Start with the required outcome, authority, and policy

A record, field, enum, feature id, or widget does not create a complete HR, payroll, attendance, scheduling, compliance, or legal-evidence process.

Short answer

A staff and work-record layer. Reviewed evidence shows no complete HR system.

Current Open Mercato supports teams, operational roles, staff profiles, leave requests, planner availability, time entries, timers and time projects. Reviewed evidence does not show a complete HRIS, HCM, payroll, attendance, shift scheduling, statutory personnel file, or labor-compliance outcome.

Choose with named record authority, policy owner, reconciliation and acceptance evidence.

  • 1. Use Open Mercato as a bounded staff and work-record layer
  • 2. Extend it for an organization-specific process
  • 3. Integrate an HR, payroll, attendance or project authority
  • 4. Keep the specialist system authoritative and reference selected records
Reviewed
2026-07-14
Current develop
01911d00e28f44cf484d0b1d04860dcfef5370bf (v0.6.5-1202-g01911d00e)
Latest public tag and root version
v0.6.5 · 0.6.5
Changelog caveat
The untagged 0.6.6 section provides current develop evidence. The latest reviewed public release remains v0.6.5.

This guide provides no employment, payroll, tax, privacy, legal-timekeeping, labor-law, scheduling, productivity or production assurance.

Capability and evidence vocabulary

  • available
  • configurable
  • custom
  • integration-required
  • latest public release
  • current develop
  • current first-party documentation
  • specification or plan
  • external primary requirement
  • editorial recommendation

Not established in reviewed evidence describes an evidence conclusion. The capability model still has four states.

Capability matrix with owners and limits

1. Teams

state
available
surface
record, API and operator page
evidence
current develop · 2026-07-14
limitation
Scoped operational grouping with no legal hierarchy or reporting lines
confidence
high for named surface, conditional for outcome
revision
01911d00e28f
owner
people operations

2. Operational team roles

state
available
surface
record and operator page
evidence
current develop · 2026-07-14
limitation
Labels do not grant RBAC or approval authority
confidence
high for named surface, conditional for outcome
revision
01911d00e28f
owner
people operations

3. Staff profiles

state
available
surface
record, API and operator page
evidence
current develop · 2026-07-14
limitation
A profile does not serve as an authentication user or governed HR master
confidence
high for named surface, conditional for outcome
revision
01911d00e28f
owner
people operations

4. Optional authentication-user link

state
configurable
surface
staff member field and self route
evidence
current develop · 2026-07-14
limitation
Optional link needs an identity and reconciliation contract
confidence
high for named surface, conditional for outcome
revision
01911d00e28f
owner
identity owner

5. Active state

state
available
surface
record lifecycle field
evidence
current develop · 2026-07-14
limitation
Covers the record lifecycle without creating complete joiner, mover, leaver, payroll, or retention processes
confidence
high for named surface, conditional for outcome
revision
01911d00e28f
owner
application owner

6. Tags

state
configurable
surface
profile field and search
evidence
current develop · 2026-07-14
limitation
Taxonomy, access and sensitive inference need governance
confidence
high for named surface, conditional for outcome
revision
01911d00e28f
owner
data owner

7. System and custom fields

state
configurable
surface
custom-field definitions
evidence
current develop · 2026-07-14
limitation
Data definitions do not execute payroll, onboarding or policy
confidence
high for named surface, conditional for outcome
revision
01911d00e28f
owner
schema owner

8. Addresses

state
available
surface
related record and profile surface
evidence
current develop · 2026-07-14
limitation
Purpose, access, correction and retention are deployment decisions
confidence
high for named surface, conditional for outcome
revision
01911d00e28f
owner
privacy owner

9. Job history

state
available
surface
related record and profile surface
evidence
current develop · 2026-07-14
limitation
Job history does not provide a contract, tenure calculation, or legal employment file
confidence
high for named surface, conditional for outcome
revision
01911d00e28f
owner
people operations

10. Notes and activities

state
available
surface
related records
evidence
current develop · 2026-07-14
limitation
Potentially sensitive operational records. They do not constitute performance management
confidence
high for named surface, conditional for outcome
revision
01911d00e28f
owner
privacy owner

