HR questions answered with AI, under the permission model HR needs
An employee of your organization asks about leave, a payslip line or a procedure. FixControl resolves who is asking, which sources that person may be answered from, and how sensitive the question is. A routine answer can be delivered straight away; a sensitive one becomes a case that only an explicitly assigned reviewer can open, and that a second person has to approve before it goes out.
Watch the governed HR flow
From an HR question in Teams to a delivered answer: who may see it, what the HR system is allowed to return, and the second person who has to approve.
Read the video transcript (in Dutch)
Een HR-vraag komt binnen
Een medewerker vraagt in Microsoft Teams hoeveel ouderschapsverlof zij nog heeft.
Eerst: wie mag dit zien?
FixControl bepaalt eerst wie dit mag zien: de medewerker en de behandelaar, niet het hele team.
Alleen-lezen, en eerlijk als er geen cijfer is
FixControl leest het saldo alleen-lezen uit het HR-systeem: alleen het veld dat nodig is. Is er geen cijfer, dan verzint FixControl niets — een mens neemt het over.
Een gevoelige vraag gaat een andere route
Een gevoelige vraag gaat naar een bevoegde beoordelaar. Wie toewijst, ziet alleen kenmerken — niet de inhoud.
Vier-ogen vóór levering
Een gevoelig antwoord gaat pas de deur uit na goedkeuring door een tweede persoon. Die goedkeuring is 72 uur geldig.
Vastgelegd en herstelbaar
Elke stap is vastgelegd. Klopt iets niet, dan volgt een gepubliceerde correctie.
Sneller, met controle
Zo krijgen medewerkers sneller antwoord, terwijl HR de controle houdt.
What an employee and an HR manager want to know
Who sees an employee’s question?+
What happens to a sensitive question?+
What does the AI see of an employee’s personnel file?+
Can an answer just go out to the employee?+
What if the answer turns out to be wrong?+
What do the connections to the HR systems read?+
Is what happens recorded?+
Through which channels can an employee ask?+
From a question to an answer someone is accountable for
Every step is a server-side check, not a setting in the chat window. The channel the question arrives on carries no permissions of its own: Teams, Slack and your chatbot all call the same command, and that command decides.
- 01The questionAn employee of your organization asks in Teams, Slack or your own chatbot
In Microsoft Teams the question is only handled in a personal chat, in Slack only in a direct message with the bot. A shared channel gets a short explanation and nothing is processed — the question text does not even reach the model. Your own chatbot can ask on an employee's behalf through an authenticated API.
- 02Who is askingIdentity is resolved before anything else happens
The chat account has to be linked to a FixControl user, and that user needs an active membership of an HR-enabled project with permission to ask. An unlinked account gets a link instruction instead of an answer. A missing identity can only make the check stricter, never looser.
- 03SensitivityThe question gets a sensitivity level it cannot lose
A deterministic classification sets a safety floor. A model may propose a stricter reading on top of it — more sensitive, or human review required — but it can never argue a question down to a lighter route.
- 04MinimisationThe model is shown the question text, not the file
The classification proposal receives the question text and nothing else, fully separated from your organization’s own data. Personnel-file data, retrieved documents and answer bodies are never sent to a model; the answer itself is drafted from templates and server-selected sources.
- 05AssignmentA sensitive case waits for an explicitly assigned reviewer
Someone with the assign permission sees a restricted case as metadata only — status, sensitivity, route — and can hand it only to an active project member whose role carries the permission that sensitivity requires. Assignment is the bridge between a case existing and anyone being allowed to read it.
- 06ApprovalA second person approves, then the answer is delivered
An approval is bound to the exact answer text and version. Whoever requested it can never decide it, the approval expires on a server-side 72-hour window clients cannot stretch, editing the answer invalidates it, and delivery consumes it in a single step so a double click cannot send twice.
The parts an HR pilot usually discovers late
Permissions, minimisation, approval and correction are the product here, not a phase after the answers work.
A visibility contract, not a shared queue
The employee who asked sees their own question. Your own HR staff see the work their project role allows. A restricted case is readable only by the reviewer it was explicitly assigned to — tenant administration is not HR access, and a technical administrator sees empty lists.
Three sensitivity levels with different routes
Normal, sensitive and highly restricted. Medical, legal and confidential employee-relations content takes the restricted human route. Missing, expired or contradicting sources, an unavailable connector, low confidence or an unclear question never produce an invented answer.
Named fields, not a personnel file
The connectors read a fixed, explicitly projected set of fields — employment percentage and type, collective agreement, remaining leave hours with an as-of date, a payroll explanation code. A widened view on the HR side cannot leak extra data into an answer.
AFAS Profit and Visma Raet Youforce, read-only
Both connectors read and write nothing back. Credentials are per organization, a project has to activate a connector explicitly, and a connection check makes a revoked token visible before an employee runs into it.
Report, correct, or withdraw
The employee who asked — and your HR staff within what they may already read — can mark an answer as incorrect. A correction is published as a new version while the original is kept and marked superseded. When there is no safe replacement, the answer is withdrawn instead.
An audit trail on identifiers, not on content
Decisions record project scope, case and answer identifiers, classification, source versions, the policy decision and its reason code. Question text, case summaries, medical content, employee references and answer bodies stay out of the audit record and inside the HR tables.
The chatbot is the easy half
AI proposes a reading; it decides nothing
See the permission model before the chatbot
Book a demo and follow one sensitive HR question through assignment, approval, delivery and correction.