LekhaHR
Start trial

Employee management software for India

Employee management software built around one governed record.

Every employee lives once in LekhaHR: their fields, their documents, the lifecycle state they're in, who is allowed to see what, and a full history of every change. Self-service for the employee, enforced access for everyone else.

  • No base fee
  • Per active employee
  • GST extra
Product workflow previewOne record, shown to each role as it is actually allowed to see it.

A manager opens a profile and the pay block is simply absent. HR sees the whole record and every edit it has ever had. The employee fixes their own details, and the sensitive ones wait for approval.

Real released UI screenshots remain required before public indexing.

Quick answer

What is employee management software, and how is LekhaHR's built?

An employee management system keeps one record per person and runs the everyday work around it: self-service, documents, access control and an audit trail. Most products treat the record as a filing cabinet. LekhaHR treats it as a governed object: the server decides which blocks each role receives, sensitive edits wait for approval, and every change is logged. The map below is the same record seen through three different sets of eyes.

One record, seen through who's allowed to see it

The same employee record shows a different truth to each role.

Pick a viewer. LekhaHR renders one governed employee record covering About, Job, Documents and Finances, and the server decides which blocks each role receives. Switch to the manager lens and the whole salary and bank block is gone: not greyed, not locked, simply never sent. That boundary is the product's own rule, shown as it works.

Choose a viewer lens to see which record blocks that role receives
Illustrative record · schematic render of the real payloadThe employee, on their own record

The employee opens their profile and sees everything HR holds about them, including their own pay details.

people.profile.view · scope self

About

Full name
Ananya Rao
Legal name
Ananya Suresh RaoSensitive field; edits route to approval
Date of birth
11 Mar 1994Sensitive field
Personal email · phone
ananya@… · +91 9•••••4471
Emergency contact
Name + phone, saved together

Which fields are safe to self-edit and which are sensitive comes from tenant config, returned by the server. The client never decides.

Job

Title · department
Senior Analyst · Finance
Work location / state
Bengaluru, KarnatakaWork-state drives PT and S&E rules, not derived from HQ
Primary manager
Reporting relationship
Secondary relationship
Project lead (dotted-line)Explains purpose; grants no access by itself
HR Partner
Support relationship, kept separate from reporting
DOJ · type · status
12 Aug 2022 · Full-time · Confirmed

Documents

PAN card
Uploaded · verified
Appointment letter
Uploaded
Degree certificate
UploadedCan also satisfy a pending leave or regularization requirement, cross-module

Finances

CTC
Display onlyShown on the record; the structure is built and run in payroll (M4)
Bank account · IFSC
••••4471 · HDFC0001234IFSC format and account validated on save
PAN
•••••••••FMasked always (only the last character shown); raw value encrypted at rest (DPDP)

What this lens can doEdit safe fields directly. Sensitive fields such as legal name, DOB, bank and PAN do not change the record; they raise a change-request that waits for HR approval, so a self-edit can never quietly rewrite the record.

Illustrative record · schematic render of the real payloadA reporting manager, on a team member's record

A manager can open a team member's profile to read the job and contact details they need.

people.profile.view · scope direct-team · no people.salary.view

About

Full name
Ananya Rao
Legal name
Ananya Suresh RaoSensitive field; edits route to approval
Date of birth
11 Mar 1994Sensitive field
Personal email · phone
ananya@… · +91 9•••••4471
Emergency contact
Name + phone, saved together

Which fields are safe to self-edit and which are sensitive comes from tenant config, returned by the server. The client never decides.

Job

Title · department
Senior Analyst · Finance
Work location / state
Bengaluru, KarnatakaWork-state drives PT and S&E rules, not derived from HQ
Primary manager
Reporting relationship
Secondary relationship
Project lead (dotted-line)Explains purpose; grants no access by itself
HR Partner
Support relationship, kept separate from reporting
DOJ · type · status
12 Aug 2022 · Full-time · Confirmed

Documents

PAN card
Uploaded · verified
Appointment letter
Uploaded
Degree certificate
UploadedCan also satisfy a pending leave or regularization requirement, cross-module

Finances · not rendered for this lens

Without people.salary.view, the server omits the salary, CTC and bank block from the response entirely. The manager does not get a greyed-out card or a locked field; the pay data is never sent to the browser. That is the product's own principle, not a UI trick.

