PROFILE & SECURITY
A Password Change Should Be Verified. Access Should Be Explicit.
An email OTP verifies password changes, and a full permissions matrix governs each role.
OVERVIEW
Verified Account Changes, Explicit Access
Verified changes, explicit rules for who sees what.
OTP-Verified Password Changes
An email OTP confirms the request before the password actually changes.
Role Permissions Matrix
A permissions matrix sets what each role can view and do.
SECURITY SNAPSHOT
This Month's Account Security, At A Glance
A sample view of what a running BizzField profile & security module looks like — illustrative data.
Permission Matrix Coverage By Role
Recent Security Events
HOW IT WORKS
How Profile & Security Protects Account Changes
From a password-change request to a verified update, and a role that governs what happens next.
Step 01
Employee Requests A Change
An employee starts a password change from their own profile, not through an admin ticket.- Self-service removes a routine request to IT or HR.
Step 02
Email OTP Verifies The Request
An email OTP confirms the request before the password actually changes.- Verification happens before the change takes effect, not after.
Step 03
Permissions Matrix Governs Access
A full permissions matrix defines what each role can view and do across the system.- The matrix is explicit per role, not inferred from ad hoc settings.
Step 04
Ties Into Role-Based Access Control
The permissions matrix is enforced by the same role-based access control that scopes data on the server.- Profile settings and data access follow the same role definitions.
WHO USES THIS
Built For Teams Where Access Is Reviewed
Verified account changes and a clear permissions matrix matter most where account security and access control are reviewed regularly.
BFSI
Strict access control over incentive-heavy compensation, with account changes verified.
Healthcare
Round-the-clock rosters and credential-linked documents, with access by role.
IT & ITES
Distributed teams and fast-moving org charts, where roles and access change often.
FAQ
Profile & Security — Questions We Get Asked
Profile & Security's permissions matrix is a Growth-plan feature, delivered alongside role-based access control and the rest of the Security & Access group.
Yes. An employee starts the change from their own profile, and an email OTP confirms the request before the password changes. No admin ticket is needed.
The OTP verifies that the request actually came from the account owner before the change takes effect, rather than accepting a password change on request alone.
The password does not change. Verification happens before the change takes effect, not after.
It defines what each role can view and do across the system — the same role definitions that role-based access control enforces server-side on every request.
Account-level events like a verified password change are the kind of real domain event that the Notifications module is built to surface to the right person.
AT A GLANCE
Profile & Security, By The Numbers
AUTOMATED CHECKS
Variance Checks Before Payroll Is Approved
Before a pay run is approved, BizzField compares the draft with the previous cycle and flags what looks wrong, so reviewers examine the exceptions instead of every line.
PRE-APPROVAL SCAN
Automated Variance Checks
Key Capabilities
- Each employee's draft pay compared with the prior month
- Pay movement above 20% flagged for review
- Duplicate leave and expense submissions detected
- Flags resolved from one HR queue before approval
Every draft run is compared with the previous cycle. Sharp pay movements, duplicate expense or leave submissions and timesheet conflicts are flagged for HR, who resolve each flag from a single queue while the run is still a draft.
See Automated Variance ChecksSECURITY & PRIVACY
Role-Scoped Access And Privacy By Design
Access is enforced on the server from the reporting hierarchy, and data handling is designed around the principles of India's DPDPA. The security page sets out what is and is not certified.
DATA PRIVACY
DPDPA-Informed Data Handling
Key Capabilities
- Consent logging for employee data
- Data export for the employee
- Deletion rights supported
Data handling is designed around the principles of India's Digital Personal Data Protection Act. That describes how data is handled; it is not a certification.
ACCESS CONTROL
Server-Scoped Access And Encrypted Storage
Key Capabilities
- Server-side role-based access, not just interface-level visibility
- Manager visibility limited to their reporting hierarchy
- AES-256 encryption at rest for employee records, bank details and document files
Role flags are not left to the front end. Access is scoped on the server, so a manager retrieves records only within their own reporting tree.
See HRMS SecurityROLLOUT TIMELINE
Getting Started with BizzField Profile & Security
A structured path from configuration to pilot testing and full launch, guided by our onboarding team.
Step 01
Employee Data Import & Hierarchy Setup
Model your reporting hierarchy, upload employee records securely, and map custom document types to BizzField's structure.- Upload employee master data from a CSV file
- Map reporting lines & org hierarchy
- Configure custom document categories
Step 02
Policy & Rule Configuration
Configure multi-level approvals, custom shift templates, statutory compliance ceilings, and salary revision workflows.- Set leave types, accruals & sandwich rules
- Define shift rosters & overtime rules
- Configure state-wise PT/LWF compliance
Step 03
Parallel Run & Validation
Verify payroll calculations, shift check-ins, and approval chains alongside your existing setup before fully cutting over.- Run a parallel payroll draft for one month
- Compare attendance records with your current process
- Confirm role-scoped access for all managers
Step 04
Full Launch & Team Training
Release employee self-service credentials, activate mobile check-in, and turn on pay run approvals and notifications.- Distribute self-service app credentials to all employees
- Publish payslips to employee self-service on pay date
- Switch on approval and leave notifications
KEEP EXPLORING
Related Pages
Other HRMS capabilities teams usually evaluate alongside this one.
Role-Based Access Control
Managers see only their reporting subtree, enforced server-side from the org hierarchy.
ExploreNotifications
Leave, timesheet and payroll events reach the right approver through the org hierarchy.
ExploreEmployee Management
One master record for lifecycle, profiles, documents and bulk import/export.
ExploreAttendance
Real-time check-in/out and monthly summaries, scoped so managers see only their team.
ExploreKeep Account Changes And Permissions Under Control
See how BizzField verifies password changes by email OTP and gives every role a clear permissions matrix.

