Start with the required outcome, authority, and policy
A record, field, enum, feature id, or widget does not create a complete HR, payroll, attendance, scheduling, compliance, or legal-evidence process.
Short answer
A staff and work-record layer. Reviewed evidence shows no complete HR system.
Current Open Mercato supports teams, operational roles, staff profiles, leave requests, planner availability, time entries, timers and time projects. Reviewed evidence does not show a complete HRIS, HCM, payroll, attendance, shift scheduling, statutory personnel file, or labor-compliance outcome.
Choose with named record authority, policy owner, reconciliation and acceptance evidence.
- 1. Use Open Mercato as a bounded staff and work-record layer
- 2. Extend it for an organization-specific process
- 3. Integrate an HR, payroll, attendance or project authority
- 4. Keep the specialist system authoritative and reference selected records
- Reviewed
- 2026-07-14
- Current develop
- 01911d00e28f44cf484d0b1d04860dcfef5370bf (v0.6.5-1202-g01911d00e)
- Latest public tag and root version
- v0.6.5 · 0.6.5
- Changelog caveat
- The untagged 0.6.6 section provides current develop evidence. The latest reviewed public release remains v0.6.5.
This guide provides no employment, payroll, tax, privacy, legal-timekeeping, labor-law, scheduling, productivity or production assurance.
Capability and evidence vocabulary
- available
- configurable
- custom
- integration-required
- latest public release
- current develop
- current first-party documentation
- specification or plan
- external primary requirement
- editorial recommendation
Not established in reviewed evidence describes an evidence conclusion. The capability model still has four states.
Capability matrix with owners and limits
1. Teams
- state
- available
- surface
- record, API and operator page
- evidence
- current develop · 2026-07-14
- limitation
- Scoped operational grouping with no legal hierarchy or reporting lines
- confidence
- high for named surface, conditional for outcome
- revision
- 01911d00e28f
- owner
- people operations
2. Operational team roles
- state
- available
- surface
- record and operator page
- evidence
- current develop · 2026-07-14
- limitation
- Labels do not grant RBAC or approval authority
- confidence
- high for named surface, conditional for outcome
- revision
- 01911d00e28f
- owner
- people operations
3. Staff profiles
- state
- available
- surface
- record, API and operator page
- evidence
- current develop · 2026-07-14
- limitation
- A profile does not serve as an authentication user or governed HR master
- confidence
- high for named surface, conditional for outcome
- revision
- 01911d00e28f
- owner
- people operations
4. Optional authentication-user link
- state
- configurable
- surface
- staff member field and self route
- evidence
- current develop · 2026-07-14
- limitation
- Optional link needs an identity and reconciliation contract
- confidence
- high for named surface, conditional for outcome
- revision
- 01911d00e28f
- owner
- identity owner
5. Active state
- state
- available
- surface
- record lifecycle field
- evidence
- current develop · 2026-07-14
- limitation
- Covers the record lifecycle without creating complete joiner, mover, leaver, payroll, or retention processes
- confidence
- high for named surface, conditional for outcome
- revision
- 01911d00e28f
- owner
- application owner
6. Tags
- state
- configurable
- surface
- profile field and search
- evidence
- current develop · 2026-07-14
- limitation
- Taxonomy, access and sensitive inference need governance
- confidence
- high for named surface, conditional for outcome
- revision
- 01911d00e28f
- owner
- data owner
7. System and custom fields
- state
- configurable
- surface
- custom-field definitions
- evidence
- current develop · 2026-07-14
- limitation
- Data definitions do not execute payroll, onboarding or policy
- confidence
- high for named surface, conditional for outcome
- revision
- 01911d00e28f
- owner
- schema owner
8. Addresses
- state
- available
- surface
- related record and profile surface
- evidence
- current develop · 2026-07-14
- limitation
- Purpose, access, correction and retention are deployment decisions
- confidence
- high for named surface, conditional for outcome
- revision
- 01911d00e28f
- owner
- privacy owner
9. Job history
- state
- available
- surface
- related record and profile surface
- evidence
- current develop · 2026-07-14
- limitation
- Job history does not provide a contract, tenure calculation, or legal employment file
