What the employee master contains
A usable master has five groups of fields. Identity: name, employee ID, date of birth, gender, photo, contact details, emergency contact. Statutory: PAN, Aadhaar reference where lawfully collected, UAN and PF member ID, ESIC IP number, bank account for salary. Job: department, branch or site, designation, reporting manager, date of joining, employment type (permanent, contract, apprentice, daily-rated), shift group, weekly-off pattern. Pay: salary structure with basic, DA, HRA and allowances, applicable policy for PF, ESI, professional tax state and leave. Documents: offer letter, ID proofs, police verification for guards, certificates, signed policy acknowledgements.
Each of these groups is owned by a different process (HR, payroll, operations, compliance), which is why the master drifts when it lives in several Excel sheets. One record, with field-level ownership and an audit log, is the fix.
- Identity and contact, including a photo used for ID cards and face enrolment confirmation
- Statutory IDs: PAN, UAN, ESIC number, bank details, PT state
- Job: site, department, reporting line, joining date, employment type, shift group
- Pay structure and the policies (PF, ESI, leave, attendance) the employee is mapped to
- Documents with expiry dates where relevant (licences, verifications, contracts)
Why it is the source for attendance rules and payroll
Attendance software does not apply rules to a name; it applies them to the attributes on the master. The shift group decides which timings a punch is validated against. The site decides which geofence applies. The employment type decides whether the 26-day divisor or calendar days are used for the per-day rate. The joining date decides leave accrual and, later, gratuity eligibility. The PF and ESI flags decide whether contributions are computed at all.
Payroll reads the same record for basic and DA (PF base), gross (ESI base), the professional tax state, and the bank account for the NEFT file. If a guard is transferred from a Gurugram site to a Faridabad site and the master is not updated, his punches will fail the old geofence and his professional tax may be computed for the wrong state. The HRMS glossary entry explains how the master sits under every other module.
DPDP handling and access control
Almost everything in the master is personal data under the Digital Personal Data Protection Act 2023, and some of it (Aadhaar, bank, face descriptors, health records) deserves stricter treatment. The practical obligations are to collect only what a stated purpose needs, tell employees what is held and why, restrict who can see each field group, keep an access log, and retain records only as long as statutory rules require after exit.
Role-based access is the everyday control: a site supervisor needs names, photos, shift group and phone numbers; he does not need bank accounts or PAN. Exports should be logged and limited to the fields the recipient needs, because the mass CSV export to a personal email is how most master-data leaks happen.
- Purpose-limited collection; no field 'just in case'
- Field-group permissions by role, with an access and export log
- Retention schedule tied to statutory requirements, with deletion at the end
- Employee self-service for viewing and correcting their own contact and bank details
A housekeeping contractor onboards 30 staff for a new Bengaluru mall from a supervisor's WhatsApp list. Joining dates are entered as the 1st of the month for everyone, though most joined on the 8th. Three things go wrong: earned leave accrues a week early for all 30; the first month's payroll pays 30 days instead of 23 for each; and PF is computed on a full month's basic. The correction touches the leave ledger, an arrears reversal and a revised ECR. Reconciling the master against offer letters before the first payroll would have taken an hour.
Attend Mitra keeps one employee database with departments, branches and sites, digital ID cards, document uploads, and the shift, leave, PF and ESI mappings that attendance and payroll preparation read from. Bulk import from Excel, role-based access, audit logs and employee self-service for contact details are included; the headcount reports and analytics exports run off the same record.