11. Attachments

state
configurable
surface
shared attachment infrastructure
evidence
current develop · 2026-07-14
limitation
Shared attachment infrastructure does not provide a personnel file, DMS, archive, or signature workflow
confidence
high for named surface, conditional for outcome
revision
01911d00e28f
owner
records owner

12. Global search

state
available
surface
search presenters
evidence
current develop · 2026-07-14
limitation
Indexed names, descriptions and tags need privacy acceptance
confidence
high for named surface, conditional for outcome
revision
01911d00e28f
owner
security and privacy

13. Leave requests

state
available
surface
records, pages, API and commands
evidence
current develop · 2026-07-14
limitation
A workflow request is not entitlement, balance, accrual, or a payroll effect
confidence
high for named surface, conditional for outcome
revision
01911d00e28f
owner
people operations

14. Leave decisions

state
available
surface
accept and reject commands
evidence
current develop · 2026-07-14
limitation
Approval records a workflow state but does not confirm legal validity in a given country
confidence
high for named surface, conditional for outcome
revision
01911d00e28f
owner
authorized manager

15. Availability rules

state
configurable
surface
planner rule sets and staff bridge
evidence
current develop · 2026-07-14
limitation
Planning input does not create a published shift or attendance fact
confidence
high for named surface, conditional for outcome
revision
01911d00e28f
owner
planning owner

16. Effective availability

state
available
surface
planner service
evidence
current develop · 2026-07-14
limitation
Timezone and exceptions still require scenario acceptance
confidence
high for named surface, conditional for outcome
revision
01911d00e28f
owner
planning owner

17. Time entries

state
available
surface
records, API and grid or list UI
evidence
current develop · 2026-07-14
limitation
Reported time capture is not approval, payability, billing, or legal sufficiency
confidence
high for named surface, conditional for outcome
revision
01911d00e28f
owner
time-policy owner

18. Timer

state
available
surface
operator UI and guarded commands
evidence
current develop · 2026-07-14
limitation
Single-active-timer hardening does not prove accurate work
confidence
high for named surface, conditional for outcome
revision
01911d00e28f
owner
application owner

19. Work and break segments

state
available
surface
segment records and API
evidence
current develop · 2026-07-14
limitation
Segment type does not enforce break law or payroll policy
confidence
high for named surface, conditional for outcome
revision
01911d00e28f
owner
time-policy owner

20. Time projects

state
available
surface
records, API and operator page
evidence
current develop · 2026-07-14
limitation
Project and cost-center references do not provide project accounting
confidence
high for named surface, conditional for outcome
revision
01911d00e28f
owner
project owner

21. Project membership

state
available
surface
membership record and API
evidence
current develop · 2026-07-14
limitation
Role, dates and visibility do not grant RBAC or capacity
confidence
high for named surface, conditional for outcome
revision
01911d00e28f
owner
project owner

22. Customer, deal and order references

state
configurable
surface
time-entry identifiers
evidence
current develop · 2026-07-14
limitation
Identifiers do not prove validation, billing or profitability
confidence
high for named surface, conditional for outcome
revision
01911d00e28f
owner
integration owner

23. Analytics mapping

state
available
surface
time-entry analytics presenter
evidence
current develop · 2026-07-14
limitation
Mapping does not define payable hours, utilization or KPI semantics
confidence
high for named surface, conditional for outcome
revision
01911d00e28f
owner
reporting owner

24. Dashboard widgets

state
available
surface
quick timer and hours by project
evidence
current develop · 2026-07-14
limitation
Operational views are not reconciled management reports
confidence
high for named surface, conditional for outcome
revision
01911d00e28f
owner
reporting owner

25. Notifications and message objects

state
available
surface
leave notification and message surfaces
evidence
current develop · 2026-07-14
limitation
Delivery and action links do not settle entitlement or authority
confidence
high for named surface, conditional for outcome
revision
01911d00e28f
owner
workflow owner

