Skip to end of metadata
Go to start of metadata

You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 4 Next »

Effective management of sensitive data is a critical aspect of maintaining data security and privacy when using Upvise.

The approach recommended below reduces the risk of unauthorized access to sensitive information.

Employee Contact Information

Employee personal contact information should be captured in a form against the employee contact record in Upvise

Types of sensitive data can include but is not limited to:

  • Residential Address

  • Personal Mobile Number (if they have a business phone)

  • Personal non-work provided email address

  • Emergency contact information

  • Licences and certificates etc

By using forms to capture this data, you have the ability to hide this from unauthorised employees.

Standard & Manager type users are only able to access forms that are included in their role. Standard users can only see forms that they have submitted.

Read more on Roles & User Types here

 1. What if I have sensitive data stored already in the workbench People record?

Employee contact data is not auto-created in workbench from your financial systems, so you have the ability to control the data you input into workbench.

It’s recommended that before implementing Upvise, you remove any Sensitive data and migrate this to Upvise Contact forms.

See below an example of data to be reviewed:

 2. How do I capture Employee Contact information in Upvise so it's only availble to HR (or authorised people)?

In Upvise, you can use a form template to capture employee-related information and you can use roles to restrict the visibility of this to specified users. 

Examples of Contact forms may include:

​a) Employee Emergency Contact Information

b) Employee Onboarding Form 

c) Training Records

d) Assigned assets (e.g. boots, laptops etc)

Forms can be made easily accessible from the contact record by using Buttons.

Form data related to that employee is available on the contact record, see the example:

To enable users to access the form, you should use roles. Read more about Users and Roles

See example role configuration:

Apply the role to the users who should have that particular level of access:

  • No labels