# Run HR files in Nucleus One

Employee files with access control that actually holds: per-folder sharing on top of Direct assignments, the fields and tags that make records findable, and onboarding as a repeatable workflow process.

Product: nucleus-one · Audience: catalog-administrator · Time: 60 minutes · Last verified: 2026-09-05

Canonical: https://help.ademero.com/nucleus-one/using-nucleus-one/run-hr-files-in-nucleus-one

**At the end of this recipe, each employee's file lives in a folder only the right people can open, every document in it is findable by field and tag, and onboarding runs as a process that assigns its own tasks — the HR wall built from standard parts.**

HR's defining requirement is the opposite of AP's: not routing speed, but *containment*. Build the access model first and everything else sits safely inside it.

## Part 1 — The access model (the part to get right)

Two layers combine into "only the right people":

1. **Project-wide default: Direct assignments.** In **Settings** > **Project Profile**, under **Member access**, set **Folders & documents** to **Direct assignments**. Non-admin members now see *nothing* in the documents area except what's explicitly shared with them. Confirming the change warns it takes time to propagate to all items — that's normal.

2. **Per-folder shares open the doors.** Each folder's **Properties & sharing** has a **Share with people (optional)** list — the people who can reach that folder. Subfolders inherit (the dialog shows **Shared by inheritance**), so share at the level that matches the secret: the whole `HR team` at the root of routine records; a specific manager on their own team's folders only.

Finish the wall with two more Project Profile settings: **Disallow content removal by project members** (on), and remember **Project Manager** is the role that sees everything — grant it accordingly, and use **Groups** (**Settings** > **Groups**, e.g. `HR team`) so shares name a group's worth of people in one line.

> **NOTE:** What restricted members experience is silence, not a locked door — folders they lack simply don't appear. When someone says "the folder is missing," that's the access model working; check the folder's share list, not for a bug.

## Part 2 — Structure and findability

- **Folders:** one per employee (`Last, First`), with standard subfolders if you like — `Onboarding`, `Reviews`, `Benefits`. Create them as you hire; a **New folder** right-click is the whole ceremony.
- **Fields** (**Settings** > **Fields** — create by name, then set **Data type** in properties): `Employee Name` (Text), `Hire Date` (Date), `Document Category` (Text with **List items**: Offer, I-9, W-4, Review, Certification…), `Expiration Date` (Date) for the certifications and work authorizations that age out.
- **Tags** mark cross-cutting states a field shouldn't own — `needs-signature`, `confidential`, `2026-review-cycle`. Type them on any document's tag control; they're created on first use.

The payoff is [advanced search](/nucleus-one/using-nucleus-one/find-anything-with-advanced-search): Document Category *word starts with* `Certification`, Expiration Date **is between and including** today and 90 days out — the expiring-credentials report, from criteria, in seconds. Save it as a template.

## Part 3 — Onboarding as a process

**Settings** > **Workflow Processes** > **+** `Onboarding`. The HR flavor of workflow is task-shaped:

- **Trigger: Document upload** scoped to intake (a signed offer arriving), or **Form submit** if you front onboarding with a form — a new-hire form with **Project Field** inputs feeds clean data straight in ([Build and submit forms](/nucleus-one/using-nucleus-one/build-and-submit-forms)).
- **Task** actions assign the checklist — collect the I-9, order equipment, schedule orientation — each **Assigned to** the right person. Give tasks **Task Milestones** and **Task States** (both under Settings; each is just a name and an order) that mirror your real stages: `Offer accepted`, `First day`, `30-day check-in`.
- **Approval** where sign-off matters (manager confirms the file is complete), **E-mail** where people just need to know.

Assignees see their work in **My Work** — the checklist runs itself instead of living in someone's memory.

## Part 4 — Intake for the paper

Signed documents arrive by **Document upload** (drag and drop), **Document scan** from a Windows desktop with the Capture Agent, or form submissions. With required fields set, intake pauses at **Tags & Field Values** — an employee file where every document carries its name, category, and dates is the file you'll actually be able to audit.

**Success check:** sign in as a test member who's shared into exactly one employee folder. They should see that folder, that folder only, and find its documents by field search — while a colleague with no shares sees an empty documents area. Then run one onboarding through the process and watch the tasks land in **My Work**.

## What's next

- [Manage project users and groups](https://help.ademero.com/nucleus-one/administration/manage-project-users-and-groups)
- [Run accounts payable in Nucleus One](https://help.ademero.com/nucleus-one/using-nucleus-one/run-accounts-payable-in-nucleus-one)