What this lens can doRead a team member's record within their scope and act on the fields their role grants. Pay stays invisible by design, so a manager review never leaks compensation.

Illustrative record · schematic render of the real payloadHR, maintaining the full record

HR reads and maintains the whole record, including the Finances block a manager never receives.

people.profile.view + people.salary.view · scope group

About

Full name
Ananya Rao
Legal name
Ananya Suresh RaoSensitive field; edits route to approval
Date of birth
11 Mar 1994Sensitive field
Personal email · phone
ananya@… · +91 9•••••4471
Emergency contact
Name + phone, saved together

Which fields are safe to self-edit and which are sensitive comes from tenant config, returned by the server. The client never decides.

Job

Title · department
Senior Analyst · Finance
Work location / state
Bengaluru, KarnatakaWork-state drives PT and S&E rules, not derived from HQ
Primary manager
Reporting relationship
Secondary relationship
Project lead (dotted-line)Explains purpose; grants no access by itself
HR Partner
Support relationship, kept separate from reporting
DOJ · type · status
12 Aug 2022 · Full-time · Confirmed

Documents

PAN card
Uploaded · verified
Appointment letter
Uploaded
Degree certificate
UploadedCan also satisfy a pending leave or regularization requirement, cross-module

Finances

CTC
Display onlyShown on the record; the structure is built and run in payroll (M4)
Bank account · IFSC
••••4471 · HDFC0001234IFSC format and account validated on save
PAN
•••••••••FMasked always (only the last character shown); raw value encrypted at rest (DPDP)

What this lens can doMaintain the record, approve or override an employee's pending change-request, and bulk-fill bank and PAN before the payroll cutoff. Every write lands in the audit log with the before value, the after value and the actor.

Lifecycle state on the record: a value, not a workflow

  1. Onboarding
  2. Probation
  3. Confirmedon this record
  4. Notice
  5. Exited

The record carries its lifecycle state as a value today, and the directory filters and colours by it. The workflows behind these states, from offer and preboarding into onboarding through resignation, clearance and full-and-final behind notice and exited, arrive with the Onboarding & Exits module (M5). LekhaHR shows the state; it does not run that workflow yet.

Structural example of the GET /api/people/:id payload and its field-level permission behaviour: the salary/CTC/bank block is absent from the response when the caller lacks people.salary.view. Labelled illustrative — not a product screenshot, not employee or customer data; salary is display-only here (Payroll processes money separately, M4).

One record, one source of truth

Each employee exists once, and everything else reads from it.

The record is a governed object, not a form. What can be edited, by whom, and through which path is decided by the server from your configuration.

No duplicate people

Each employee is one row, not a copy in payroll, another in the attendance sheet and a third in a shared drive. The profile is the hub every other module reads from.

Config decides the edit path

The server returns editableFields and sensitiveFields from tenant config. Safe fields save on the spot; sensitive ones route to approval. No client-side guess about what counts as sensitive.

Readiness dots name the gap

The directory flags an employee as not-ready and lists the missing field by name, whether that is bank, PAN or the salary structure. It surfaces what is missing, never the value itself.

Reads scope to the group

Directory facets are intersected in SQL, so a group-scoped HR Admin cannot even enumerate people outside their coverage. Scope is a floor, not a front-end filter.

Documents on the record

Every certificate lives with the person it belongs to.

Employee records management means the paper travels with the person. Upload once, attach where it is needed, and keep an export trail that names who pulled what.

