Compliance

Evidence ready before anyone asks.

Obligations, owners, due dates, and the documents that prove the work was done — held together instead of scattered across inboxes and shared drives.

Two colleagues reading through a printed policy together

This week

Awaiting your approval4
Completed this week37
Everything elseOn track

What's included

What the Compliance module covers

Built for firms carrying obligations on behalf of clients as well as internal teams answering to one regulator.

A safety officer completing a site checklist on a tablet
Evidence is collected where the work happens, then filed against the requirement.

Compliance items & tasks

Every obligation has an owner, a cadence, a due date, and attached evidence. Tasks are scoped to the client they belong to.

Credentials

Licences, certifications, background checks, and right-to-work documents with expiry dates that warn the holder and their manager ahead of time.

Policies

Versioned policy library with distribution, read-and-acknowledge tracking, and a record of exactly which version a person signed.

Document register

A central index of what documents exist, who owns them, where they came from, and when they expire or must be destroyed.

Retention & data privacy

Retention schedules by record type, subject access request handling, and deletion workflows that respect legal hold.

Audit trail

Immutable log of who changed what and when across the workspace, exportable for an auditor without engineering involvement.

The screens

Compliance in the product

Screens from the working product, filled with sample data so you can see the shape of the thing before you talk to us.

Compliance dashboard showing credential expiry and policy acknowledgement rates
Credentials, checks and acknowledgements with the expiry dates in view.

Screens shown with sample data from a demonstration workspace.

Meet Pixi

The assistant that already read your compliance data

Pixi answers from your own records and policies, cites what it used, and hands the decision back to you. It drafts and suggests; it never approves, hires, or pays anyone on its own.

Runs on its own

Reminders, escalations, and status changes fire from the same rules, so nothing sits in a queue because a person forgot to look.

How Pixi works
What needs my attention in compliance today?

Four items are waiting on you, two of them past their target date. I have grouped them by who is blocked and linked each one to the record it came from.

Your live records Policy library
Scoped to your tenant · every call logged with model, tokens, and cost

How it runs

Running a recurring obligation

An annual policy attestation is representative of how most obligations behave in the platform.

  1. 01

    The obligation is defined once

    Scope, owner, cadence, and the evidence required. For consultancies, it is attached to a specific client rather than the whole workspace.

  2. 02

    Tasks generate on schedule

    Each cycle creates tasks against the right people automatically. Nobody has to remember to start the round.

  3. 03

    People complete and attest

    Employees read the current policy version and acknowledge. The acknowledgement records the version hash and timestamp.

  4. 04

    Gaps escalate

    Outstanding items appear on the compliance dashboard and escalate to the manager, then to the owner, on your escalation ladder.

  5. 05

    Evidence is exported on demand

    The completed cycle — who, what version, when, with documents — exports as a single evidence pack.

A team talking together during a morning standup

People first

We stopped chasing spreadsheets and started actually talking to people again.

Sean Morrison · Founder, HaloHR

Questions about any of this? Write to us.info@halohr.ai
One record
People, time, and pay share a single source
Per tenant
Data and AI retrieval never cross a client line
Minutes
Typical time to set up a new client workspace

Built in

Scoped to exactly what a person should see

Compliance data is the clearest case for narrow access. HaloHR enforces the boundary in the database, not the interface.

  • Client assignments limit users to the compliance items and tasks of the clients they are explicitly assigned to
  • Row-level security applies the same filter to every read path, including reports and exports
  • Evidence documents inherit the access rules of the item they support
  • Legal hold blocks deletion even when a retention schedule would otherwise purge
  • Sensitive records are access-scoped by role and RLS, and key writes are recorded in an append-only activity log

Keep exploring

Connected to the rest of the platform

Every module writes to the same database, so a change in one place shows up everywhere else.

All modules