HollyHR Developer Docs
  • Developer platform
  • GitHub
  • Sign in
  • Manage API keys
  • Start Here
  • Core API
  • AI and MCP
  • API Reference
  • Integrations
  • Recipes
  • Resources
HollyHR MCPAI connectorsReviewer demo guideAI safety and privacy
AI and MCP

AI safety and privacy

HollyHR's API and MCP surfaces are designed for controlled HR integrations, not unbounded data export. API-key and OAuth connector access are organisation-scoped, scope-limited, audited, and revocable.

During Public Preview, HollyHR MCP accepts scoped bearer API keys for server-side clients and OAuth 2.1 for interactive connector hosts. OAuth creates a stable, revocable organisation-bound principal after the signed-in System Admin selects an organisation and approves the requested scopes. The model cannot select an organisation, principal or scope.

What clients can see

Clients can only access data covered by the scopes you grant. For MCP, HollyHR also applies a stricter server-side projection layer:

  • tenant id is derived from the authenticated principal and is never accepted as tool input;
  • MCP outputs exclude payroll, bank, tax, government identifiers, compensation, home contact details, document links, document filenames, explicit sickness totals, and raw sensitive absence labels;
  • absence and document metadata are bucketed where needed to reduce special-category inference;
  • daily HR-data row ceilings limit broad workforce extraction;
  • request logs record source, status, request id, and row counts rather than raw model prompts or returned HR payloads.

Writes

Reads are available on every plan. Standard and higher plans include governed MCP writes without a separate HollyHR approval, but a System Admin must explicitly select every write scope. HollyHR also retains an independent global production emergency switch:

Code
HOLLYHR_MCP_WRITE_MODE=enabled

Writes require:

  • ordinary REST write scopes for the data being changed;
  • the additional mcp:write opt-in scope;
  • modern input_required host approval, so the user sees and approves the action;
  • a frozen server-signed payload;
  • idempotency keys and ETags where the REST API requires them;
  • a human-entered business reason for lifecycle writes.

Hosts that do not support modern approval, including stateless legacy clients, cannot commit MCP writes.

Customer responsibility

Only connect HollyHR to tools you trust. A third-party MCP host, AI client, or integration platform may process data under its own terms. Review the client's data handling, retention, training, subprocessors, and region controls before granting a production API key or OAuth consent.

Use a disposable synthetic tenant for demos, directory review, and partner proofs. Do not use a real customer tenant for experiments.

Review status

HollyHR's internal DPIA/DPO sign-off for MCP and AI-agent access is approved. That approval depends on System Admins explicitly granting mcp:write plus each underlying write scope; it does not permit HollyHR to add write scopes silently to existing connections or API keys. Customers remain responsible for their own DPIA, policies and rollout decisions when connecting third-party AI services to employee data.

For integration questions or security concerns, contact support.

Last modified on October 6, 2026
Reviewer demo guide
On this page
  • What clients can see
  • Writes
  • Customer responsibility
  • Review status