HR Files
Secure document management system for HR files, candidate documents, and employee records.
Meet the agent
This app ships with a production AI agent — permission-aware, tenant-scoped, audit-logged, and governed by the Agent Development Lifecycle.
AI HR File Manager
HR documents, search, version history, and compliance review — in chat.
Overview
HR Files is the single, audience-controlled library for every employee document — offer letters, contracts, certifications, performance reviews, tax forms, medical and garnishment paperwork — so HR stops keeping the real record in a shared drive and a mailbox.
Who sees a file is a property of the file, not a folder it happens to sit in. Each document carries an audience — the employee alone, their management chain, specific roles, or the whole company — and sensitive types like medical, garnishment and disciplinary are clamped to HR and the employee no matter what else is set. On top of that, per-person access grants cover the one-off cases, with an expiry date and a full history of who was given what and when. Files of the types you designate as sensitive route through an approval queue before anyone can see them, and editing an approved file back into a sensitive state sends it around again.
Documents arrive without anyone filing them: Recruiting, Offer Manager and Onboarding push their paperwork straight in, and an optional AI pass reads each upload and suggests the type, category and expiry date for a human to confirm. Missing paperwork surfaces on a document-coverage roster, and you can ask an employee for a specific document and track the request until it lands. Expiring certifications generate reminders ahead of the date and flip to expired on their own; retention policies compute a retire-by date and notify before anything is archived. Managers pull a complete employee packet as one zip instead of clicking through files one at a time.
Every view, download, grant and approval is written to an audit trail you can filter and export, downloads of sensitive files can require re-authentication, and offboarding archives an employee's records rather than losing them.
Keep every employee document in one secure, audience-controlled library with sensitive-type clamps, per-file access grants, approval workflows, and a full audit trail on views and downloads.
Highlights
Capabilities
Access Control & Visibility
-
One audience setting per file: Private to HR · Employee only · Employee + reporting chain · Specific roles · All employees
-
Sensitive-type clamp keeps types like medical, garnishment, and disciplinary limited to HR + the assigned employee, regardless of audience
-
Per-file access grants with view / download / edit / delete / share / delegate permissions
-
Time-limited access grants that expire automatically
-
Suspend, restore, or revoke an individual person's access
-
Read-only grants allow viewing but block download
Approval Workflow
-
Sensitive documents wait in a pending-approval queue before broad audiences can see them
-
Approve/reject is admin-gated — a file's uploader cannot approve their own file
-
Bulk approve or reject from the Approvals queue
-
Editing an approved file into a sensitive state sends it back for re-approval
Auto-Sync from Connected Apps
-
Recruiting — resumes and signed offer letters
-
Onboarding Hub — tax documents, I-9, ID, and policy acknowledgments
-
E-Signature — completed signed documents
-
Forms — employee-submitted HR forms
-
Employee Profile documents
-
Per-source rules control which document types, categories, and events sync
-
Consolidate a hired candidate's recruiting + onboarding documents into their employee folder in one step
Compliance & Retention
-
Per-file expiry date with an expired-status flag
-
Dashboard alert for files expiring within 30 days
-
Compliance-document flag blocks deletion (retention hold)
-
Document-coverage roster flags employees below a document minimum
-
Optional auto-archive of an offboarded employee's non-compliance files
Audit & Export
-
Every view, download, edit, approval, and access change is logged
-
Per-file audit trail plus a business-wide audit log
-
Export the audit log to CSV, JSON, or PDF with a date range
-
Export the file list to CSV or JSON
-
Bulk exports are themselves recorded in the audit log
AI Assistant
-
Ask the AI agent to list and search your documents in chat
-
Get a document's details, versions, and access info via the agent
-
Surface documents pending approval, expiring soon, or compliance-flagged
-
Per-business toggle to enable or disable the AI agent
Storage, Uploads & Versioning
-
Amazon S3-backed storage, encrypted at rest
-
Automatic version numbering on every upload
-
View and download any prior version
-
SHA-256 hash stored per version for integrity verification
-
Bulk drag-and-drop upload with shared metadata and tags
-
Company-wide documents not tied to any single employee
-
Soft delete (with optional reason), archive, and restore — no permanent data loss
Limits & Specs
-
Max file size: 100 MB per file (500 MB for video)
-
Max files per bulk upload: 50 per batch
-
Accepted file types: PDF, DOC, DOCX, XLS, XLSX, CSV, TXT, JPG, JPEG, PNG, GIF, MP4, MOV, AVI, WEBM, MPEG
-
Download link validity: 1 hour (preview links 5 minutes)
-
Storage provider: Amazon S3, encrypted at rest
-
Pricing: License required (per-tenant opt-in)
Use cases
Resources
FAQ
HR Files requires a license and is opt-in per tenant — an administrator enables it for your business from the Apps Marketplace. It is disabled by default until then. Contact your MangoApps administrator about enabling it for your organization.
Each file has one audience setting: Private to HR, Employee only, Employee + reporting chain, Specific roles, or All employees. On top of that you can add per-person access grants (with separate view, download, edit, delete, share, and delegate permissions) that can be time-limited, suspended, or revoked. Sensitive file types such as medical, garnishment, and disciplinary are always clamped to HR plus the assigned employee, no matter the audience.
When the approval workflow is on, sensitive documents are held in a pending-approval queue and broad audiences can't see them until an administrator approves. Approve and reject are admin-gated, so a file's own uploader cannot approve it. If an already-approved file is later edited into a sensitive state, it is automatically sent back for re-approval.
HR Files does not send documents out for e-signature itself — instead it automatically imports completed signed documents from the E-Signature app, and you can flag a file as requiring a signature as a reminder. For retention, there is no automatic purge: flagging a document as a compliance record blocks deletion, expiry dates drive dashboard alerts, and you can optionally auto-archive an offboarded employee's non-compliance files. Files are always retained unless someone with permission deletes them.
Recruiting (resumes and signed offer letters), Onboarding Hub (tax documents, I-9, ID, policy acknowledgments), E-Signature (completed signed documents), Forms (employee-submitted HR forms), and Employee Profile documents. Each source has its own rules for which document types, categories, and events sync, and re-synced files create a new version rather than a duplicate.
Individual files can be up to 100 MB (500 MB for video). Bulk upload accepts up to 50 files per batch. Supported formats are PDF, DOC, DOCX, XLS, XLSX, CSV, TXT, JPG, JPEG, PNG, GIF, MP4, MOV, AVI, WEBM, and MPEG. Files are stored in Amazon S3, encrypted at rest.
The HR File Manager agent lets you list and search your documents in chat, pull up a document's details and version history, and surface documents that are pending approval, expiring soon, or compliance-flagged. It only ever returns documents you already have permission to see, and an administrator can turn it on or off per business.
Drive is general-purpose file storage for collaborative work. HR Files is purpose-built for personnel records: it adds audience gating, sensitive-type clamps, an approval workflow, retention holds, and a full access audit trail that general storage doesn't have. Employee profile documents actually sync into HR Files, so the profile stays the employee-facing view while HR Files is the governed, auditable system of record for the underlying documents.