

PROFILE & SECURITY

A Password Change Should Be Verified. Access Should Be Explicit.

An email OTP verifies password changes, and a full permissions matrix governs each role.

2Account Protections Covered
3Security & Access Modules In This Group

OVERVIEW

Verified Account Changes, Explicit Access

Verified changes, explicit rules for who sees what.

OTP-Verified Password Changes

An email OTP confirms the request before the password actually changes.

Role Permissions Matrix

A permissions matrix sets what each role can view and do.

SECURITY SNAPSHOT

This Month's Account Security, At A Glance

A sample view of what a running BizzField profile & security module looks like — illustrative data.

Password Changes
22
Each verified by email OTP
Permission Matrix Entries
38
Role × Module combinations
Failed OTP Attempts
3
Password not changed
Profile Update Requests
41
Self-service

Permission Matrix Coverage By Role

Admin8
Manager13
Employee17

Recent Security Events

Farhan Sheikh — password changed via OTP12 Jul
Ananya Gupta — permission matrix updated10 Jul

HOW IT WORKS

How Profile & Security Protects Account Changes

From a password-change request to a verified update, and a role that governs what happens next.

  1. Step 01

    Employee Requests A Change

    An employee starts a password change from their own profile, not through an admin ticket.
    • Self-service removes a routine request to IT or HR.
  2. Step 02

    Email OTP Verifies The Request

    An email OTP confirms the request before the password actually changes.
    • Verification happens before the change takes effect, not after.
  3. Step 03

    Permissions Matrix Governs Access

    A full permissions matrix defines what each role can view and do across the system.
    • The matrix is explicit per role, not inferred from ad hoc settings.
  4. Step 04

    Ties Into Role-Based Access Control

    The permissions matrix is enforced by the same role-based access control that scopes data on the server.
    • Profile settings and data access follow the same role definitions.

WHO USES THIS

Built For Teams Where Access Is Reviewed

Verified account changes and a clear permissions matrix matter most where account security and access control are reviewed regularly.

BFSI

Strict access control over incentive-heavy compensation, with account changes verified.

Healthcare

Round-the-clock rosters and credential-linked documents, with access by role.

IT & ITES

Distributed teams and fast-moving org charts, where roles and access change often.

FAQ

Profile & Security — Questions We Get Asked

Profile & Security's permissions matrix is a Growth-plan feature, delivered alongside role-based access control and the rest of the Security & Access group.

Yes. An employee starts the change from their own profile, and an email OTP confirms the request before the password changes. No admin ticket is needed.

The OTP verifies that the request actually came from the account owner before the change takes effect, rather than accepting a password change on request alone.

The password does not change. Verification happens before the change takes effect, not after.

It defines what each role can view and do across the system — the same role definitions that role-based access control enforces server-side on every request.

Account-level events like a verified password change are the kind of real domain event that the Notifications module is built to surface to the right person.

AT A GLANCE

Profile & Security, By The Numbers

2Related Modules Featured HereRole-Based Access Control, Notifications
3Security & Access Modules In This Groupthe full set this module belongs to

AUTOMATED CHECKS

Variance Checks Before Payroll Is Approved

Before a pay run is approved, BizzField compares the draft with the previous cycle and flags what looks wrong, so reviewers examine the exceptions instead of every line.

PRE-APPROVAL SCAN

Automated Variance Checks

Key Capabilities

  • Each employee's draft pay compared with the prior month
  • Pay movement above 20% flagged for review
  • Duplicate leave and expense submissions detected
  • Flags resolved from one HR queue before approval

Every draft run is compared with the previous cycle. Sharp pay movements, duplicate expense or leave submissions and timesheet conflicts are flagged for HR, who resolve each flag from a single queue while the run is still a draft.

See Automated Variance Checks

SECURITY & PRIVACY

Role-Scoped Access And Privacy By Design

Access is enforced on the server from the reporting hierarchy, and data handling is designed around the principles of India's DPDPA. The security page sets out what is and is not certified.

DATA PRIVACY

DPDPA-Informed Data Handling

Key Capabilities

  • Consent logging for employee data
  • Data export for the employee
  • Deletion rights supported

Data handling is designed around the principles of India's Digital Personal Data Protection Act. That describes how data is handled; it is not a certification.

Key Capabilities

  • Server-side role-based access, not just interface-level visibility
  • Manager visibility limited to their reporting hierarchy
  • AES-256 encryption at rest for employee records, bank details and document files

Role flags are not left to the front end. Access is scoped on the server, so a manager retrieves records only within their own reporting tree.

See HRMS Security

ROLLOUT TIMELINE

Getting Started with BizzField Profile & Security

A structured path from configuration to pilot testing and full launch, guided by our onboarding team.

  1. Step 01

    Employee Data Import & Hierarchy Setup

    Model your reporting hierarchy, upload employee records securely, and map custom document types to BizzField's structure.
    • Upload employee master data from a CSV file
    • Map reporting lines & org hierarchy
    • Configure custom document categories
  2. Step 02

    Policy & Rule Configuration

    Configure multi-level approvals, custom shift templates, statutory compliance ceilings, and salary revision workflows.
    • Set leave types, accruals & sandwich rules
    • Define shift rosters & overtime rules
    • Configure state-wise PT/LWF compliance
  3. Step 03

    Parallel Run & Validation

    Verify payroll calculations, shift check-ins, and approval chains alongside your existing setup before fully cutting over.
    • Run a parallel payroll draft for one month
    • Compare attendance records with your current process
    • Confirm role-scoped access for all managers
  4. Step 04

    Full Launch & Team Training

    Release employee self-service credentials, activate mobile check-in, and turn on pay run approvals and notifications.
    • Distribute self-service app credentials to all employees
    • Publish payslips to employee self-service on pay date
    • Switch on approval and leave notifications

KEEP EXPLORING

Related Pages

Other HRMS capabilities teams usually evaluate alongside this one.

Role-Based Access Control

Managers see only their reporting subtree, enforced server-side from the org hierarchy.

Explore

Notifications

Leave, timesheet and payroll events reach the right approver through the org hierarchy.

Explore

Employee Management

One master record for lifecycle, profiles, documents and bulk import/export.

Explore

Attendance

Real-time check-in/out and monthly summaries, scoped so managers see only their team.

Explore

Keep Account Changes And Permissions Under Control

See how BizzField verifies password changes by email OTP and gives every role a clear permissions matrix.