An HR system holds what a company protects most
An AI that is useful about your organisation needs to know who does what and who reports to whom. That information lives in your HR system, right next to payroll, absences, annual reviews and departure files.
Those two things get conflated the moment you plug in the whole tool. That is why the Lucca connector does not ask for an employee's file. It asks for their name, their job title, their department and their manager, and then it stops.
That limit is not a setting you could loosen. It is written into the request sent to Lucca, which lists the fields it wants. The other fields never leave Lucca, because nobody asked for them.
What the connector asks Lucca for, row by row
Every row can be checked in your own Lucca, by opening an employee record.
| Item in an employee record | Requested by the connector |
|---|---|
| First name and surname | Yes |
| Job title | Yes |
| Department | Yes |
| Manager, the reporting line | Yes |
| Pay and compensation items | Never |
| Leave, absences and sick notes | Never |
| Reviews, appraisals and disciplinary items | Never |
| Personal phone, address and email | Never |
| Date of birth | Never |
| National identity and insurance numbers | Never |
| Bank details | Never |
| Work email address and login | Never |
The first four rows are the whole of what comes in. The last one often surprises people, and it is deliberate. A work email address teaches nothing about how your company is organised, so it is not requested, and your Kastel is not meant to become a contact directory.
Lucca sets no read permission per employee
In a chat tool or a file store, every object already carries a record of who has access, and a connector only has to inherit it. Lucca does not work that way. The access key sees the entire directory, from the intern to the chief executive, and there is no per-employee permission to inherit.
The connector draws the most cautious conclusion available. The whole directory is filed in a single department, the one you designate as your HR department, and that department has to genuinely exist in your organisation for the filing to happen at all. Until it is designated, or while the name given matches nothing real in your organisation, the directory stays on hold and nobody reads it.
One other option would have been tempting, and we turned it down. Filing each employee's record into their own department would give an org chart that is immediately useful everywhere. It would also spread personal data across every department of the company, so the connector does not offer it.
Every hold leaves a trace, and the decision that lifts it leaves another one. That is the work Kastel calls governing your knowledge, and an HR source is where it shows most clearly.
Four items per employee, and nothing else
This connector's scope is deliberately narrow, and it is described in fields rather than in categories.
The reporting line is captured person by person, through each employee's manager, which is enough to answer who reports to whom. The hierarchy of departments among themselves is not read in this version.
A departed employee's record does not disappear on its own
Lucca cannot say what has changed since last time. The dates it exposes are contract dates, not modification dates, so every pass rereads the whole directory. An unchanged record costs nothing to review, and a new joiner shows up on the following pass.
When a record is no longer returned by Lucca, which is exactly what a departure looks like from the outside, it is not erased from your Kastel. Your Kastel records the disappearance without withdrawing the record, whose read permissions do not change until an administrator decides to erase it.
That is how every Kastel connector behaves, and on an HR source it deserves saying plainly. Erasing a person's record is a decision that belongs to someone, not to a program noting an absence from a list. The connector only raises the flag, and the decision stays in your hands.
The same caution applies to another sensitive source in the catalogue, accounting, described on the Pennylane connector page. Every supported source is listed in the connector catalogue.
What this connector does not do
These records carry the most restrictive marker the engine can put on a piece of content. That marker does not decide who may read them, and it only acts on permitted destinations once an administrator has put the matching rule in place. Without that rule it stays a label, and it is better known than assumed.
Caution has a functional cost worth naming. Because the whole directory is filed in a single department, an AI working for a sales director has no access to the org chart. If your goal is that everyone can query the reporting line, this connector is not the right path as it stands.
It does no HR work. It tracks no absence, prepares no payroll, runs no appraisal, and it replaces neither Lucca nor your head of people. It gives an AI enough to understand how your company is organised, which is a small part of what your HR system holds.
What a job title says depends on what your teams write in it. It is the only free-text field of the four, and it comes in as written. A job title filled in with a comment about someone's situation would therefore bring into your Kastel something the connector never asked for.
Tell us who should be reading your directory.
An HR source is decided before it is connected. Write to us with what you want an AI to know about your organisation, and we will answer with what the connector reads, what it refuses to request, and what remains your responsibility.
Get in touch