The assistant acts without asking. It never acts without a record.
The honest question about any payroll tool that uses AI is what happens when it gets something wrong. Every change is written down with the value before and the value after. Some can be put back for a day, the ones that move money wait out a hold you can cancel, and the rest say plainly that they are final. Here is how to check each of those in your own account rather than taking our word for it.
It acts, and you can see all of it
The assistant makes the change itself. Rename a department and it is done, with an Undo button beside it in Agent activity for a day. Ask it to raise a salary, change bank details or lock a run and it schedules the change instead, held long enough for anyone entitled to stop it. A few things, like ending someone's employment, cannot be taken back at all, and it says so at the moment it happens.
See for yourself. Ask it to rename a department, then put it back from Agent activity.
A record of who did what
Every change, lock and decision is written down with the time, who or what did it, and the value before and after. An assistant change is marked as one. It is there when your auditor asks, and it reads like sentences rather than a database dump.
See for yourself. Open Audit and export a month as a spreadsheet.
Your accountant sees the payroll, not your people
Invite your accountant and they get what they need to file: payroll figures and reports. IC numbers, addresses and bank details are not in their account to open. You decide who is in your workspace, and nobody outside it can see your company at all.
See for yourself. Invite them, then look at what they can actually open.
The assistant can only do what you can do
It runs with your permissions, not its own. Ask it for something outside your role and it declines the same way the rest of the app would. Your staff do not have it at all.
See for yourself. Sign in as one of your employees. There is no assistant there.
You can check where the numbers come from
EPF, SOCSO, EIS, PCB and HRDF come from rate tables that carry an effective date and a link to the authority that set them. When a rate changes, your runs change with it.
See for yourself. The table below is that data, read from the payroll engine itself.
Every rate carries its source and the date it took effect
This is the part most payroll tools ask you to take on faith. Ours is a table you can audit, read straight from the same rate tables the payroll run uses.
| Code | Instrument | Rate basis | Effective from | Authority |
|---|---|---|---|---|
| EPF | Employees Provident Fund | 11% employee, 13% employer | 2025-10-01 | Third Schedule, EPF Act 1991 (KWSP) |
| SOCSO | Social Security Organisation | Wage-banded schedule | 2024-10-01 | PERKESO Act 4 / Act 800 contribution schedule |
| EIS | Employment Insurance System | Wage-banded schedule | 2024-10-01 | PERKESO Act 4 / Act 800 contribution schedule |
| PCB | Monthly Tax Deduction | Computerised MTD | 2025-01-01 | LHDN computerised MTD specification (YA2025) |
| HRDF | HRD Corp levy | Headcount-banded | 2024-01-01 | HRD Corp levy calculation guideline |
Data usage
Your employee data, payroll records and salary information are used solely to run your payroll inside your own workspace. We do not train models on your data. Assistant queries go to the model provider we run the assistant on, under their API terms, and there is no way to point the assistant at a provider of your own. If your policy requires AI processing to stay inside your own infrastructure, talk to us before you rely on this page for compliance.
PDPA posture
- Data is processed under your instructions, as a data processor.
- Tenant isolation means your data is never visible to another company.
- Audit logs provide the access records PDPA compliance requires.
- Encrypted at rest by our database and storage providers, and in transit with TLS.