Employee agreement
The employee agreement as a web page: HR issues it, the employee reads and signs it, the Company countersigns it, and it is kept for good. There is no PDF file; the page is the record, and the browser's Print (or Save as PDF) makes a paper copy.
Rules: 22 · Leave and the employee agreement
(EA-001 … EA-013), ACC-081 for the reporting officer. Permissions: PERMISSIONS.md §6.21. Routes:
Leave and agreements API.
Pages: src/pages/agreements/ · text and signature helpers: src/components/agreements/.
| Page | Where | Who |
|---|---|---|
My agreement (/me/agreement, one at /me/agreement/:id) |
header Settings menu → My agreement | the employee, their own only |
Employee agreements (/hr/agreements, one at /hr/agreements/:id) |
Admin → Employee agreements | hr.agreements.view: HR, CEO, GM, Auditor |
The text
The text is the owner's Employee Agreement v3 — Clauses 1–25 and Annexures A–E — kept in the database as a template that never changes; a new text is a new version (EA-001). The bracketed blanks of the paper version are values filled per employee. The only wording the system adds is in Clause 25: a sentence that the copy is signed electronically with the record shown after it, and Witnesses (starting as "none — signed electronically with the record shown below"), in place of the paper signature and witness tables. The owner is to confirm these (EA-011, open).
The page shows the text with its headings, lists and tables. A value HR typed is shown as plain text only.
Prepare (HR) and approve (CEO)
On Employee agreements HR (hr.agreements.issue) sees every active employee and where their
agreement stands: not issued, waiting for CEO approval, waiting for the employee, waiting for the
Company, signed, superseded, withdrawn.
Issue agreement on the employee's row (Issue new version when one is already issued) opens the dialog Prepare the agreement for … with the values, grouped as in the agreement (agreement, company, employee, appointment, terms, Annexures A, B and E) (EA-002):
- filled from the employee's record: name, father's / guardian's name, address, Aadhaar / PAN (last four digits only), employee code, designation, department, reporting manager, joining date;
- filled from the company settings in Leave admin: legal name, address, the authorised signatory's name and designation;
- every other bracket starts as the text in the brackets — for example probation "six (6)", notice "60 days", leave year "1 April to 31 March"; the salary lines start as "as set out in the offer letter".
The appointment — designation, department, reporting to, date of joining (EA-012):
- Designation and Department come from the employee's profile. When the profile is empty, they come from the login's highest staff role — for example CEO → "Chief Executive Officer", Management; ADMIN_HR → "HR Manager", Human Resources; OPS_EXEC → "Operations Executive", Operations. The designation box suggests the designations already in use and the role titles; any other text can be typed.
- Reporting to is picked from the staff list — a searchable list of active staff with their designation and employee code, never the employee or anyone who reports to them (ACC-081). It is never typed and never guessed. The text in the agreement reads "Designation (Name)".
- Date of joining comes from the profile only (DD/MM/YYYY). It is never guessed.
A small tag beside each of the four says where the value came from: From profile, From role — check (read it before issuing), Missing, or Typed here. Open employee record opens the record in a new tab, to fill the other profile fields.
Father's / guardian's name comes from the profile too, with the same tag (From profile, Missing or Typed here). It is never guessed.
Also save these to the employee's profile (on by default,
EA-013): when the agreement is issued, the four
appointment values and the father's / guardian's name used are written to the profile — only those that were empty there or that HR changed — as an
Edit profile change, in the audit trail with HR's name. Writing a profile needs the same right as
Edit profile: HR's hr.profiles.edit covers every staff login except an IT Admin or Super Admin
(ACC-084),
so HR's issue saves the appointment of a salesperson, operations, finance, a manager, the GM or a
CEO. For an IT Admin or Super Admin, or for someone with neither right, the agreement is still
issued, the tick box is off and the dialog says why (for example "Not saved to the profile — HR
can't edit an IT Admin or Super Admin profile."). A joining date that is not a date is not saved;
the dialog says so.
HR changes any value and sees the whole text before sending it. An empty required value is
refused and named — for example the father's / guardian's name, or the signatory while the
setting is empty. Send to the CEO for approval freezes the text and stores its SHA-256 hash
(EA-003); the number reads EA-<employee code>-V4-<n>.
