HridaOne (AI Enterprise)
One platform for the whole employee record — from onboarding to offboarding, and everything paid in between.
HridaOne is a multi-tenant HR, payroll and finance system. A company registers as a tenant, its people sign in to one of four role-scoped portals, and everything an HR team runs — attendance, leave, payroll, reimbursements, tax, documents, assets, performance, support — lives in one place, isolated per company.
It runs two ways:
| Mode | What it is |
|---|---|
| SaaS | The default — multi-tenant, self-serve, plan-based. Companies request a demo, pick a plan, and manage their own subscription. |
| Enterprise | A dedicated single-customer install (typically bundled with Hrida AI Studio and Keycloak). The self-serve commercial surface — demo requests, plan catalog, billing — is switched off. |
Four portals
Every user lands in exactly one portal, decided by their role:
| Portal | Role | What it's for |
|---|---|---|
Employee (/p/em) | EMPLOYEE | Self-service — clock in, request leave, view payslips, file reimbursements, declare tax, sign documents, raise tickets, run the exit process. |
Admin (/p/ad) | ADMIN | Day-to-day HR — manage employees, attendance, leave, payroll, performance, assets, org hierarchy, documents. |
Super Admin (/p/sa) | SUPER_ADMIN, COMPANY_ADMIN | Company owner — manage admins, company profile, branded email, the security keyword, and everything the Admin portal can do. |
Global Admin (/p/ga) | GLOBAL_ADMIN | Platform operator — companies, plans, subscriptions, users & roles, reports, salary setup, audit logs, platform settings. |
On top of the role, an additive Groups layer grants extra granular permissions without changing anyone's portal.
Feature map
| Area | What's there |
|---|---|
| Roles & access control | Five roles, the additive Groups + Permission catalog, the encrypted security keyword for sensitive actions, Global Admin company-access approval. |
| Authentication | Native email / password, login OTP, password reset, Keycloak browser SSO, shared-directory LDAP provisioning, per-tenant LDAP / AD federation. |
| Attendance & timesheets | Work sessions with breaks, internal-work tracking, correction requests, admin manual entry, daily / weekly summaries and analytics. |
| Leave management | Leave types and balances, employee requests, team-leader and HR approval, balance adjustments. |
| Payroll & salary | Payroll runs with approval and lock, salary components and structures, auto-payroll, manual entry, payslip generation and settings, salary-revision history. |
| Finance Hub | Reimbursement claims, tax declarations, manual and auto invoicing, employee bank details with verification, Razorpay payments. |
| Employee lifecycle | Onboarding, employee documents with AI OCR extraction, HR letters (offer, relieving, revision…), org hierarchy, the exit / offboarding portal. |
| Performance | Performance data and structured feedback per employee. |
| Assets, policies & support | Asset assignment and tracking, the policy vault, internal and client support tickets, notifications. |
| Branded company email | Per-tenant sending domain over AWS SES — SPF / DKIM / DMARC records and a verification lifecycle. |
| Subscriptions & plans | Plan catalog, the feature catalog, FIXED / CUSTOM / ALL plan types, per-company feature toggles, demo and plan requests, renewal reminders. |
| Administration | The Global Admin console, activity logs, audit logs, maintenance mode, deployment mode. |
| Installation · Configuration | Docker deployment, the required secrets, the full environment reference, optional integrations. |
| Security model | JWT auth, field encryption, tenant isolation, the security keyword, support-access approval, audit trail. |
Architecture
| Part | Stack |
|---|---|
| Backend | Spring Boot — REST API, Spring Security (JWT), Spring Data JPA, Spring Data LDAP, Spring Mail |
| Frontend | React + Vite, Tailwind |
| Database | PostgreSQL (one database per app; tenants share it, isolated by tenant_code) |
| Media | Local upload volume, or Cloudinary when configured |
| Optional | Keycloak (SSO), LDAP / AD, AWS SES (branded email), Razorpay (payments), OpenAI (document OCR) |
Ships as a single Docker image (Spring Boot serving the built frontend). See Installation.
License
Proprietary — Zlabs Innovation Software License. Not open-source. Commercial and enterprise licensing: sales@hrida.ai.