Holly and developer access

Use Holly in the app. Connect your own agent too.

Ask about people, time off and how to use HollyHR. Holly answers inside each member's permissions, while API and MCP give your own tools a separate route.

Holly and read-only developer access are available on the Free plan.

HollyHR keeps the people recordEach route has its own identity and controls
Holly in the appUses the signed-in member's current permissions.
Your chosen agentUses a separate organisation credential and scopes.
Fresh permission checkCurrent membership and permissions are checked for each request.
Holly and customer-connected assistants use separate access routes.
Holly in the app

Ask about the work already in HollyHR.

Holly can find approved information, explain product help and prepare selected time-off actions. It does not make employment decisions for you.

Find an answer

Ask about people, time off, policies or how to use the product.

Current access

The answer stays inside the signed-in member's organisation and current permissions.

Confirm a change

Supported changes wait for the member to review and confirm.

1
Ask HollyA plain-language question
2
Check accessFresh membership and permissions
3
Answer or prepareMember confirmation required for changes
Holly reads approved context and waits for member confirmation before a supported change.
Practical controls

Holly follows each member's permissions.

  • Holly uses fresh workspace membership and the member's current permissions.
  • An authorised workspace admin can turn Holly off for the organisation.
  • Holly does not save conversation history.
  • Operational records contain outcomes and coarse usage, not prompts or returned payloads.
Organisation settingHolly can be turned off immediately.
Member accessPermission is checked on each request.
Explicit confirmationSupported changes wait for approval.
Your own tools

Connect an approved assistant with narrowly scoped access.

API and MCP use a separate organisation credential. Reads return bounded fields, and the external provider keeps its own terms and processing choices.

Reads and webhooks are on every plan

Approved organisation-scoped read access is available on every plan. Every plan can manage the shipped, event-bounded signed webhook surface for data its API key can read.

Connections receive only the approved fields needed for the request, not a joined copy of the whole HR record.

Standard includes System Admin-scoped writes

Included on Standard and above. System Admins explicitly grant each write scope; MCP writes remain governed by the production safety switch. Changes run only when that action is enabled and separately scoped.

Activity records show which organisation connection made the request.

ORG
Separate organisation credentialIt does not inherit Holly access
READ
Approved fields onlyUseful fields returned while higher-risk fields stay out
WRITE
Separate scope and confirmationOnly for an enabled supported action
A customer-controlled credential fixes the organisation, then scopes narrow the tools it can call.
Model route

Holly runs through Amazon Bedrock.

HollyHR uses its current approved Claude model through Amazon Bedrock. The model route is separate from any external assistant your organisation connects.

Holly starts in AWS London and can use Bedrock's listed European destination regions. The full route is published in the subprocessor register.

Bedrock is configured not to retain Holly's requests or responses, and model invocation logging is off for this route.
In-app assistant
Holly
Managed route
Amazon Bedrock
Model
HollyHR's current approved Claude model
Retention
Requests and responses are not retained for this route
Holly's current approved model route. Customer-connected assistants use their own provider.
Before a change

Review every proposed change before it reaches the record.

Holly prepares supported actions for a member to review and confirm. Employment, legal and HR decisions stay with your team.
1
PrepareShow the proposed supported change
2
ReviewDisplay what will change
3
ConfirmCommit only after explicit approval
Every supported change waits for a separate confirmation step.
AI FAQ

The practical questions about access, providers and cost.

What is Holly?

Holly is HollyHR's in-app assistant. It answers approved questions within the signed-in member's current permissions and can prepare supported actions for confirmation.

Who provides Holly's AI model?

Holly runs through Amazon Bedrock using HollyHR's current approved Claude model. The route is configured not to retain requests or responses, and Bedrock model-invocation logging is off.

Does Holly save conversations?

No. Holly does not save conversation history. Operational records contain outcomes, coarse usage and feedback, not questions, answers or tool results.

Can an organisation disable Holly?

Yes. An authorised workspace admin can switch Holly off or on. Membership and permissions are still checked on every request.

Can Claude, ChatGPT or another assistant connect to HollyHR?

Yes. API and MCP use a separate organisation credential. The chosen agent and provider retain their own terms, retention, training and processing choices.

What can an assistant read from HollyHR?

Approved connections can read selected people, time-off and reference fields. Higher-risk fields stay out of the response, and absence details are reduced to broader categories.

Can an assistant change an HR record?

Holly can prepare a supported change when that action is enabled, but every change waits for confirmation. MCP writes use separate scopes and confirmation in the connected assistant.

What does AI and developer access cost?

Holly, API reads and MCP reads are on every plan. Standard includes System Admin-scoped writes. Usage allowances and the customer's chosen external AI provider can still affect cost.

Start with Holly. Connect more when you need it.

Holly is available on every plan. API and MCP reads are there when your team wants a separate, governed route.

Organisation-bound access, public developer docs and explicit confirmation for supported changes.