- confidence
- high for named surface, conditional for outcome
- revision
- 01911d00e28f
- owner
- people operations
10. Notes and activities
- state
- available
- surface
- related records
- evidence
- current develop · 2026-07-14
- limitation
- Potentially sensitive operational records. They do not constitute performance management
- confidence
- high for named surface, conditional for outcome
- revision
- 01911d00e28f
- owner
- privacy owner
11. Attachments
- state
- configurable
- surface
- shared attachment infrastructure
- evidence
- current develop · 2026-07-14
- limitation
- Shared attachment infrastructure does not provide a personnel file, DMS, archive, or signature workflow
- confidence
- high for named surface, conditional for outcome
- revision
- 01911d00e28f
- owner
- records owner
12. Global search
- state
- available
- surface
- search presenters
- evidence
- current develop · 2026-07-14
- limitation
- Indexed names, descriptions and tags need privacy acceptance
- confidence
- high for named surface, conditional for outcome
- revision
- 01911d00e28f
- owner
- security and privacy
13. Leave requests
- state
- available
- surface
- records, pages, API and commands
- evidence
- current develop · 2026-07-14
- limitation
- A workflow request is not entitlement, balance, accrual, or a payroll effect
- confidence
- high for named surface, conditional for outcome
- revision
- 01911d00e28f
- owner
- people operations
14. Leave decisions
- state
- available
- surface
- accept and reject commands
- evidence
- current develop · 2026-07-14
- limitation
- Approval records a workflow state but does not confirm legal validity in a given country
- confidence
- high for named surface, conditional for outcome
- revision
- 01911d00e28f
- owner
- authorized manager
15. Availability rules
- state
- configurable
- surface
- planner rule sets and staff bridge
- evidence
- current develop · 2026-07-14
- limitation
- Planning input does not create a published shift or attendance fact
- confidence
- high for named surface, conditional for outcome
- revision
- 01911d00e28f
- owner
- planning owner
16. Effective availability
- state
- available
- surface
- planner service
- evidence
- current develop · 2026-07-14
- limitation
- Timezone and exceptions still require scenario acceptance
- confidence
- high for named surface, conditional for outcome
- revision
- 01911d00e28f
- owner
- planning owner
17. Time entries
- state
- available
- surface
- records, API and grid or list UI
- evidence
- current develop · 2026-07-14
- limitation
- Reported time capture is not approval, payability, billing, or legal sufficiency
- confidence
- high for named surface, conditional for outcome
- revision
- 01911d00e28f
- owner
- time-policy owner
18. Timer
- state
- available
- surface
- operator UI and guarded commands
- evidence
- current develop · 2026-07-14
- limitation
- Single-active-timer hardening does not prove accurate work
- confidence
- high for named surface, conditional for outcome
- revision
- 01911d00e28f
- owner
- application owner
19. Work and break segments
- state
- available
- surface
- segment records and API
- evidence
- current develop · 2026-07-14
- limitation
- Segment type does not enforce break law or payroll policy
- confidence
- high for named surface, conditional for outcome
- revision
- 01911d00e28f
- owner
- time-policy owner
20. Time projects
- state
- available
- surface
- records, API and operator page
- evidence
- current develop · 2026-07-14
- limitation
- Project and cost-center references do not provide project accounting
- confidence
- high for named surface, conditional for outcome
- revision
- 01911d00e28f
- owner
- project owner
21. Project membership
- state
- available
- surface
- membership record and API
- evidence
- current develop · 2026-07-14
- limitation
- Role, dates and visibility do not grant RBAC or capacity
- confidence
- high for named surface, conditional for outcome
- revision
- 01911d00e28f
- owner
- project owner
22. Customer, deal and order references
- state
- configurable
- surface
- time-entry identifiers
- evidence
- current develop · 2026-07-14
- limitation
- Identifiers do not prove validation, billing or profitability
- confidence
- high for named surface, conditional for outcome
- revision
- 01911d00e28f
- owner
- integration owner
23. Analytics mapping
- state
- available
- surface
- time-entry analytics presenter
- evidence
- current develop · 2026-07-14
- limitation
- Mapping does not define payable hours, utilization or KPI semantics
- confidence