The CEO approves it before the employee sees it (EA-017). The CEOs get an e-mail and an inbox notice, and a bar on every page, Review and approve. On the agreement page a CEO reads the whole text, salary included, then Approve and send or Reject with a reason. Nobody approves an agreement they prepared or their own; a CEO's own agreement is approved by the other CEO. On approval the employee receives it (e-mail, inbox, bar) and the HR who prepared it is told; on rejection only HR is told, with the reason, and prepares it again. Preparing again replaces a version still waiting for the CEO; the approval of a new version withdraws an earlier one the employee has not signed. Withdraw (with a reason) takes back an issued agreement the employee has not signed.
The text since 02/10/2026 is version 4: version 3 with three changes — salary as approved by the CEO, with a salary slip (5.1); salary review and increments, yearly from 1 April by a written increment letter approved by the CEO, never automatic (5.6, EA-018); and how the Company may change the agreement — at once when the law requires, otherwise on 30 days' written notice, never cutting fixed salary or legal rights without consent (24.3, EA-019). Agreements already signed on version 3 stay in force until a version 4 is signed.
E-mails and reminders
Every step is e-mailed as well as put in the ERP inbox (EA-014):
| Step | Who gets the e-mail |
|---|---|
| HR prepares it | each CEO who may approve it: Review and approve |
| The CEO approves it | the employee: Read and sign; the HR who prepared it |
| The CEO rejects it | the HR who prepared it, with the reason (the employee never hears of it) |
| The employee signs | each countersigner: Open and countersign; the HR who issued it, for information |
| The Company countersigns | the employee: Open my copy; the HR who issued it |
| HR withdraws it | the employee, with HR's reason |
The e-mail is a link: it never contains the agreement or the pay. An agreement still waiting is reminded every 3 days for the employee and every 2 days for the countersigners, for 30 days (EA-015).
While an agreement waits for your signature, a bar across the top of every ERP page says so, with Read and sign; the app's home screen says the same. A countersigner sees how many wait for the Company (EA-016).
Read and sign (the employee)
My agreement lists the employee's agreements, newest first. One waiting for a signature opens with the full text and, at the end, the signing box (EA-004):
- read to the end;
- tick I have read and understood this agreement;
- type your full name exactly as it is on your record;
- draw your signature in the box (mouse, finger or pen; Clear starts again);
- confirm with your password.
The database checks the password against your login; five wrong passwords lock signing for fifteen minutes. It also checks that the text on your screen is the text issued — if not, it asks you to reload. The signature record keeps the time, the typed name, the IP address, the browser, the hash and the drawn signature. Management is told — by e-mail and in the inbox — that the agreement waits for the Company.
Countersign (the Company)
The authorised signatory (hr.agreements.countersign — CEO and GM today, see
EA-010, open) opens an agreement the employee has signed
and countersigns the same way: typed name, drawn signature and password. Your designation is
optional: left empty, the designation on the signatory's employee record is used, else the
signatory designation in Leave admin → Settings (EA-005).
Nobody countersigns their own agreement. The
employee is told — by e-mail and in the inbox — that the agreement is complete, with a link to
their copy.
The record
Each agreement page shows, under the text, the signature blocks: for the employee and for the Company, the drawn signature, the typed name, the date and time, the IP address and the browser. The header shows the agreement number, the version, the status, who issued it and when, and whether the hash still matches the text — checked in the database and again in the browser (EA-003).
Print prints the page, or saves it as PDF through the browser's print dialog. The printout carries the text and the signature blocks, without the menus.
Permanent
An agreement is never deleted, and its text, hash, values and signatures never change; its status only moves forward (EA-007). A change is a new version, issued and signed again; when it is countersigned the older one shows Superseded and stays readable (EA-006). Every issue, withdrawal, signature, countersignature and wrong password is in the audit trail.
Not built
- A PDF file. Deliberately: the owner asked for a web page. The browser prints it.
- A copy on the Google Shared Drive. The agreement lives in the database only.
- Aadhaar eSign or a digital signature certificate. This is a simple electronic signature with an audit trail (EA-009).
- Witnesses. There are none; the value says so.
- Editing a signed agreement. By design (EA-007): issue a new version.
- Printing from the phone app. The app reads and signs; printing is on the web.
- Approving on the phone. The CEO's home screen says what waits and opens the website, where the whole text and the salary are read before approving.
- Increment letters and change notices in the system (EA-018, EA-019). They are letters signed by the CEO for now.
- A guessed reporting officer or joining date. When the profile has none, HR picks or types it (EA-012).
- Saving an IT Admin's or Super Admin's appointment as HR. Issuing never widens who may edit a profile (EA-013, ACC-084); an admin updates their own profile, or another admin does.