26. Lifecycle events

state
available
surface
event definitions
evidence
current develop · 2026-07-14
limitation
Event names do not prove subscribers or downstream outcomes
confidence
high for named surface, conditional for outcome
revision
01911d00e28f
owner
integration owner

27. Feature permissions

state
configurable
surface
staff ACL
evidence
current develop · 2026-07-14
limitation
Approve and lock ids do not prove timesheet flows exist
confidence
high for named surface, conditional for outcome
revision
01911d00e28f
owner
access owner

28. Tenant and organization scope

state
available
surface
records, routes and tests
evidence
current develop · 2026-07-14
limitation
Effective access still needs negative cross-scope acceptance
confidence
high for named surface, conditional for outcome
revision
01911d00e28f
owner
security owner

29. Optimistic and transactional guards

state
available
surface
selected commands and routes
evidence
current develop · 2026-07-14
limitation
Guards cover specific conflicts and give no universal audit assurance
confidence
high for named surface, conditional for outcome
revision
01911d00e28f
owner
application owner

30. Undo surfaces

state
configurable
surface
selected commands
evidence
current develop · 2026-07-14
limitation
Undo coverage and external effects require operation-level review
confidence
high for named surface, conditional for outcome
revision
01911d00e28f
owner
application owner

31. Integration seams

state
custom
surface
APIs, commands, events and module boundaries
evidence
current develop · 2026-07-14
limitation
Extension points only. No maintained HRIS, payroll, or attendance connector
confidence
high for named surface, conditional for outcome
revision
01911d00e28f
owner
integration owner

32. Timesheet approval and locking

state
integration-required
surface
ACL vocabulary and Phase 2 plan
evidence
current develop · 2026-07-14
limitation
Not established in reviewed runtime entities, routes, commands, events and pages
confidence
high for named surface, conditional for outcome
revision
01911d00e28f
owner
time-policy owner

Identity contract: keep eleven records separate

Record authority, stable abstract key, creation, update, merge, disablement, deletion, reconciliation and owner.

  1. 1

    Authentication user: sign-in principal and feature grants

  2. 2

    Directory organization: platform data-scope boundary

  3. 3

    Staff member: operational profile, optionally linked to a user

  4. 4

    Team: operational grouping

  5. 5

    Team role: operational label without RBAC grants

  6. 6

    RBAC role: access-policy container

  7. 7

    Availability rule set: planning input

  8. 8

    Time project: time-attribution record

  9. 9

    Project membership: assignment metadata

  10. 10

    Customer, deal or order reference: optional business identifier

  11. 11

    External HR or payroll person id: specialist-system join key

A staff member may exist without a user. A user is not automatically a governed staff profile. Team role ids are operational labels: they grant no RBAC, name no manager, and authorize no leave or timesheet decisions. A team is not automatically a legal organization, reporting line, cost-center hierarchy, payroll unit or scheduling group.

Active and soft-delete fields manage the record lifecycle without creating complete joiner, mover, leaver, access-revocation, payroll-termination, or retention processes.

Staff-data minimization and stewardship register

Define purpose, sensitivity, source of truth, allowed editors and readers, searchability, encryption evidence, attachment exposure, retention, correction, deletion, export, downstream consumers, review owner and acceptance evidence.

  • 1. Display name
  • 2. Description
  • 3. Authentication-user link
  • 4. Team
  • 5. Operational roles
  • 6. Tags
  • 7. Availability link
  • 8. Active state
  • 9. Custom fields
  • 10. Address
  • 11. Job history
  • 12. Comments
  • 13. Activities
  • 14. Leave note
  • 15. Decision comment
  • 16. Free-text unavailability reason
  • 17. Time notes
  • 18. Attachments
  • 19. Search documents

The reviewed default staff encryption map covers leave note, decision comment and free-text unavailability reason only. It does not encrypt all staff data or attachments. Encrypted-at-rest handling does not settle display access, logs, search, exports, backups, keys, retention, legal access, correction or deletion. Global search covers teams, members, roles and time projects, so indexed fields need a privacy and access acceptance test.