- high for named surface, conditional for outcome
- revision
- 01911d00e28f
- owner
- reporting owner
24. Dashboard widgets
- state
- available
- surface
- quick timer and hours by project
- evidence
- current develop · 2026-07-14
- limitation
- Operational views are not reconciled management reports
- confidence
- high for named surface, conditional for outcome
- revision
- 01911d00e28f
- owner
- reporting owner
25. Notifications and message objects
- state
- available
- surface
- leave notification and message surfaces
- evidence
- current develop · 2026-07-14
- limitation
- Delivery and action links do not settle entitlement or authority
- confidence
- high for named surface, conditional for outcome
- revision
- 01911d00e28f
- owner
- workflow owner
26. Lifecycle events
- state
- available
- surface
- event definitions
- evidence
- current develop · 2026-07-14
- limitation
- Event names do not prove subscribers or downstream outcomes
- confidence
- high for named surface, conditional for outcome
- revision
- 01911d00e28f
- owner
- integration owner
27. Feature permissions
- state
- configurable
- surface
- staff ACL
- evidence
- current develop · 2026-07-14
- limitation
- Approve and lock ids do not prove timesheet flows exist
- confidence
- high for named surface, conditional for outcome
- revision
- 01911d00e28f
- owner
- access owner
28. Tenant and organization scope
- state
- available
- surface
- records, routes and tests
- evidence
- current develop · 2026-07-14
- limitation
- Effective access still needs negative cross-scope acceptance
- confidence
- high for named surface, conditional for outcome
- revision
- 01911d00e28f
- owner
- security owner
29. Optimistic and transactional guards
- state
- available
- surface
- selected commands and routes
- evidence
- current develop · 2026-07-14
- limitation
- Guards cover specific conflicts and give no universal audit assurance
- confidence
- high for named surface, conditional for outcome
- revision
- 01911d00e28f
- owner
- application owner
30. Undo surfaces
- state
- configurable
- surface
- selected commands
- evidence
- current develop · 2026-07-14
- limitation
- Undo coverage and external effects require operation-level review
- confidence
- high for named surface, conditional for outcome
- revision
- 01911d00e28f
- owner
- application owner
31. Integration seams
- state
- custom
- surface
- APIs, commands, events and module boundaries
- evidence
- current develop · 2026-07-14
- limitation
- Extension points only. No maintained HRIS, payroll, or attendance connector
- confidence
- high for named surface, conditional for outcome
- revision
- 01911d00e28f
- owner
- integration owner
32. Timesheet approval and locking
- state
- integration-required
- surface
- ACL vocabulary and Phase 2 plan
- evidence
- current develop · 2026-07-14
- limitation
- Not established in reviewed runtime entities, routes, commands, events and pages
- confidence
- high for named surface, conditional for outcome
- revision
- 01911d00e28f
- owner
- time-policy owner
Identity contract: keep eleven records separate
Record authority, stable abstract key, creation, update, merge, disablement, deletion, reconciliation and owner.
- 1
Authentication user: sign-in principal and feature grants
- 2
Directory organization: platform data-scope boundary
- 3
Staff member: operational profile, optionally linked to a user
- 4
Team: operational grouping
- 5
Team role: operational label without RBAC grants
- 6
RBAC role: access-policy container
- 7
Availability rule set: planning input
- 8
Time project: time-attribution record
- 9
Project membership: assignment metadata
- 10
Customer, deal or order reference: optional business identifier
- 11
External HR or payroll person id: specialist-system join key
A staff member may exist without a user. A user is not automatically a governed staff profile. Team role ids are operational labels: they grant no RBAC, name no manager, and authorize no leave or timesheet decisions. A team is not automatically a legal organization, reporting line, cost-center hierarchy, payroll unit or scheduling group.
Active and soft-delete fields manage the record lifecycle without creating complete joiner, mover, leaver, access-revocation, payroll-termination, or retention processes.
Staff-data minimization and stewardship register
Define purpose, sensitivity, source of truth, allowed editors and readers, searchability, encryption evidence, attachment exposure, retention, correction, deletion, export, downstream consumers, review owner and acceptance evidence.
