Leave & PTOBeginner

Privacy — Who Sees What

By Jamie AquilaLast updated Jul 20, 2026

Leave’s access model has one hard line: medical information stays with the leave team, plus at most one designated person on the client side. Everything else anyone sees is planning data — dates,…

Leave’s access model has one hard line: medical information stays with the leave team, plus at most one designated person on the client side. Everything else anyone sees is planning data — dates, status, approvals. The line is enforced on the server: clinical free-text is stripped out of the response before it reaches the browser, so there is nothing to leak client-side.

What’s redacted for viewers outside the boundary: the determination summary, per-program eligibility reasons, extension reasons and details, and time-off notes — and the message thread and documents are hidden entirely. What’s kept: that the case exists, the coarse leave type, key dates, status, and each program’s approval status. Where a field is withheld, the page shows a small “Restricted — visible to the HR Partner and Leave team only” note.

  • The employeeEverything on their own case.Yes — it’s theirs
  • Humareso leave teamThe full case, to run it.Yes
  • HR Partner (Client) — the case’s designated oneThe case, including medical detail, to handle eligibility.Yes — the only client-side yes
  • Named manager / requestor (participant)The case they’re on: status, dates, balances, program approvals — redacted free-text.No — redacted server-side
  • Company overseer (Detail mode)Read-only view of in-scope company cases they aren’t named on.No — redacted server-side
  • Company roll-up (dashboard)Aggregate counts (Summary mode) or case rows (Detail mode) — per the org’s choice; optionally scoped by location.No

The three viewer tiers — participant (named on the case), overseer (Detail-mode company oversight), and operator (Humareso staff) — are explained in What you can see on a case.

Behind the scenes

  • Medical/PHI content is redacted before it reaches AI drafting or error-reporting systems.
  • Documents shared by email are limited to blank statutory forms explicitly confirmed to contain no PHI; everything else stays behind login.
  • Every access-relevant change is audited — who, what, when.
If someone needs more access, the answer is a role change made deliberately — set them as the case’s HR Partner (Client) — never a screenshot or a forwarded email.

Related articles