Employment Records
Keep the Employment and Working-Time Records the Law Asks For
Who was employed, on what terms, in which country, what they did on each day, and how long every one of those has to be kept. Enlivy holds the employment record as a record, with the rules coming from the person's own jurisdiction rather than your company address.
Create a free accountFree account, no card needed. The Payroll pack is €19.99/month, excluding VAT, and you add it in the app.
ONE ROW HOLDS IT ALL
The Employment Is the Spine
Everything else hangs off it: the contract, the working-time record, the payslips.
An employment is one row that says who is engaged, under what kind of arrangement, in which country, on which timezone, and from when.
Working-time days, and payslips linked to an employment, take their rules from the employment, not from your organization.
A Romanian company with a remote employee in Spain gets Spanish rules for that person, automatically, everywhere the rules are consulted.
-
Jurisdiction splits by concern:
the country governing working time is not always the one governing payroll, social security or tax, so each is named separately rather than assumed.
-
Down to the subdivision:
a US state or a Spanish autonomous community can be named, and is checked against the country it is claimed to belong to.
-
Seven kinds of engagement
Permanent, fixed term, part time, day labourer, copyright, contractor and internship.
-
Its own timezone
Anchored per employment, not per company, so a distributed team does not share one clock.
-
Where the facts came from
A start date carries its source, so an inferred date never reads as a confirmed one.
-
Official registration, stated
Every employment says where it stands with the official registry: unknown, not required, required or confirmed. It is never quietly implied to be done.
-
Agreements on record
Elections such as a UK 48 hour opt-out or a working-time exemption are held with their date, their evidence and their end.
-
Survives the person leaving
The identity is kept encrypted on the employment, so the record outlives the user account being removed.
The Questions Arrive Years After the Work
An inspection, a dispute, a former employee asking for proof.
-
The pontaj lives in a spreadsheet
Without Enlivy: One file per month, on somebody's drive, with no history of who changed what. When a month is questioned, there is no way to show it was not edited afterwards.
With Enlivy: Every change keeps the previous state and who made the change, and an hourly scan checks for anything that changed without going through the app.
-
Nobody signed anything
Without Enlivy: The record says a person worked those hours, but nothing shows anyone ever confirmed it was right.
With Enlivy: A month can be confirmed by a second party in the organization, and correcting a confirmed day voids that confirmation rather than hiding it.
-
A remote hire breaks the rules you built
Without Enlivy: You set the company up for one country's labour rules, then hired someone who lives under another set entirely.
With Enlivy: Rules are resolved from the employment, and the country governing working time is named separately from the ones governing payroll, social security and tax.
-
Nobody knows what can be deleted
Without Enlivy: Data you are required to keep sits beside data you are required to remove, and nobody wants to be the one who guesses wrong.
With Enlivy: Retention is a policy with the statute cited, the sweep reports before it acts, and anything unverified is undeletable by construction.
THE DAILY RECORD
A Month at a Time, Authored by People
One row per day, saying what the person actually did.
A whole month is written in a single pass.
Each day states its disposition: worked, absent, a rest day, a public holiday, a scheduled non-working day, or honestly not recorded.
Days that carry hours can carry the interval instead, and the hours are calculated from it. A record that can disagree with itself is not a record.
-
No job ever writes a day:
gaps are detected and reported, never filled in overnight. A nightly job that completed the record would be manufacturing evidence.
-
Romania asks for start and end:
where the local rules require the times, any day carrying hours has to supply both, and the record enforces it.
-
Ten absence reasons
Annual, paid event, unpaid, sick, work accident, maternity, paternity, parental, carers leave and unexcused absence.
-
Overtime, night and weekend
Counted in their own buckets, so premiums can be worked out from the record.
-
Hours you cannot double-state
A day that records an interval may not also assert its own hour count. The span minus the break is the answer.
-
Health detail stays private
The reason behind a sickness absence is hidden below a dedicated permission that sits in no integration scope.
-
Work site per day
Where the work happened is part of what the day asserts, not a property of the company.
-
A timesheet your accountant can read
Through the API, export the month in the shape the person doing the payroll actually wants.
Getting the Record Started
Four steps, and the record answers for itself.
Nothing here runs on a schedule and nothing fills itself in. You state what happened, the system keeps every version of what you stated, and your team confirms it.
-
Create the Employment
The person, the kind of engagement, the country and timezone, the job title, and the contract it was agreed under. This is the row everything else hangs off.