System-defined fields include hourly rate and currency, employment date and type, an onboarded flag, years of experience, bio, focus areas and work mode. These fields define data. They do not create payroll, invoicing, compensation validation, onboarding workflow, legal employment status, or work-policy enforcement.

Leave and availability are separate layers

  1. 1

    Request with pending, approved or rejected state

  2. 2

    Decision with submitter, decider, timestamp and comment

  3. 3

    Notification and message action

  4. 4

    Recurring availability rule

  5. 5

    Date-specific availability or unavailability

  6. 6

    Effective schedule calculation

  7. 7

    Staffing or assignment decision

  8. 8

    Attendance fact

  9. 9

    Payroll effect

  10. 10

    Legal entitlement and evidence

Current leave records support pending, approved and rejected; a bounded reason or free text; note; submitter; decider; decision comment and timestamp; personal and administrative views; notifications and message actions. Reviewed evidence does not show balances, accrual, carryover, statutory types, public holidays, part-day units, payroll effect, substitute coverage, supporting-document rules, or country-specific validity.

Accept inclusive or exclusive dates, timezone, daylight-saving changes, cross-midnight periods, partial days, overlaps, cancellation, correction, absence without request and changed entitlement explicitly. Planner has timezone-aware recurring and date-specific availability or unavailability, exceptions, reason fields, self or all-member access and an effective-availability service. Availability provides planning input without defining published shifts, assignments, attendance, capacity, or legal working-time calculations. Planner fails closed for staff-managed writes when staff is missing.

Time capture and project control map

Name source, authority, validation, permission, correction, evidence, failure, reconciliation and owner.

  • 1. Member and work date
  • 2. Integer duration in minutes
  • 3. Timer start and end
  • 4. Work and break segments
  • 5. Note purpose and sensitivity
  • 6. Time project
  • 7. Customer, deal and order references
  • 8. Source enum: manual, timer, kiosk or mobile
  • 9. Project code and state
  • 10. Owner user and cost-center text
  • 11. Project assignment and role
  • 12. Grid visibility
  • 13. Assignment dates
  • 14. One-entry maximum: 1,440 minutes
  • 15. Bulk-save maximum: 200 rows
  • 16. Single-active-timer invariant
  • 17. Organization scope
  • 18. Correction path
  • 19. Approval and lock authority
  • 20. Export and specialist reconciliation

Duration is stored in integer minutes. Current validation caps one entry at 1,440 minutes and a bulk save at 200 rows. Current UI provides weekly or monthly grid and list experiences, timer behavior, project management, a quick-timer widget and hours-by-project view. Kiosk and mobile enum values do not prove shipped kiosk hardware, a mobile application, offline capture, geolocation, biometrics, or trusted-device controls.

Approve and lock feature ids exist. The reviewed runtime entities, routes, commands, events and pages contain no timesheet approval or locking flows. The runtime has Phase-1-shaped capture and project work; reviewed evidence does not show approval, locking, rates, billing, utilization, payroll and policy. Customer, deal, order, owner-user and cost-center references serve as identifiers without providing cross-record validation, billing, project accounting, wage costing, invoice generation, profitability, or utilization governance. Single-active-timer and transaction guards cover specific mechanisms without providing accuracy, audit, wage, billing or legal assurance.

  • Allowed capture methods
  • Rounding
  • Timezone and daylight saving
  • Overlaps
  • Crossing midnight
  • Break handling
  • Missing timers
  • Proxy entry
  • Backdating
  • Edits and reason
  • Approval
  • Lock and close
  • Reopen and post-close correction
  • Project and customer attribution
  • Payroll interpretation
  • Billing interpretation
  • Export
  • Reconciliation and evidence retention

Responsibility matrix

Assign responsible, accountable, consulted and informed roles, denied combinations, evidence, backup and escalation.

  • 1. People operations
  • 2. Line manager
  • 3. Project owner
  • 4. Employee or worker
  • 5. Finance and payroll
  • 6. Application owner
  • 7. Security and privacy
  • 8. Integration owner
  • 9. External specialist provider

Specialist-system boundary matrix

Record expected outcome, current reviewed evidence, missing controls, likely system of record, handoff, reconciliation, acceptance evidence and stop condition. Keep the specialist authority external until every item is accepted.

