What this does
Indian SMEs juggle a long list of statutory obligations and a shorter — but sharper — set of data-protection duties. WorkRight gives HR admins three surfaces to stay on top of both: a tenant-scoped audit log of who-did-what-when, a compliance command center that shows the next due date for each obligation, and DPDP-aligned consent captured as part of normal HR flows. An optional analytics dashboard rounds out the picture for workforce trends.
Who can do it
- HR admins (
company_adminorhr_manager): the audit log, the compliance dashboard and the analytics dashboard are all restricted to HR admins, both in the UI and on the server. Regular employees don't see them. - Everyone: their own actions are recorded in the audit log, and they give DPDP consent at the points the product asks for it.
The audit log
WorkRight records every state-changing action automatically, scoped to your company. HR admins open it under Settings → Audit log to see who did what, and when. It is the evidence trail behind your statutory records — the kind of who-changed-this-record history that POSH §11 and the DPDP Act §11(1)(d)expect you to be able to produce. You don't turn it on; it is always running.
The compliance command center
The Compliance page is a single calendar of your Indian SME statutory obligations, each with its statute reference and the next due date, computed for you:
- Monthly: PF/ECR, ESI and Professional Tax (due the 15th of the next month), plus GST returns where applicable.
- Quarterly: TDS 24Q.
- Annual / periodic:the POSH §21 annual report (due 31 January), the Shops & Establishments return, Bonus Form D, Maternity §11A, and LWF.
Each card shows a status — filed for this period, overdue, or pending— and links straight to the generator that produces the filing. There's no period picker to fiddle with: the dates are anchored to today, so HR sees the current obligation set at a glance.
DPDP & confidentiality
WorkRight captures employee consent in line with the Digital Personal Data Protection (DPDP) Act as part of normal HR flows, and keeps a record of it. Sensitive surfaces are protected accordingly — for example, POSH complaint data is treated as confidential, kept off the public API, and the committee surface sits behind strict two-factor (see POSH training & complaints). Together with the always-on audit log, this is what lets you show, not just assert, that personal data is handled responsibly.
Related
- Roles & access — who can see the audit log and compliance dashboard.
- Set up POSH & the ICC — the §21 annual report that the compliance calendar tracks.