-
Set the Working-Time Terms
The agreed norm, in hours or in days, and from when it applies. Terms change over time, and the record keeps every version.
-
Record the Month
Fill the grid: what each day was, the hours or the interval behind them, and the reason for any absence. Save the month in one pass.
-
Confirm and Keep
Attest the month in the app. From there the retention policy knows how long it has to be kept, and why.
Offers, contracts, invoices and payments
The Answer Is Already in the Record
When an inspection asks who worked when, on what terms, and what they were paid, the answer is in one place and it is already written down.
Free account, no card · Payroll pack €19.99/month · Prices exclude VAT
EVIDENCE, HANDLED HONESTLY
Confirmed by Your Team. Watched by the System.
A record only helps if you can say who wrote it, who confirmed it, and whether it changed since.
A month can be attested by a second party in the organization.
Every content change files the previous state, its hash, its version and its author before the new state lands.
An hourly scan re-checks those hashes and never repairs a mismatch: repairing legal evidence would falsify it.
-
We say tamper-evident, not tamper-proof:
the hash covers what the day asserts happened. Anyone who can write to the database could recompute it. This catches accident and casual interference, and we would rather say so than imply a seal we do not have.
-
Correcting an attested day voids that attestation:
and what was confirmed is kept, so nobody can quietly amend a month somebody already signed off.
-
Every day shows where it stands
Each recorded day in the grid reads Confirmed, Not Confirmed or Confirmation Withdrawn.
-
Attestation needs completeness
A month can only be confirmed once the employment's own window inside it is actually complete.
-
Provenance cannot be forged
Who recorded a day, when, and how it was attested are set by the system and refused from the request.
-
Every prior version is kept
Each correction keeps the day's previous content, its version and who replaced it.
-
Confirming is not changing
The hash covers the facts, not the audit envelope, so an attestation never reads as tampering.
-
Never repaired automatically
The scan only reads the days it checks. No automatic correction, ever.
HOW LONG YOU MUST KEEP IT
Retention That Names the Law It Comes From
A retention rule is not a number of years in a settings screen. It is a document class, in a jurisdiction, over an effective window, with a condition and a citation.
- The clock is pinned to the statute With the law named, not a rule of thumb.
- Romania: the daily record is kept five years from the end of the financial year
- Legea 82/1991 art. 25, as amended by Legea 36/2023
- Never shortened by counting from the day itself
- Unknown means undeletable A rule we have not verified cannot authorize a deletion.
- Unverified retention blocks the sweep by construction
- Nothing is removed on an assumption
- A protected record is refused outright
- A sweep that reports before it acts Report-only unless it is explicitly applied.
- Dry run by default
- Refuses anything protected or not researched firm
- Counts what would go before anything does
What We Do, and What We Do Not
Two boundaries worth stating plainly, because a payroll product that leaves them vague is a product that will disappoint you later.
We keep, we never file. Enlivy produces documents and retains records. It does not transmit anything to a tax or labour authority. Romania’s employment registry is authoritative and ours is operational: where they disagree, the registry is right, which is exactly why every employment states its own registry status instead of implying the filing was done.
We do not calculate payroll. Your accountant remains the calculation engine. Enlivy holds, structures, validates and retains the result.
There is also no clock-in. The daily record is an authored grid, one row per day, not a stream of punches, and we would rather say that than sell you a time clock we have not built.
What the Record Gives You
The duty to keep these records is yours, which is why the export centre stays open even if a subscription lapses.
- Write a whole month in one pass
Open the grid, state what each day was, and save the month in a single save. No day-by-day data entry.
- Confirm a month once it is complete
Attest the month from the grid once every day in it is recorded.
- Export the timesheet your accountant wants
Take the month out through the API, in the shape the person doing the payroll actually asked for.
- Keep every prior version of every day
Every change keeps what it replaced and who replaced it.
Offers, contracts, invoices and payments
The Answer Is Already in the Record
When an inspection asks who worked when, on what terms, and what they were paid, the answer is in one place and it is already written down.
Free account, no card · Payroll pack €19.99/month · Prices exclude VAT
API Reference
Employment and Working Time from the API
Read and write the employment record programmatically: the employments themselves, the working-time terms behind them, and the month grid that says what each person actually did.
The month is written in one call, not day by day. Provenance fields are refused from the request on purpose: origin, version and content hash are set by the system, so nothing that proves a record can be supplied by the caller.