  • 1. HR master
  • 2. Recruitment and ATS
  • 3. Onboarding
  • 4. Contracts and e-signature
  • 5. Personnel file and DMS
  • 6. Payroll, tax and social insurance
  • 7. Benefits
  • 8. Performance and goals
  • 9. Learning and compliance training
  • 10. Leave entitlement and accrual
  • 11. Shift scheduling and optimization
  • 12. Time and attendance authority
  • 13. Expenses and travel
  • 14. PSA and project accounting
  • 15. Invoicing and rates
  • 16. Governed BI
  • 17. Identity and SSO
  • 18. Legal and compliance evidence

Current package and release chronology

  1. 1

    v0.4.9 release listed a timesheets specification; the runtime feature had yet to ship

  2. 2

    Current develop contains the reviewed staff and Phase 1-shaped time runtime

  3. 3

    v0.6.5 is the latest reviewed public tag and records staff/planner hardening

  4. 4

    The 0.6.6 changelog section is untagged. The latest reviewed public release remains v0.6.5

Staff is currently a first-party, MIT, ejectable module registered from @open-mercato/core and requires planner plus resources. Contributor material describes intended future extraction. That plan supplies no package name, date, migration path, support contract or parity.

Set authority before considering branding

  1. 1

    Name the required workforce outcome and competent authority

  2. 2

    Identify legal, payroll, privacy and operating constraints

  3. 3

    Choose authoritative records and abstract identity keys

  4. 4

    Classify each need with one of the four capability states

  5. 5

    Map permissions, allowed data and prohibited data

  6. 6

    Define handoffs, failures, reconciliation and correction

  7. 7

    Run acceptance cases including negative and privacy tests

  8. 8

    Stop when authority, evidence or ownership is missing

Three synthetic operating scenarios

Hypothetical only

1. Synthetic project-services team

outcome
Abstract project time attribution
authority
External HR and payroll
identity
Abstract staff and project keys
data
Minimal profile and time data
capture
Manual grid and timer
owner
Project operations
failure
Missing timer and wrong project
reconciliation
Weekly project exception review
acceptance
Scoped capture and export evidence
decision
Bounded use only

Hypothetical only

2. Synthetic operations team with external specialists

outcome
Selected profile and availability references
authority
External HR, payroll and attendance
identity
Abstract external-person and staff keys
data
No health, compensation or contract data
capture
Attendance remains external
owner
People operations
failure
Identity mismatch and stale availability
reconciliation
Daily exception file
acceptance
Cross-system and access tests
decision
Integration-required

Hypothetical only

3. Synthetic stop scenario

outcome
Statutory time, payroll and optimized shifts
authority
Not assigned
identity
No stable person key
data
Sensitive scope unowned
capture
Biometric and geolocation required
owner
Missing
failure
No correction or legal evidence path
reconciliation
Missing
acceptance
Not available
decision
Stop and select specialist authority

Local planning tool

Staff and workforce decision worksheet

Starts empty and remains browser-local. It provides no HR, payroll, legal, privacy, timekeeping, scheduling or go-live approval.

Do not enter real data: Use abstract role and system labels only. Never enter real employee names, addresses, absence or health details, compensation, contracts, performance notes, credentials, project or customer identifiers, times, rates, costs, endpoints, legal cases or production configuration.

Privacy: The page does not send worksheet content, put it in the URL, or store it in cookies.

Required-field progress: Not started (0/20). This count tracks field completion. It does not score fit or determine readiness.
Planning row 1

Poor fit without verified specialist architecture

  • Payroll is the core requirement: keep or select a specialist authority and obtain competent review.
  • Statutory timekeeping lacks validated controls: keep or select a specialist authority and obtain competent review.
  • Leave entitlement is complex or multi-jurisdictional: keep or select a specialist authority and obtain competent review.
  • Shift optimization or demand forecasting is required: keep or select a specialist authority and obtain competent review.
  • Attendance hardware, geolocation or biometrics are required: keep or select a specialist authority and obtain competent review.
  • Recruitment, performance, benefits or learning are deep domains: keep or select a specialist authority and obtain competent review.
  • Multi-country HR compliance is expected: keep or select a specialist authority and obtain competent review.
  • Sensitive-data governance has no accountable owner: keep or select a specialist authority and obtain competent review.
  • Project accounting, rates or invoicing must be authoritative: keep or select a specialist authority and obtain competent review.

