Key Concepts
Core Entities
Tenants
The platform supports multi-tenancy at the company level. Each company operates as an independent tenant with isolated data and configurations.
Users
Users are individuals with access to the platform. They can have multiple roles and permissions based on their responsibilities.
Employees
Employees are users with an employment relationship. All employee data including personal information, employment details, and documents are maintained in the system.
Companies
Organizations using the platform. Can have multiple locations, departments, and hierarchies.
Authentication & Authorization
JWT (JSON Web Tokens)
- Access tokens valid for 4 hours
- Refresh tokens valid for 7 days
- Stored in HTTP-only cookies for security
Roles
System-defined roles like Admin, Manager, HR, Employee. Roles determine baseline access levels.
Permissions
Granular permissions (38+ defined) control specific actions like viewing employees, editing leave, approving requests, etc.
RBAC (Role-Based Access Control)
Access control at three levels:
- Route-level: Entire pages restricted by permission
- Component-level: UI elements shown/hidden based on permissions
- Data-level: API filters data based on user access rights
Data Concepts
Master Data
Centralized configuration data used across the platform:
- Departments, designations, locations
- Skill categories and skills
- Leave types, policies
- Company holidays and work policies
Data Groups
Hierarchical organization of master data enabling flexible configuration and reporting.
Workflows
Multi-step approval processes for:
- Leave applications
- Separation requests
- Confirmation processes
- Performance reviews
Approval Chains
Configurable approval hierarchies with escalation rules and timeout handling.
Document Management
Document Categories
- Personal documents (ID proofs, address proof)
- Educational certificates
- Work experience letters
- Statutory documents (PAN, Aadhaar)
- Offer letters, contracts
- Policies and acknowledgments
Document Storage
All documents stored in AWS S3 with presigned URL access for security.
Organizational Structure
Reporting Hierarchy
Tree-based organizational structure with manager-employee relationships.
Departments & Teams
Logical groupings of employees for management and reporting.
Locations & Offices
Physical locations where employees work, supporting multi-location operations.
Employee Lifecycle Stages
- Candidate: Applicant in recruitment process
- Onboarding: Accepted candidate completing pre-joining formalities
- Active: Current employee
- Confirmation: Employee in probation period
- Separation: Employee in notice period or exit process
- Exited: Former employee
Performance Management Concepts
OKRs (Objectives and Key Results)
Goal-setting framework with objectives and measurable key results.
Performance Cycles
Time-bound periods for performance evaluation (quarterly, annual).
Performance Stages
Multi-stage review process including self-assessment, manager review, and calibration.
Rating Scales
Standardized rating systems for performance evaluation.
Leave & Attendance
Leave Types
Different categories of leave (casual, sick, earned, etc.) with separate policies.
Leave Balance
Accrual-based leave entitlements with carry-forward rules.
Attendance Policies
Work hours, flexible timing, and attendance tracking rules.
Integration Concepts
Webhooks
External systems send data to PeopleHub via webhook endpoints (e.g., Digio e-signature status).
API Keys
Authentication for external system access to PeopleHub APIs.
Data Sync
Scheduled jobs pull data from external systems (ATS, payroll) and update PeopleHub database.
Notification System
Notification Triggers
Events in the system that trigger notifications (leave approved, onboarding complete, etc.).
Notification Templates
Reusable email templates with dynamic data placeholders.
Notification Channels
Currently email via AWS SES, with future support for SMS and in-app notifications.
Security Concepts
PII (Personally Identifiable Information)
Sensitive employee data requiring special handling and encryption.
Encryption
- At rest: AWS KMS encryption for database and S3
- In transit: TLS 1.3 for all API communication
Audit Trails
Complete logging of all data changes with user, timestamp, and action details.
Related Documentation
- Overview - Platform capabilities
- Architecture Philosophy - Design decisions
- Authentication & Authorization - Detailed auth implementation
- Security Overview - Security approach