- 1. Display name
- 2. Description
- 3. Authentication-user link
- 4. Team
- 5. Operational roles
- 6. Tags
- 7. Availability link
- 8. Active state
- 9. Custom fields
- 10. Address
- 11. Job history
- 12. Comments
- 13. Activities
- 14. Leave note
- 15. Decision comment
- 16. Free-text unavailability reason
- 17. Time notes
- 18. Attachments
- 19. Search documents
The reviewed default staff encryption map covers leave note, decision comment and free-text unavailability reason only. It does not encrypt all staff data or attachments. Encrypted-at-rest handling does not settle display access, logs, search, exports, backups, keys, retention, legal access, correction or deletion. Global search covers teams, members, roles and time projects, so indexed fields need a privacy and access acceptance test.
System-defined fields include hourly rate and currency, employment date and type, an onboarded flag, years of experience, bio, focus areas and work mode. These fields define data. They do not create payroll, invoicing, compensation validation, onboarding workflow, legal employment status, or work-policy enforcement.
Leave and availability are separate layers
- 1
Request with pending, approved or rejected state
- 2
Decision with submitter, decider, timestamp and comment
- 3
Notification and message action
- 4
Recurring availability rule
- 5
Date-specific availability or unavailability
- 6
Effective schedule calculation
- 7
Staffing or assignment decision
- 8
Attendance fact
- 9
Payroll effect
- 10
Legal entitlement and evidence
Current leave records support pending, approved and rejected; a bounded reason or free text; note; submitter; decider; decision comment and timestamp; personal and administrative views; notifications and message actions. Reviewed evidence does not show balances, accrual, carryover, statutory types, public holidays, part-day units, payroll effect, substitute coverage, supporting-document rules, or country-specific validity.
Accept inclusive or exclusive dates, timezone, daylight-saving changes, cross-midnight periods, partial days, overlaps, cancellation, correction, absence without request and changed entitlement explicitly. Planner has timezone-aware recurring and date-specific availability or unavailability, exceptions, reason fields, self or all-member access and an effective-availability service. Availability provides planning input without defining published shifts, assignments, attendance, capacity, or legal working-time calculations. Planner fails closed for staff-managed writes when staff is missing.
Time capture and project control map
Name source, authority, validation, permission, correction, evidence, failure, reconciliation and owner.
- 1. Member and work date
- 2. Integer duration in minutes
- 3. Timer start and end
- 4. Work and break segments
- 5. Note purpose and sensitivity
- 6. Time project
- 7. Customer, deal and order references
- 8. Source enum: manual, timer, kiosk or mobile
- 9. Project code and state
- 10. Owner user and cost-center text
- 11. Project assignment and role
- 12. Grid visibility
- 13. Assignment dates
- 14. One-entry maximum: 1,440 minutes
- 15. Bulk-save maximum: 200 rows
- 16. Single-active-timer invariant
- 17. Organization scope
- 18. Correction path
- 19. Approval and lock authority
- 20. Export and specialist reconciliation
Duration is stored in integer minutes. Current validation caps one entry at 1,440 minutes and a bulk save at 200 rows. Current UI provides weekly or monthly grid and list experiences, timer behavior, project management, a quick-timer widget and hours-by-project view. Kiosk and mobile enum values do not prove shipped kiosk hardware, a mobile application, offline capture, geolocation, biometrics, or trusted-device controls.
Approve and lock feature ids exist. The reviewed runtime entities, routes, commands, events and pages contain no timesheet approval or locking flows. The runtime has Phase-1-shaped capture and project work; reviewed evidence does not show approval, locking, rates, billing, utilization, payroll and policy. Customer, deal, order, owner-user and cost-center references serve as identifiers without providing cross-record validation, billing, project accounting, wage costing, invoice generation, profitability, or utilization governance. Single-active-timer and transaction guards cover specific mechanisms without providing accuracy, audit, wage, billing or legal assurance.
- Allowed capture methods
- Rounding
- Timezone and daylight saving
- Overlaps
- Crossing midnight
- Break handling
- Missing timers
- Proxy entry
- Backdating
- Edits and reason
- Approval
- Lock and close
- Reopen and post-close correction
- Project and customer attribution
- Payroll interpretation
- Billing interpretation
- Export
- Reconciliation and evidence retention
Responsibility matrix
Assign responsible, accountable, consulted and informed roles, denied combinations, evidence, backup and escalation.
