brillienta Book a demo ↗

HOME / BLOG / SECURITY

Why your HR data should stay in your own Microsoft 365 tenant

Employee records are the most sensitive data most companies hold. Here is what changes when the HR system stores them in your SharePoint instead of a vendor’s cloud.

Brillienta team·Published ·6 min read

An HR system holds salaries, bank details, performance reviews, absence reasons and home addresses. Most HR software keeps that data in the vendor's own cloud, which means one more company to assess, one more contract to manage and one more place your employees' data can leak from.

Brillienta HRMS takes a different approach: it runs inside a SharePoint page, and all of its data lives in SharePoint lists on your own site. There is no server, database or third-party API.

What that means in practice

1. Your security team already knows the platform

Access is controlled with SharePoint permissions and Entra ID groups — the same controls your IT team already manages, audits and reports on. Brillienta HRMS uses four HRMS groups and per-list security profiles, so the right people see the right lists.

2. Privacy is enforced by SharePoint, not by the app

With employee privacy switched on, people can read only their own items, and SharePoint itself enforces it. Payroll lists are closed to the wider HR team. Even someone who bypasses the app and opens a list directly sees only what SharePoint allows.

3. No vendor lock-in for your records

Because the records are ordinary SharePoint lists in your tenant, they stay with you whatever happens to your contract. You can report on them with Power BI, back them up with your existing tools and apply your retention policies.

4. One less processor in your privacy notice

When the vendor never receives your employees' data, it does not become a processor of it. That simplifies data protection assessments and the conversations with your works council or DPO.

What to check in any HR system

  • Where exactly is the data stored, and who can access the storage?
  • Is privacy enforced by the storage layer, or only hidden in the interface?
  • What happens to the data when the contract ends?
  • Which permissions does the app request, and why?
The HRMS guide answers each of these for Brillienta HRMS, including the full list of SharePoint lists and roles.
All articles →

KEEP READING

More from the blog.

SEE IT FOR YOURSELF

Book a demo on
a live tenant.

Book a demo ↗