Workforce access with boundaries built in.
EscoHR's product design connects to Escochex Payroll for identity and role context, requests sensitive device permissions only when they are relevant, and keeps private workflows scoped to authorized participants.
Escochex-managed identity
Sign-in uses existing Escochex Payroll credentials. Company access and assigned roles are resolved from Escochex rather than created inside EscoHR.
Session verification
New authenticated sessions include a one-time verification code, with resend, expiry and failed-attempt states in the product flow.
Device re-entry
A valid session can be unlocked using supported device security such as Face ID or a device PIN without selecting a different role.
Event-based location
Location is requested for attendance events to confirm a worksite or approved remote location. The product design explicitly rejects continuous location tracking.
Just-in-time attachments
Camera or file access is requested when an employee chooses to attach content to a supported workflow, not as background access.
Private HR cases
Employee cases are scoped to the reporter and the assigned authorized HR Admin, with reassignment and resolution history preserved.
Useful alerts without exposing the case on the lock screen.
The product design uses general notification wording for sensitive updates, then deep-links the authenticated user to the authoritative record inside EscoHR.
If a user's Escochex role or company access changes, EscoHR requires refreshed authentication instead of continuing with stale permissions.
Read how EscoHR handles personal information.
The Privacy Policy distinguishes employer-controlled workforce data from app operations and explains location, attachments, notifications, access, retention and privacy requests.