Acceptance pack

Specify setup, actor, abstract ids, allowed and denied path, expected evidence, failure injection, correction, reconciliation, owner and pass criterion.

  • 1. Route and draft isolation
  • 2. Staff profile without user
  • 3. User without governed staff profile
  • 4. Team role does not grant RBAC
  • 5. Cross-organization denial
  • 6. Profile field minimization
  • 7. Search exposure
  • 8. Attachment access
  • 9. Custom-field purpose
  • 10. Leave create and personal view
  • 11. Leave administrative queue
  • 12. Leave accept and reject
  • 13. Finalized leave conflict
  • 14. Timezone and date semantics
  • 15. Cross-midnight absence
  • 16. Daylight-saving change
  • 17. Partial-day requirement
  • 18. Overlapping leave and availability
  • 19. Leave correction and cancellation
  • 20. Missing staff dependency fails closed
  • 21. Recurring availability
  • 22. Date-specific exception
  • 23. Self-only availability write
  • 24. All-member availability write
  • 25. Manual time entry
  • 26. Grid and list time views
  • 27. Start and stop timer
  • 28. Concurrent timer start
  • 29. Work and break segments
  • 30. 1440-minute validation
  • 31. 200-row bulk boundary
  • 32. Overlap policy
  • 33. Midnight and timezone policy
  • 34. Proxy and backdated entry
  • 35. Project assignment dates
  • 36. Grid visibility
  • 37. Customer, deal and order reference
  • 38. No automatic billing
  • 39. No automatic payroll
  • 40. No runtime approval flow
  • 41. No runtime lock flow
  • 42. Kiosk enum is not a shipped kiosk
  • 43. Mobile enum is not a shipped app
  • 44. Export and specialist reconciliation
  • 45. Correction after close
  • 46. Retention and deletion
  • 47. No-JavaScript method
  • 48. Print manager brief
  • 49. Browser-local privacy sentinel
  • 50. Conditional owner sign-off

Stop conditions

  • No employee-data owner.
  • No stable identity key.
  • No lawful and approved data purpose.
  • No specialist authority where required.
  • No reconciliation owner.
  • No correction path.
  • No privacy and access acceptance test.
  • No time policy.
  • No acceptance evidence.

Practical questions

Can a staff profile exist without a login?

Yes. Staff records and user accounts are separate. A team role describes operational work and does not itself grant RBAC permissions or approval authority.

Does approved leave calculate payroll or entitlement?

The reviewed leave request states support a decision on a request. Entitlement balances, accrual, payroll and country-specific employment rules need a defined authoritative system and integration.

Are timesheet approvals and locks implemented?

The reviewed runtime does not establish timesheet approval or locking flows. Feature identifiers alone are insufficient evidence. Test the required approval and correction process before adopting time entries for payroll.

Can the module replace an HR or payroll system?

Evaluate operational staff, leave and time needs separately from legal personnel records and payroll. Keep the specialist system authoritative where those obligations exceed the verified implementation.

Source ledger and correction path

Capability and limitation reviewed 2026-07-14. Report corrections through this site with the exact claim, source revision and replacement evidence.

  • 1. v0.6.5 public release, 2026-06-15: latest public release and staff/planner hardening
  • 2. Current develop at the reviewed revision: entities, routes, commands, events and tests
  • 3. First-party teams, members, leave and availability documentation
  • 4. Implemented timesheets specification: phase context only, runtime remains authoritative
  • 5. Current app registries: staff is loaded from @open-mercato/core
  • 6. Editorial recommendation: choose authority, controls and reconciliation before configuration
Sources

Suggest a correction