List the employments in your organization with pagination and navigation metadata. Each row carries the kind of engagement, the job title, the jurisdiction and subdivision that govern it, its own timezone, and where it stands with the official registry.
const organizationId = "your_org_id";
const token = "YOUR_TOKEN_HERE";
fetch(`https://api.enlivy.com/organizations/${organizationId}/employments?page=1&limit=20&include_meta=navigation`, {
method: 'GET',
headers: {
'Authorization': `Bearer ${token}`,
'Content-Type': 'application/json'
}
}); Create the row everything else hangs off. The jurisdiction and timezone are set per employment, not per company, so a Romanian organization hiring in Spain sends `ES` and `Europe/Madrid` here and every later rule resolves from that.
const organizationId = "your_org_id";
const token = "YOUR_TOKEN_HERE";
fetch(`https://api.enlivy.com/organizations/${organizationId}/employments`, {
method: 'POST',
headers: {
'Authorization': `Bearer ${token}`,
'Content-Type': 'application/json'
},
body: JSON.stringify({
organization_user_id: "org_user_...",
organization_contract_id: "org_contract_...",
type: "permanent",
job_title: "Software Engineer",
jurisdiction_code: "ES",
timezone: "Europe/Madrid",
start_date: "2026-09-01"
})
}); Read one employment's month as a grid. Every day states its disposition (worked, absent, a rest day, a public holiday, a scheduled non-working day, or not recorded), with the hours or the interval behind it, and its own version and content hash.
const organizationId = "your_org_id";
const token = "YOUR_TOKEN_HERE";
const employmentId = "org_employment_...";
fetch(`https://api.enlivy.com/organizations/${organizationId}/working-time-days/month?organization_employment_id=${employmentId}&month=2026-09`, {
method: 'GET',
headers: {
'Authorization': `Bearer ${token}`,
'Content-Type': 'application/json'
}
}); Write the whole month in a single call. A day may carry an interval or its own hour counts, never both, and `expected_version` lets you refuse to overwrite a day somebody else changed while you were working.
const organizationId = "your_org_id";
const token = "YOUR_TOKEN_HERE";
const employmentId = "org_employment_...";
fetch(`https://api.enlivy.com/organizations/${organizationId}/working-time-days/month`, {
method: 'PUT',
headers: {
'Authorization': `Bearer ${token}`,
'Content-Type': 'application/json'
},
body: JSON.stringify({
organization_employment_id: employmentId,
month: "2026-09",
days: [
{
date: "2026-09-01",
disposition: "worked",
started_at: "2026-09-01T09:00:00+03:00",
ended_at: "2026-09-01T17:30:00+03:00",
break_minutes: 30
},
{ date: "2026-09-02", disposition: "absent", absence_reason: "annual_leave" },
{ date: "2026-09-05", disposition: "rest_day" }
]
})
}); Attest a completed month. This endpoint takes second-party methods only, such as `supervisor_approved`: a worker's own confirmation is first-party and comes from the portal, so nobody can confirm a month on someone else's behalf through here.
const organizationId = "your_org_id";
const token = "YOUR_TOKEN_HERE";
const employmentId = "org_employment_...";
fetch(`https://api.enlivy.com/organizations/${organizationId}/working-time-days/month/attest`, {
method: 'POST',
headers: {
'Authorization': `Bearer ${token}`,
'Content-Type': 'application/json'
},
body: JSON.stringify({
organization_employment_id: employmentId,
month: "2026-09",
attestation_method: "supervisor_approved"
})
}); Works together with
- Payslips Your accountant works out the figures. Enlivy is where they land: every amount on its own coded line, in the vocabulary your country actually uses, checked against the payslip's own totals and tied to the employment, the contract and the payment it belongs to.
- Contracts Draft contracts from templates, send them for signature with SMS or email identity verification, and track every signature and renewal.
- Users Easily customize roles and permissions in Enlivy for clients, partners, accountants, and administrators, ensuring secure and efficient access.
- Customer Portal A branded, self-service portal, on your own domain if you add one, where clients accept proposals, pay invoices, manage subscriptions and sign contracts themselves. Every action lands on the client's record in Enlivy.
- Data Export Export your invoices, receipts, payslips, contracts, and transactions in the format and folder structure your accountant expects, for any date range. Built in, at no extra cost, on every plan.
- MCP Connect Enlivy to Claude, ChatGPT, Cursor, or any AI assistant through MCP. Ask about your invoices, contracts, and pipeline, and get real work done, safely scoped to exactly what your own account can already do.