Who has access to salaries, and what is left behind when somebody opens them
Echipa HR 365 · reviewed 2026-09-05 · 5 min read
The access circle for salaries should be the smallest in the company and is usually far wider than anyone thinks. Not because it was decided that way, but because the salary sits in the same file as the rest of the personnel data, and the file circulates.
Who has a real reason
| Role | What they see | What they have no reason to see |
|---|---|---|
| HR responsible for payroll | Everything | — |
| Accounting | The amounts needed for payment and reporting | Negotiation history, reviews |
| Department manager | The team budget and the salaries of those they propose for a raise | Other departments |
| Leadership | Aggregated by department; individual only for the roles they decide | All staff, individually, as a routine |
| IT | Nothing of the content | The data; they need access to the system, not to what is inside it |
The last row is the distinction most often missing. A system administrator needs to be able to fix the system, not to read salaries. They are two technically different things, and confusing them is why, in many companies, two or three people in IT have access to everything without anyone having decided it.
Where it actually leaks
- The payroll file, emailed to accounting every month. It stays in two mailboxes, permanently.
- The export with every column, made for one report and saved in the shared folder.
- A screen left open in a shared office. The most mundane and the most frequent.
- The raise discussion, held in a meeting with more managers than necessary.
- The budget file, which contains individual salaries and gets forwarded.
Why what is left behind matters
Access that leaves no trace can never be checked. The practical difference appears in one situation, but that one counts: somebody learns a salary figure and wonders where it came from. With a log, the question is answered in two minutes. Without one, it stays a suspicion touching everybody with access.
The log has a second effect, more important than the first: it changes behaviour. A system known to record openings gets used differently — not out of fear, but because access becomes a conscious action rather than a reflex.
Re-authentication: small friction, large effect
Asking for the password again when opening salary data looks like a formality. It solves the most common real exposure scenario: a session left open on a computer somebody else reaches. It costs five seconds for the person entitled to it and completely stops accidental access.
Where to start
Write the list of people who can currently see any individual salary. If it takes you more than a minute, or you are not sure, that is the problem — not the length of the list.
Then look at what circulates monthly by email to accounting. In most companies, that is the one file containing every salary and, by its nature, reaching the most places.
How you limit access without blocking work
Restricting access fails when it makes work impossible: if a manager needs their team’s budget and cannot get it, they will ask for an export — and the export is exactly what you were avoiding. The practical rule is to give each person the form they need, not full access or nothing.
| What they want to do | What they get | What is not needed |
|---|---|---|
| Propose a raise | That person’s salary and the role band | The whole team, individually |
| Stay within a budget | The team total and current spend | The breakdown by person |
| Benchmark a job offer | The role band and the team average | Colleagues’ individual salaries |
| Report the cost of a project | Aggregated cost by hours, not by person | Salaries |
The last row solves one of the most frequent export requests. A project’s cost can be calculated from hours and an average cost per role, with nobody seeing an individual salary — and the result is just as accurate for that purpose.
The moments when the circle widens on its own
- Budget season. Access is opened “temporarily” and stays open until the following year.
- Somebody leaving HR. A colleague takes over the tasks and receives the rights, but the person who left keeps theirs.
- An audit or an external request. A full export is made and stays in the shared folder.
- Implementing a new system. Broad rights are granted “to make it work”, with the intention of narrowing them later — which does not happen.
All four have the same solution: any access granted temporarily gets an expiry date at the moment it is granted. Without a date, “temporary” means permanent, and a six-monthly review is the only thing that catches them — six months late.
What if a manager asks for the whole team’s salaries?
Ask what for. If it is for a budget, give them the total; if it is for a raise proposal, give them that person and the role band. The full request usually appears because it is the only form on offer, not because it is what is needed.
Is it fine for two people in HR to see everything?
Yes, if that is their job and if the access leaves a trace. The problem is not the number, it is the absence of a limit: a circle that grows without anybody deciding reaches ten people in two years.
Salaries visible only after re-authentication, with a log on every access
Whoever opens a figure confirms their identity again, and the access stays recorded — so “where did they hear that” has an answer rather than assumptions.
Free account, every module for 7 days, no card required.