- 1. People operations
- 2. Line manager
- 3. Project owner
- 4. Employee or worker
- 5. Finance and payroll
- 6. Application owner
- 7. Security and privacy
- 8. Integration owner
- 9. External specialist provider
Specialist-system boundary matrix
Record expected outcome, current reviewed evidence, missing controls, likely system of record, handoff, reconciliation, acceptance evidence and stop condition. Keep the specialist authority external until every item is accepted.
- 1. HR master
- 2. Recruitment and ATS
- 3. Onboarding
- 4. Contracts and e-signature
- 5. Personnel file and DMS
- 6. Payroll, tax and social insurance
- 7. Benefits
- 8. Performance and goals
- 9. Learning and compliance training
- 10. Leave entitlement and accrual
- 11. Shift scheduling and optimization
- 12. Time and attendance authority
- 13. Expenses and travel
- 14. PSA and project accounting
- 15. Invoicing and rates
- 16. Governed BI
- 17. Identity and SSO
- 18. Legal and compliance evidence
Current package and release chronology
- 1
v0.4.9 release listed a timesheets specification; the runtime feature had yet to ship
- 2
Current develop contains the reviewed staff and Phase 1-shaped time runtime
- 3
v0.6.5 is the latest reviewed public tag and records staff/planner hardening
- 4
The 0.6.6 changelog section is untagged. The latest reviewed public release remains v0.6.5
Staff is currently a first-party, MIT, ejectable module registered from @open-mercato/core and requires planner plus resources. Contributor material describes intended future extraction. That plan supplies no package name, date, migration path, support contract or parity.
Set authority before considering branding
- 1
Name the required workforce outcome and competent authority
- 2
Identify legal, payroll, privacy and operating constraints
- 3
Choose authoritative records and abstract identity keys
- 4
Classify each need with one of the four capability states
- 5
Map permissions, allowed data and prohibited data
- 6
Define handoffs, failures, reconciliation and correction
- 7
Run acceptance cases including negative and privacy tests
- 8
Stop when authority, evidence or ownership is missing
Three synthetic operating scenarios
Hypothetical only
1. Synthetic project-services team
- outcome
- Abstract project time attribution
- authority
- External HR and payroll
- identity
- Abstract staff and project keys
- data
- Minimal profile and time data
- capture
- Manual grid and timer
- owner
- Project operations
- failure
- Missing timer and wrong project
- reconciliation
- Weekly project exception review
- acceptance
- Scoped capture and export evidence
- decision
- Bounded use only
Hypothetical only
2. Synthetic operations team with external specialists
- outcome
- Selected profile and availability references
- authority
- External HR, payroll and attendance
- identity
- Abstract external-person and staff keys
- data
- No health, compensation or contract data
- capture
- Attendance remains external
- owner
- People operations
- failure
- Identity mismatch and stale availability
- reconciliation
- Daily exception file
- acceptance
- Cross-system and access tests
- decision
- Integration-required
Hypothetical only
3. Synthetic stop scenario
- outcome
- Statutory time, payroll and optimized shifts
- authority
- Not assigned
- identity
- No stable person key
- data
- Sensitive scope unowned
- capture
- Biometric and geolocation required
- owner
- Missing
- failure
- No correction or legal evidence path
- reconciliation
- Missing
- acceptance
- Not available
- decision
- Stop and select specialist authority
Local planning tool
Staff and workforce decision worksheet
Starts empty and remains browser-local. It provides no HR, payroll, legal, privacy, timekeeping, scheduling or go-live approval.
Do not enter real data: Use abstract role and system labels only. Never enter real employee names, addresses, absence or health details, compensation, contracts, performance notes, credentials, project or customer identifiers, times, rates, costs, endpoints, legal cases or production configuration.
Privacy: The page does not send worksheet content, put it in the URL, or store it in cookies.
Poor fit without verified specialist architecture
- Payroll is the core requirement: keep or select a specialist authority and obtain competent review.
- Statutory timekeeping lacks validated controls: keep or select a specialist authority and obtain competent review.
