Spreadsheets and WhatsApp for HR: the real monthly cost
The tools are free, which is why nobody adds up what they cost. A way to work out what your current HR setup actually takes each month.
Read the articleGanesh HS ·
A founder found out that an office administrator had been sharing salary figures, not maliciously, but because she had access to the payroll sheet and saw nothing unusual about discussing it. Nobody had ever told her the data was restricted, because nobody had ever decided that it was.
That is the normal state. Access in a small business is granted by whoever needs to do a job, accumulates over years, and is never reviewed. It only becomes visible when something goes wrong.
SELF
Own record, own payslips, own leave balance, own documents.
Can request changes to personal details.
MANAGER
Team's attendance, leave balances and requests.
Team's performance records and probation dates.
Contact and emergency details for their own team.
Salary: a deliberate decision — see below.
HR ADMINISTRATION
All employee records, documents, attendance and leave.
Payroll inputs. Letters and templates.
Salary structures: yes, because the job requires it.
OWNER / FINANCE
Everything, including cost by department and individual pay.
PLUS, separately from all four:
Who may CHANGE a salary, as against who may SEE one.
These are different permissions and are frequently
granted together without anyone intending it.That last block is the one most often missed. Viewing and changing are different risks, and a system that bundles them gives the person who prepares payroll the ability to alter it.
Should a line manager see what their team members earn? Both answers are defensible and the wrong thing is to leave it undecided.
The middle position depends on having grades at all, which is why this decision often waits until a compensation and rewards strategy exists. Before that, managers are either told everything or nothing.
Not who should — who does. Include the spreadsheet, the shared drive, the email thread where payroll is circulated, and anyone who was given access for one task three years ago.
Write them down, including the manager question. Half an hour of decisions, and it is the input a system configuration actually needs.
For salary, structure changes, and employee master data. Specify who may approve a change as distinct from who may enter one.
Salary changes and access to pay data should be logged. In a dispute, being able to show who saw or changed what is the difference between a question and an allegation.
The spreadsheet on the shared drive, the payroll file circulated by email. Access control in a system means nothing if the same data sits unprotected elsewhere.
That last step is the one businesses skip, and it is the one that matters most. Configuring core employee management carefully while a payroll spreadsheet remains on a shared drive is security theatre.
Salary is the obvious case. Several others carry as much sensitivity and usually have no access rules at all.
Access accumulates. People change roles and keep old permissions, someone is given temporary access for a project, an employee leaves and their account stays active for months.
An annual review — who has what, is it still needed, does anyone have access from a role they no longer hold — takes an hour and catches the majority of it. Tie it to something that already happens, like the audit or the annual policy review, or it will not happen at all.
The exit half of that is worth automating rather than remembering: access revocation on the last working day, against the issue record, as a step in the exit and offboarding process rather than a favour someone does for IT. If you want to see how the access levels would look configured against your own roles, book a free demo of GullyHR software.
The moment this becomes urgent is the first HR or finance hire. Until then access is simple because it is one person, and the question has never had to be answered.
That hire arrives, needs to do the job from week one, and is handed everything — the payroll sheet, the shared drive, the folder of employee files. Access granted that way is almost never narrowed afterwards, because nobody revisits a decision that was never consciously made.
Access decisions are usually discussed as what to grant. The harder problem arrives later, when somebody who has had visibility needs to lose it.
A manager who moves to a role with no team, or an assistant who supported a function and no longer does, has seen things they will continue to remember. Removing the access is straightforward and should be done on the day the role changes rather than whenever it is noticed. Managing the fact that they know is a separate matter and cannot be undone.
Two practical consequences. Grant access narrowly at the outset, because every grant is effectively permanent in terms of knowledge even when it is revoked in terms of systems. And handle the removal explicitly rather than silently — a person who discovers their access has gone, with no conversation, reasonably concludes something has gone wrong with their standing.
The removal is also the moment to check the rest. Most businesses discover, when they finally look, that access accumulated over years and nobody has ever taken anything away. A role-change trigger that prompts a review of what someone should still see is the cheapest control available and almost nobody has one.
So the half hour is best spent before the hire, not after. Decide the four levels, decide the manager question, and hand over exactly what the role needs. It is also a better first day for them: being told what they may see and why reads as a business that takes its records seriously, which is the standard you want them to keep. Holding those permissions against the employee record rather than against a folder is what core employee management makes possible.
If they prepare payroll inputs, they will see the figures whatever the policy says, so the useful control is separating who may change a salary from who may see one, and logging changes.
Then access is simple and the risk sits elsewhere — in what happens when the first HR hire arrives. Deciding the levels before that hire is far easier than retrofitting them afterwards.
Whatever your view, they will, and a policy attempting to forbid it may carry legal complications worth checking. A defensible structure is a better answer than a prohibition, because it means the comparison has an explanation.
Give the minimum needed for the task, under a written agreement covering handling and retention, and review what they hold annually. Treat their access exactly as you would an internal role.
Changes to salary, structure and employee master data at minimum, with who and when. Whether to log views as well depends on how sensitive your context is and on what your system supports.
Using an HR system for records, attendance, payroll inputs, performance and exits.
Request a GullyHR Software DemoThe tools are free, which is why nobody adds up what they cost. A way to work out what your current HR setup actually takes each month.
Read the articleHR software rarely fails at the demo. It fails in month three. The five reasons it happens and what to settle before configuration starts.
Read the articleTwo different products often sold as one. What each actually does, which one your late payroll needs, and why buying the wrong one changes nothing.
Read the articleGet expert recommendations on payroll coordination, compliance readiness, and modern HR automation. Request a free, no-obligation HR audit.
Prefer the full picture? Request a free 360-degree HR audit.