Sign-in and sessions
Time-limited tokens, refresh handling, throttled failed sign-ins and session history are part of the platform.
Scarlet Sails HRM handles sensitive company data: employee files, ID-card information, bank accounts, attendance records, payroll formulas and payslips. The first question is not whether the UI looks good; it is where the data lives and who can view or change it.
The system does not force payroll data into a shared third-party cloud. Depending on internal policy, it can run inside your company or on a private VPS.
Time-limited tokens, refresh handling, throttled failed sign-ins and session history are part of the platform.
A user can only enter companies they are assigned to, keeping group-company data from bleeding across units.
Access can be limited to a department tree, direct reports, or only the employee's own record.
Payroll, bank accounts, ID data and personal information are controlled by role and server-side data scope.
Important changes can be traced back to who changed what, when, and what the previous value was.
Closed attendance and payroll periods can be locked to reduce accidental edits after figures are used for payment.
Leave, overtime and other controlled actions can follow multi-level approval by employee or department scope.
The backup plan depends on the deployment model. With on-premise hosting, internal IT can fully own the schedule.
In HRM, view permission and edit permission must be separated. A line manager may need team attendance, but not every salary line or identity document.
| Data group | Risk when access is too broad | Control to enable |
|---|---|---|
| Salary and allowances | Exposure of income, formulas and personal deductions | Role permissions, data scope and payroll period locking |
| ID cards, address, bank accounts | Exposure of personal data, document images and payment details | Limit to authorised HR roles and control uploads/downloads |
| Attendance logs and edits | Wrong clock-in/out edits without traceability before payroll close | Before/after audit trail, approval flow and anomaly reports |
| Accounts and permissions | Over-granted access or former staff accounts staying active | Periodic user review, account lockout and sign-in history |
Not on this website, because there is no public proof to publish. If procurement requires a formal certificate, raise it at the start so both sides can decide the right path.
No. OTP/MFA screens have a design direction, but it should not be sold as a production feature yet. If 2FA is mandatory, it must be included in the implementation scope.
It depends on deployment. With a company server, internal IT owns the main backup schedule; the Scarlet Sails team can help configure checks, recovery tests and file-upload backup scope.
Yes. The platform supports data scope by department tree, direct reports or the employee's own record, applied server-side rather than only hidden in the UI.
Send the IT policy, data-scope rules and user groups ahead of time. The demo can then follow the way your company actually wants to control access.