DocsSign inInstall Kastel
All connectors

Your AI can know the org chart PayFit holds without ever reading a salary.

With Kastel

Connect one PayFit company to your Kastel and four things come in per collaborator, their name, their job title, their department and their manager. Pay, the employment contract, bank details and personal contact details are never read. And until an administrator has named the department entitled to read that directory, nobody reads it.

A payroll system holds what a company protects most

PayFit holds your employees' payslips, contracts, bank details and dates of birth. It is the source a director fears most, and that fear is warranted. A salary read by the wrong person is not something a technical fix repairs.

It is also where your organisation is written down in black and white. Who holds which job, in which department, reporting to whom. An AI that does not know this answers beside the point on almost every internal question, because it knows neither who it is talking to nor who does what in the company.

Kastel's PayFit connector takes that one layer and leaves everything else. It writes four things per collaborator, and it calls a single address at PayFit.

Four things written, one address called

PayFit's interface cannot return part of a record. It returns the whole record, pay and bank details included. A connector that merely filtered what it received would have to know in advance every field it must hide, and would get it wrong the day PayFit adds one.

This connector works the other way round. It names the four fields it writes, the name, the job title, the department and the manager, and it writes those only. The record PayFit returns is never kept, and only the text composed from those four fields is written. A field the connector has not named therefore has no path into your Kastel, including a field PayFit might add tomorrow.

The caution goes one step further. If one of those four fields arrives in an unexpected shape, a nested structure where the connector expects a name for instance, the line is omitted rather than copied across as it stands. A record of an unforeseen shape produces a shorter entry, never a wider one.

On the network side, the engine's PayFit reader knows one verb, reading. No write method exists in the code, and one address appears in it, the collaborator list of one company. The key requested from PayFit carries the read scope of that directory, and it never appears in a URL, a log, or a file in your Kastel.

Four lines of the org chart, no payroll item

On a payroll source, scope is described in fields rather than in categories. Here is the list, as it is written in the connector.

What your Kastel reads in PayFit

  • The collaborator's name
  • Their job title, when PayFit holds one
  • Their department
  • Their manager, meaning the reporting line

What it never reads

  • Pay and every payroll element
  • The employment contract
  • Bank details, account numbers included
  • Personal postal address, phone number and personal email address
  • Date of birth and national identification number

The contract and the pay are excluded for a simple reason. Knowing who reports to whom never requires knowing what anyone earns, and a field that is never read cannot be shown to an AI by mistake.

What it takes before an AI can read that directory

PayFit sets no read permission at the level of a collaborator. The key sees the entire directory, and it is the same key for everyone. There is therefore no original permission to inherit, unlike a shared file or a discussion channel, and the connector draws the most closed conclusion available.

  1. An administrator connects a company, and the key is verified before it is stored

    A PayFit key covers a single company. The engine attempts a read before storing anything, and refuses a key that does not authenticate. A group holding three companies in PayFit therefore connects three keys, each with its own scope.

  2. At this point nobody reads the directory

    With no further decision, the directory is filed in no department and waits for an administrator. No connected AI, no employee and no department reaches it.

  3. An administrator names the department entitled to read it

    Three conditions have to hold. That department must be named, its name must be a valid identifier, and it must genuinely exist in your organisation. An HR department invented in a configuration file is not enough to open access, and that is the point.

  4. A record is never filed in the collaborator's own department

    Filing a developer's record in the engineering department would open the HR directory to the whole engineering team, department by department, without anyone having decided it. The connector refuses that shortcut. Either the named department reads the directory, or nobody does.

  5. The decision is rechecked, and a change withdraws the earlier version

    If the named department changes, or disappears from your organisation, the records are filed again and the version readable by the former department is withdrawn. That check has its own guaranteed pass, because a governance change alters no record and would otherwise go unnoticed. How Kastel decides who reads what.

A full reread on every pass, and nothing that erases itself

PayFit's interface cannot say which collaborators changed since last time. Every pass therefore lists the directory in full, and an unchanged record produces nothing. A move in your organisation shows up on the following pass rather than the second your HR team enters it.

One precaution deserves naming, because it protects your data rather than our convenience. When a page of results announces more to come without giving the means to reach it, the pass fails loudly instead of carrying on. Without that rule, a partial reconciliation would conclude that the unread collaborators had left the company, which is the quietest way to lose data.

When a record no longer appears in the PayFit directory, it is not erased from your Kastel. Your Kastel keeps the record and notes that the source no longer returns it, with its read permissions untouched, until an administrator decides to erase it. That is the rule for every source Kastel can read, and on an HR record keeping is the cautious behaviour.

Disconnecting PayFit removes the key and stops the reading, without withdrawing what has already been read. Erasing the content is a separate step, requested explicitly by an administrator.

What this connector does not do

It does no HR administration. It computes no payroll, tracks no absence, prepares no payslip, and writes nothing into PayFit. It gives an AI enough to know who works for you, in which job, and under whose responsibility.

The org chart it reads is worth what your directory is worth. A job title left empty in PayFit stays empty in your Kastel, and a missing reporting line is not invented. The exact field names of PayFit's interface are not all confirmed by real access on our side, and the connector is written to omit a line it does not recognise rather than to guess it.

A name tied to a job title and a manager remains personal data, with no pay figure anywhere in sight. And the directory is read as one block. Since PayFit sets no permission per collaborator, there is no way to open half of that directory to one department and the other half to another.

Kastel marks these records with its most restrictive class. That marking only takes effect if an administrator has set a destination rule for the class. Without that rule, the directory text is handled by whichever indexing tool is configured, like any other content, and it would be dishonest to sell the marking as a protection in itself.

A payroll directory deserves a conversation before a connection.

Tell us what you want an AI to know about your organisation, and who should be able to read it. We will tell you plainly what this connector writes, what it leaves out, and what an administrator has to decide before the first pass.

Get in touch
Other connectors in detail
Lucca
Name, job title, department, manager. No salary, absence or contact detail.
Factorial
Employees and teams. No pay, no leave, no absences.
Pennylane
Number, date, counterparty and total. Never the bank details.

See the full connector catalogue