- Leave entitlement is complex or multi-jurisdictional: keep or select a specialist authority and obtain competent review.
- Shift optimization or demand forecasting is required: keep or select a specialist authority and obtain competent review.
- Attendance hardware, geolocation or biometrics are required: keep or select a specialist authority and obtain competent review.
- Recruitment, performance, benefits or learning are deep domains: keep or select a specialist authority and obtain competent review.
- Multi-country HR compliance is expected: keep or select a specialist authority and obtain competent review.
- Sensitive-data governance has no accountable owner: keep or select a specialist authority and obtain competent review.
- Project accounting, rates or invoicing must be authoritative: keep or select a specialist authority and obtain competent review.
Acceptance pack
Specify setup, actor, abstract ids, allowed and denied path, expected evidence, failure injection, correction, reconciliation, owner and pass criterion.
- 1. Route and draft isolation
- 2. Staff profile without user
- 3. User without governed staff profile
- 4. Team role does not grant RBAC
- 5. Cross-organization denial
- 6. Profile field minimization
- 7. Search exposure
- 8. Attachment access
- 9. Custom-field purpose
- 10. Leave create and personal view
- 11. Leave administrative queue
- 12. Leave accept and reject
- 13. Finalized leave conflict
- 14. Timezone and date semantics
- 15. Cross-midnight absence
- 16. Daylight-saving change
- 17. Partial-day requirement
- 18. Overlapping leave and availability
- 19. Leave correction and cancellation
- 20. Missing staff dependency fails closed
- 21. Recurring availability
- 22. Date-specific exception
- 23. Self-only availability write
- 24. All-member availability write
- 25. Manual time entry
- 26. Grid and list time views
- 27. Start and stop timer
- 28. Concurrent timer start
- 29. Work and break segments
- 30. 1440-minute validation
- 31. 200-row bulk boundary
- 32. Overlap policy
- 33. Midnight and timezone policy
- 34. Proxy and backdated entry
- 35. Project assignment dates
- 36. Grid visibility
- 37. Customer, deal and order reference
- 38. No automatic billing
- 39. No automatic payroll
- 40. No runtime approval flow
- 41. No runtime lock flow
- 42. Kiosk enum is not a shipped kiosk
- 43. Mobile enum is not a shipped app
- 44. Export and specialist reconciliation
- 45. Correction after close
- 46. Retention and deletion
- 47. No-JavaScript method
- 48. Print manager brief
- 49. Browser-local privacy sentinel
- 50. Conditional owner sign-off
Stop conditions
- No employee-data owner.
- No stable identity key.
- No lawful and approved data purpose.
- No specialist authority where required.
- No reconciliation owner.
- No correction path.
- No privacy and access acceptance test.
- No time policy.
- No acceptance evidence.
Practical questions
Can a staff profile exist without a login?
Yes. Staff records and user accounts are separate. A team role describes operational work and does not itself grant RBAC permissions or approval authority.
Does approved leave calculate payroll or entitlement?
The reviewed leave request states support a decision on a request. Entitlement balances, accrual, payroll and country-specific employment rules need a defined authoritative system and integration.
Are timesheet approvals and locks implemented?
The reviewed runtime does not establish timesheet approval or locking flows. Feature identifiers alone are insufficient evidence. Test the required approval and correction process before adopting time entries for payroll.
Can the module replace an HR or payroll system?
Evaluate operational staff, leave and time needs separately from legal personnel records and payroll. Keep the specialist system authoritative where those obligations exceed the verified implementation.
Source ledger and correction path
Capability and limitation reviewed 2026-07-14. Report corrections through this site with the exact claim, source revision and replacement evidence.
- 1. v0.6.5 public release, 2026-06-15: latest public release and staff/planner hardening
- 2. Current develop at the reviewed revision: entities, routes, commands, events and tests
- 3. First-party teams, members, leave and availability documentation
- 4. Implemented timesheets specification: phase context only, runtime remains authoritative
- 5. Current app registries: staff is loaded from @open-mercato/core
- 6. Editorial recommendation: choose authority, controls and reconciliation before configuration
Latest reviewed public release · Immutable reviewed staff source