A Documents tab per profileUpload a PAN card, an appointment letter or a degree certificate with a multipart POST to the record. Each document carries a status, and an oversize file returns a clean 413 rather than a broken save.
One certificate, two jobsA document attached to the record can also satisfy a pending leave or regularization requirement in another module, referenced by its attachment id. The same proof does not get uploaded twice.
Exports leave a trailA report export is generated into private object storage behind a signed URL, and the export itself is audit-logged: who pulled which PII-bearing report, and when.

Lifecycle states, honestly scoped

The record shows the state. The workflow behind it is a later module.

Employment status moves through onboarding, probation, confirmed, notice and exited. LekhaHR renders that state on the record and filters the directory by it today.

What is not here yet: the workflow that drives those transitions, from offer and preboarding through resignation, clearance and full-and-final. That arrives with Onboarding & Exits, behind the M5 release gate. We show the state without pretending to run the process.

  1. Onboarding
  2. Probation
  3. Confirmed
  4. Noticeworkflow M5-gated
  5. Exitedworkflow M5-gated

Who sees what

Access is a permission on the server, not a setting on a screen.

The manager lens in the map above is not a demo trick. It is the same field-level authorization the product runs everywhere: seeing a profile and seeing its pay are different permissions.

Five core roles, clone-only

Five protected roles ship with the product. You cannot edit a core role in place; you clone it into a custom template and adjust that, so the baseline stays intact.

Scope is explicit

Every grant carries a scope: off, self, direct-team, team-tree, group or org. An assignment can cover several locations or groups at once without ever widening to the whole org.

Field-level is separate

Seeing a profile and seeing its pay are two different permissions. people.salary.view gates the compensation block on its own, which is how a manager reads the record but not the salary.

An inspector, not impersonation

The effective-access inspector simulates an actor, a target and a capability, then returns the exact allow-or-deny reason: the role, the scope intersection and the relationship, without anyone logging in as someone else.

Every change, audited

A record you can trust is a record you can replay.

Sensitive edits do not quietly overwrite the truth. They wait for approval, and everything that does change is written down with its before and after.

Sensitive edits waitA change to a sensitive field creates a change-request. The record is not touched until an approver acts, an open request on the same field blocks a duplicate with a 409, and no one can approve their own request.
A timeline per employeeEvery write records the before value, the after value and the actor. The per-employee change history reads back as a plain timeline for anyone with people.audit.view.
Bulk-fill is still per-rowWhen HR bulk-fills bank or PAN for many employees before a cutoff, each row is validated and audited on its own. One bad IFSC fails only its row, not the batch, and each fill is its own audit entry.

Built for Indian teams

The details a global tool leaves out.

The record is shaped for Indian payroll and compliance realities without quoting a single statutory number in marketing copy.

PAN masked and encrypted

A PAN is stored masked and its raw value is encrypted at rest, with a consent notice shown at collection, following the DPDP posture. It is never returned in the clear.

Bank fields are validated

IFSC format and the account number are checked when they are saved, so a payroll run does not inherit a typo from a spreadsheet paste.

Work-state is first-class

Each location carries its own state, and that work-state, not the head office, drives the profession tax and shops-and-establishment rules that apply to the employee.

LekhaHR can capture location when an employee checks in or out and validate the configured office geofence. It does not track movement in the background, build travel routes or monitor employees between punches. That punch-time-only boundary is why LekhaHR is a record and access product, not an employee-monitoring one.

A good fit when

  • You want one trustworthy employee record, with documents, self-service and a real audit trail, instead of scattered spreadsheets.
  • You need managers to open profiles without ever seeing pay, and you want that enforced on the server, not promised in a policy.
  • You run teams across more than one Indian state and want work-state to drive the rules on each record.

Not the right tool when

  • You need a released payroll run today. Salary is display-only on the record, and processing sits behind the M4 gate.
  • You need the onboarding or exit workflow itself. Offer, preboarding, clearance and full-and-final arrive with Onboarding & Exits (M5).
  • You want performance reviews or workforce analytics, which are later modules; we hide what we cannot yet prove.
  • You are shopping for employee monitoring or productivity tracking. LekhaHR reads location only at a punch and never in the background, which is the opposite of a monitoring tool.

