TWO CONTROLLED ROUTES one HR system of record

Use Holly in the app. Connect your own agent too.

Holly uses each member's current permissions. API and MCP give a customer-selected agent a separate organisation-bound route.

Holly is on Standard · API and MCP reads are on every plan

Permission-aware in-app answers Explicit confirmation before changes AI remains optional
Two shipped read tools provide bounded fields; the approved assistant composes the answer.
AI-ready, in plain English

One governed record. Two deliberately different AI channels.

Holly uses the signed-in member, a pinned Bedrock route and permission-projected tools. It does not save conversation history.

API and MCP agents use separate organisation credentials, provider terms and projections. Enabling one channel never grants authority to another.

Inspect the developer contract
The key fixes the organisation. Request records capture route, outcome and row count — not prompts or returned payloads.
Start with an ordinary job

Three questions worth making easier.

01

How much leave do I have left?

Holly can answer from your current balance and link to the full record.

02

Who is away next week?

Authorised people admins can see the permission-safe organisation view.

03

Book Friday as annual leave.

Holly prepares the request and shows the exact change for confirmation.

Smaller on purpose

Every channel gets a projection, never a copy of the HR database.

Holly projects from app permissions. MCP starts from approved fields and withholds, redacts or buckets selected values. Their safeguards share intent, not authority.

  • Names, work context, dates and balances can be returned when in scope.
  • Home, bank, tax, compensation and document-file fields are withheld.
  • Detailed absence categories are reduced to a broad bucket.
An approved assistant can combine the separate people and time-off results; HollyHR does not return this as one joined record.
Human control, before the commit

An agent can prepare a change. It cannot quietly improvise one.

HollyHR freezes a validated proposal. Only that signed, short-lived payload can be confirmed after authority is checked again.

Holly currently supports explicit time-off confirmations. MCP writes retain separate Standard-plan, scope, server-enablement and host-confirmation gates.

Developer-preview contract. Writes are not generally enabled and are attributed to the API key, not a named host user.
Open platform, correctly packaged

Use an assistant when it helps. Use the API when code is clearer.

API/MCP reads and bounded webhooks are on every plan. Approved writes are separate.

API and MCP reads plus bounded signed read-event webhooks are on Free; writes need Standard and separate approval.
The important boundary

Useful access without pretending the hard decisions disappeared.

Assistance reduces lookup work. People decisions, privacy and provider due diligence remain human responsibilities.

The current contract

What a buyer can rely on.

  • Holly uses the signed-in member's fresh workspace membership and current permissions.
  • A workspace admin can turn Holly off immediately; the global route can also be disabled.
  • API and MCP use a separate organisation credential or OAuth principal and do not inherit Holly access.
Not claimed

Where the product deliberately stops.

  • No autonomous HR, legal or employment decisions.
  • No saved Holly conversation history or silent record changes.
  • No claim that Holly and a customer-selected agent use the same processor, identity or projection.
AI and HR software questions

Clear answers before you connect anything.

Availability, data access, human control, compliance and cost in plain English.

What is Holly?

Holly is HollyHR's in-app assistant. It answers approved questions within the member's current permissions and prepares supported actions for confirmation.

Who provides Holly's AI model?

Holly uses Claude Sonnet 4.6 through a pinned Amazon Bedrock EU geographic profile with retention set to none, invocation logging unconfigured and no model fallback.

Does Holly save conversations?

No. History stays in the browser session. Operational records contain outcomes, coarse usage and feedback—not questions, answers or tool results.

Can an organisation disable Holly?

Yes. An authorised workspace admin can switch Holly off or on. Membership and permissions are still checked on every request.

Can Claude, ChatGPT or another assistant connect to HollyHR?

Yes. API and MCP use a separate organisation credential. The chosen agent and provider retain their own terms, retention and processing choices.

What can an assistant read from HollyHR?

Approved MCP tools cover people, time off and reference data. Positive projections withhold selected sensitive fields and bucket absence categories.

Can an assistant change an HR record?

Holly can prepare supported time-off changes for confirmation. MCP writes use the same frozen write-intent domain with separate scopes and host confirmation.

Is connecting an AI assistant automatically UK GDPR compliant?

No. Your organisation must assess access and the chosen provider's retention, training, region and subprocessors.

What does AI and developer access cost?

Holly is included with Standard. API and MCP reads are on every plan; other providers set their own charges.

Ask a practical question.

Use Holly on Standard, or connect your agent through the documented API and MCP.

AI remains optional and workspace admins stay in control