Privacy — Who Sees What
Leave’s access model has one hard line: medical information stays with the leave team, plus at most one designated person on the client side. Everything else anyone sees is planning data — dates,…
Leave’s access model has one hard line: medical information stays with the leave team, plus at most one designated person on the client side. Everything else anyone sees is planning data — dates, status, approvals. The line is enforced on the server: clinical free-text is stripped out of the response before it reaches the browser, so there is nothing to leak client-side.
What’s redacted for viewers outside the boundary: the determination summary, per-program eligibility reasons, extension reasons and details, and time-off notes — and the message thread and documents are hidden entirely. What’s kept: that the case exists, the coarse leave type, key dates, status, and each program’s approval status. Where a field is withheld, the page shows a small “Restricted — visible to the HR Partner and Leave team only” note.
- The employee — Everything on their own case. — Yes — it’s theirs
- Humareso leave team — The full case, to run it. — Yes
- HR Partner (Client) — the case’s designated one — The case, including medical detail, to handle eligibility. — Yes — the only client-side yes
- Named manager / requestor (participant) — The case they’re on: status, dates, balances, program approvals — redacted free-text. — No — redacted server-side
- Company overseer (Detail mode) — Read-only view of in-scope company cases they aren’t named on. — No — redacted server-side
- Company roll-up (dashboard) — Aggregate counts (Summary mode) or case rows (Detail mode) — per the org’s choice; optionally scoped by location. — No
The three viewer tiers — participant (named on the case), overseer (Detail-mode company oversight), and operator (Humareso staff) — are explained in What you can see on a case.
Behind the scenes
- Medical/PHI content is redacted before it reaches AI drafting or error-reporting systems.
- Documents shared by email are limited to blank statutory forms explicitly confirmed to contain no PHI; everything else stays behind login.
- Every access-relevant change is audited — who, what, when.
If someone needs more access, the answer is a role change made deliberately — set them as the case’s HR Partner (Client) — never a screenshot or a forwarded email.