HR Lockbox
A private place for an employee to give HR documents to named people. The employee owns their files; administrators decide who can read them; every time a document is opened, that is recorded and the employee can see it.
This is not the Restricted Vault
The two are easy to confuse and behave almost oppositely, so it is worth being explicit:
- Restricted Vault - administrators author the documents; selected people are granted read access. Write is OrgAdmin-only.
- HR Lockbox - the employee authors the documents, in their own space. Administrators never write into it, and being an administrator does not by itself let anyone read one.
For employees (My TATER → My Lockbox)
Add a document, and it can be opened by you and by the people listed at the top of the page. That list is shown again inside the add dialog, next to the button that commits the file, so you can see who will be able to read it before you decide.
- You can see who has access. Always, on the page itself.
- You can see every time one of your documents is opened - who opened it and when - from the Who opened it button on any document.
- You do not control the access list. Your organisation's administrators do, and they set it in Manage. You will be emailed when it changes.
Withdrawing a document
The control is called Withdraw, not Delete, because of what it does and does not do:
- The people who could read it lose access, and they are told that you withdrew it. An HR record should not be able to disappear as though it never existed.
- The record that it was added and withdrawn is kept.
- Anyone who already opened it still has their copy. TATER cannot take that back.
- A document under legal hold cannot be withdrawn. You will be told that it is held, and by whom to ask about it.
What this protection is, and is not
Access is enforced by TATER: the API checks, on every single open, whether you are the owner or on the access list, and refuses otherwise. It is not enforced by encryption.
The people who run your organisation's IT systems can reach the underlying storage directly. That is stated in the product at upload time and it is stated here, because a security promise that is not quite true is worse than a smaller promise that is.
What the model does guarantee is narrower and real:
- Being an administrator grants no access on its own. Only the named people, and the employee, can open a document through TATER.
- An administrator can add themselves to the list - and cannot do it quietly. The change is visible to every employee who holds a document, is emailed to them, and is written to the audit log.
- TATER Security staff and any MSP operating your tenant are refused outright, regardless of the list.
- Assistant channels are refused. A document cannot be pulled into an AI transcript, even by its own owner.
For administrators (Manage → HR Lockbox Access)
One list, for the whole organisation, of who can read HR lockbox documents. Three things about it are worth knowing before you change it:
- It is retroactive. Anyone you add can open every document employees have already put in their lockboxes, including documents added before today under a shorter list.
- Every employee holding a document is emailed when the list changes, and told who was added or removed.
- Adding yourself is allowed and is not private. It appears in each employee's own record of who can read their documents.
Each document also records who could see it at the time it was uploaded, so "who had access to this in March?" is answerable from the record rather than reconstructed from today's list.
What the notifications say
Alerts say that something happened, never what. A document's title, filename and category never appear in an email - only an opaque reference like LBX-7QK4M2 and a link into TATER.
This is deliberate. Mail lands in shared mailboxes, on phone lock screens and in archives; a subject line naming the document would defeat the lockbox without anyone opening a file, and no access control inside TATER could take it back.
Retention
A withdrawn document’s file is retained for seven years and then permanently deleted by a nightly sweep. The record that the document existed, who could see it, and when it was withdrawn is kept regardless — only the file itself is removed, and the employee’s own history ends with an entry saying so rather than simply stopping.
Documents under legal hold are exempt from both withdrawal and deletion, and the sweep reports what it skipped and why rather than passing over it silently.
Seven years is fixed for every organisation on the platform, and is not configurable per organisation. It is set in the platform code, so changing it is a release rather than a setting an administrator can adjust. If seven years conflicts with your own record-retention schedule, raise it with us rather than looking for a control — there isn’t one.
The window is stamped onto a document at the moment it is withdrawn, not recomputed later. So if the platform’s retention period were ever changed, documents withdrawn before that change would keep the window they were originally given — a retention commitment already made to an employee is not re-dated quietly.