Transparent pricing

See what one employee record costs without a platform minimum.

Operations starts at ₹79 per active employee/month billed annually. Business starts at ₹119. GST extra.

Employee management FAQ

What buyers ask about the record, access and audit.

What is employee management software?

Employee management software keeps one governed record for every employee and runs the routine work around it: self-service edits, document storage, role-based access and an audit trail of changes. It replaces the scattered spreadsheets and shared drives where employee data usually lives, so there is a single, trustworthy source for each person instead of several copies that drift apart.

What information is stored on an employee record?

LekhaHR groups the record into four tabs. About holds name, legal name, date of birth, contact and emergency contact. Job holds title, department, work location and state, the primary manager, typed secondary relationships, the HR Partner, date of joining, employment type and status. Documents holds uploaded files. Finances holds the bank account and IFSC, PAN stored masked, and CTC shown for display only. Which fields count as sensitive comes from tenant config, not from hardcoded client logic.

Can employees update their own records?

Yes, with a boundary. Safe fields save directly when the employee edits them. Sensitive fields such as bank, PAN, legal name and date of birth do not change the record on their own; they raise a change-request that routes to an approver, and the stored value only changes once HR approves it. An open request on a field blocks a second one, and no one can approve their own request.

Who can see an employee's salary and bank details?

Only roles that hold the people.salary.view permission. Field-level access is a separate permission from seeing the profile, so a manager can open a team member's record but the salary, CTC and bank block is omitted from the server response entirely. It is not greyed out or locked on screen; the data is never sent to the browser at all.

Is every change to a record tracked?

Yes. Every write to a record lands in the audit log with the before value, the after value and the actor who made the change. There is a per-employee change timeline for anyone with people.audit.view, and even bulk operations are audited one row per employee. Report exports are logged too, recording who exported which report containing personal data and when.

Can I store documents against an employee?

Yes. Each profile has a Documents tab where you upload files such as a PAN card, an appointment letter or a certificate. A document on the record can also satisfy a pending leave or regularization requirement in another module by its attachment id, so the same proof is not uploaded twice, and an oversize upload returns a clean error rather than failing silently.

Is employee data secure and India-compliant?

PAN is stored masked with its raw value encrypted at rest, and a consent notice is shown at collection, following the DPDP posture. Bank IFSC and account fields are validated on save. Work location carries its own state so profession tax and shops-and-establishment rules follow the right state per employee. Specific statutory figures are not quoted on this page; those live in dated fixtures rather than in marketing copy.

Does it handle onboarding and exits?

The record shows the lifecycle state today, whether onboarding, probation, confirmed, notice or exited, and the directory filters by it. The onboarding and exit workflows themselves, from offer and preboarding through resignation, clearance and full-and-final, arrive with the Onboarding & Exits module, which is behind the M5 release gate. We show the state; we do not claim to run that workflow yet.

Which is the best employee management software, including in India?

We will not rank ourselves, and we have no customer logos or testimonials to point at yet, so any "we are number one" claim would be invented. The honest answer is a fit answer: LekhaHR suits an Indian team that wants one governed record with server-enforced access and a real audit trail, and it is the wrong choice if you need released payroll, an onboarding workflow or employee monitoring today.

When should I not choose LekhaHR?

When you need a released payroll run, an onboarding or exit workflow, performance reviews or workforce analytics right now, since those are gated modules we deliberately do not claim. Also when you want employee monitoring or productivity tracking, or biometric kiosk hardware, since LekhaHR reads location only at a punch and runs no continuous tracking.

Is there free employee management software?

There is no free-forever plan. LekhaHR offers a 14-day trial, then per-active-employee pricing with no base platform fee and no minimum headcount. The published rates are on the pricing page and GST is charged separately, so a small team pays only for the people it actually has on the record.