HR Modules & Core Functionality
This document covers all core HR modules and authentication/authorization in PeopleHub.
Authentication & Authorization
Authentication
JWT-Based Authentication:
Login Flow:
- User submits email + password
- API validates credentials (bcrypt hash comparison)
- Generate access token (4 hours) + refresh token (7 days)
- Tokens sent as HTTP-only cookies
- User redirected to dashboard
Token Types:
- Access Token: Short-lived (4 hours), used for API requests
- Refresh Token: Long-lived (7 days), used to get new access token
Token Refresh Flow:
- Access token expires → Frontend detects 401 error
- Automatically calls
/api/auth/refreshwith refresh token - New access token issued → Original request retried
Logout: Cookies cleared, tokens invalidated server-side, redirect to login page
Password Security:
- Hashing: bcrypt with 10 rounds
- Reset: Email-based password reset with temporary token
- Policy: Minimum 8 characters (can be configured)
Authorization (RBAC)
System-defined Roles:
- Super Admin: Full system access
- HR Admin: HR operations
- Manager: Team management
- Employee: Self-service access
- Support: Helpdesk access
- Vendor: Limited external access
Users can have multiple roles.
Permissions (38+ granular permissions):
- Employee:
VIEW_EMPLOYEES,EDIT_EMPLOYEES,DELETE_EMPLOYEES - Leave:
VIEW_LEAVE,APPLY_LEAVE,APPROVE_LEAVE - Performance:
VIEW_PERFORMANCE,EDIT_OKR,APPROVE_PERFORMANCE - Settings:
MANAGE_USERS,MANAGE_ROLES,MANAGE_MASTER_DATA
Access Control Levels:
- Route-Level Protection: Entire pages restricted by permission
- Component-Level Protection: UI elements shown/hidden based on permissions
- Data-Level Filtering: API returns data based on user's organizational hierarchy
- Employees see only own data
- Managers see team data
- HR sees all data
Security Features:
- HTTP-Only Cookies (prevents XSS)
- SameSite Cookies (prevents CSRF)
- Token Expiry (short-lived access tokens)
- IP Logging for audit
HR Modules
Employee Management
Purpose: Maintain comprehensive employee records and organizational structure.
Features:
- Personal information (name, DOB, contact, address)
- Employment details (employee ID, designation, department, manager)
- Banking and statutory information (PAN, Aadhaar, UAN, bank account)
- Education and work experience
- Skills and certifications
- Family and dependents
- Document management (ID proofs, certificates)
- Organizational hierarchy and reporting structure
Key Tables: user_master, user_employment_details, employee documents
Recruitment
Purpose: End-to-end recruitment process from job posting to candidate selection.
Features:
- Job requisition creation and approval
- Candidate sourcing and tracking
- Interview scheduling and feedback
- Referral program management
- Offer letter generation
- Integration with external ATS (TalentRecruit - planned)
Workflow: Job creation → Candidates apply → Screening → Interviews → Selection → Offer
Key Tables: demand_master, demand_skill, employee_demand_status
Candidate Onboarding
Purpose: Pre-joining formalities for selected candidates before Day 1.
Features:
- Personal information collection (isolated portal for candidates)
- Document uploads (ID proofs, education certificates, experience letters)
- Background verification (BGV) details submission
- Policy review and e-signature (via Digio)
- Pre-joining task tracking (IT, Admin)
- Data migration to employee record on Day 1
Isolation: Separate frontend and API for security
Key Tables: user_onboarding, onboarding-related tables
Confirmation Management
Purpose: Employee confirmation after probation period.
Features:
- Probation period tracking (typically 3-6 months)
- Manager recommendation submission
- HR review and approval
- Confirmation letter generation
- Status update to "Confirmed"
Workflow: Probation end date → Manager review → HR approval → Confirmation
Key Tables: confirmation_policy_master, confirmation requests
Leave Management
Purpose: Leave application, approval, and balance tracking.
Features:
- Multiple leave types (casual, sick, earned, etc.)
- Leave application with date selection
- Multi-level approval workflows
- Leave balance tracking with accrual rules
- Leave policy configuration (per company/department)
- Calendar view of team leaves
- Leave encashment (planned)
Workflow: Employee applies → Manager approves → HR final approval (if configured)
Key Tables: Leave applications, leave balances, leave policies
Attendance Tracking
Purpose: Track employee attendance and work hours.
Features:
- Daily attendance marking
- Attendance policies (work hours, flexible timing)
- Attendance regularization requests
- Monthly attendance reports
- Integration with biometric systems (planned)
Key Tables: Attendance logs, attendance policies
Performance Management
Purpose: OKR-based performance reviews and goal tracking.
Features:
- Performance cycles (quarterly, annual)
- OKR (Objectives and Key Results) framework
- Goal setting and approval
- Progress tracking during cycle
- Self-assessment at cycle end
- Manager review and rating
- Multi-stage review process (self → manager → calibration)
- Rating scales and performance bands
- Performance improvement plans (PIP)
Workflow: Create cycle → Set OKRs → Track progress → Self-review → Manager review → Calibration → Final rating
Key Tables: performance_cycle, okr, okr_goal, sub_goal, okr_review, rating_scale
Separation & Exit
Purpose: Employee resignation or termination workflows.
Features:
- Resignation initiation (by employee or employer)
- Notice period calculation based on policy
- Exit survey for feedback
- Clearance workflows (IT, Admin, Finance, HR, Manager NOCs)
- Final settlement calculation
- Access revocation
- Experience/relieving letter generation
- Exit interview scheduling
Workflow: Resignation → Notice period → Exit survey → Clearances → Final settlement → Exit
Key Tables: separation_request, separation_approval, exit_survey_*, NOC tables
Talent Management
Purpose: Skills tracking and internal mobility.
Features:
- Employee skills profile
- Skill assessment and validation
- Training and development tracking
- Internal job demand matching
- Career progression planning
- Succession planning (planned)
Key Tables: skill, skill_group, employee skills, certifications
Demand Management
Purpose: Internal job demands and employee matching.
Features:
- Create internal job demands
- Match demands with existing employee skills
- Recommend employees for internal positions
- Facilitate internal mobility
Integration: Links with talent management and recruitment
Key Tables: demand_master, employee_demand_status
Support Tickets
Purpose: Internal helpdesk for employee queries.
Features:
- Ticket creation by employees
- Ticket assignment to support team
- Comment threads for discussion
- File attachments
- SLA tracking
- Status management (open, in-progress, resolved, closed)
- Priority levels
Use Cases: IT support, HR queries, facility requests
Key Tables: support_ticket, support_ticket_comment, support_ticket_sla
Recognition & Rewards
Purpose: Employee recognition and rewards program (basic implementation).
Features:
- Peer recognition
- Manager appreciation
- Reward points (planned)
- Leaderboards (planned)
Status: Basic framework in place, full implementation planned