Philippines staffing research ·
Can Payroll File Access Be Segregated Without Breaking Preparation?
Research on least-privilege file lanes, preparation duties, approvals, exports, temporary access, and release boundaries.

Research question. This study asks whether payroll preparation can limit access and separate preparation from approval while producing a reviewable handoff. It creates a buyer-side evaluation method, not a claim about Outsourced Employment or another provider.
Evidence basis. The Philippine Data Privacy Act says personal information should serve declared purposes, remain accurate and relevant, not be excessive, and receive reasonable organizational, physical, and technical protection. Its implementing rules address accountable roles, access duties, processing records, processor arrangements, and review. NIST CSF 2.0 supplies a general vocabulary for governance, identity, data security, detection, response, and recovery. CISA guidance supports least privilege. These are design inputs; owners and qualified advisers interpret them for a real organization.
Unit of analysis. Examine one fictional payroll input version, preparation task, access grant, reviewer decision, and transfer acknowledgment. This narrow unit prevents favorable totals from hiding unsupported transitions. Every conclusion identifies its source event, version, observed time, and accountable next decision.
Test population. Create 94 cycles covering standard inputs, bonus files, bank changes, corrections, rejected imports, temporary coverage, approver absence, emergency access, exports, shared links, stale copies, and revoked users. Use invented organizations, people, documents, amounts, accounts, and identifiers. Keep the seeded answer key separate through independent review. Record exclusions and reasons rather than silently replacing difficult cases.
Required evidence. Capture cycle token, purpose, field class, source version, preparer, reviewer, access role, grant, expiry, export, change ID, approval, checksum, receiving acknowledgment, exception, and revocation. Define purpose and allowed values before testing. Blank, unknown, not applicable, not received, restricted, and cannot determine remain different. Reviewers cannot turn absence into an answer.
Failure hypothesis. Folder access is not proof of least privilege, and a second name is not proof of independent review. Downloads, email, automation, and backups can outlive the shared file. Include positive controls that should proceed, negative controls that should stop, and ambiguous controls that should reach an owner. A workflow that never stops is uncontrolled; one that stops every case is unusable.
Decision boundary. Coordinators may assemble approved fields, maintain versions, record access, apply checks, and transfer approved packages. Payroll, finance, HR, security, privacy, legal, and system owners decide need, entitlement, adjustments, release, retention, and incidents. Count an unauthorized substantive decision as a serious error even if the guess proves correct. Coordination does not transfer accountability.
Controlled comparison. Randomize case order and compare one shared workbook with purpose-specific views, independent review evidence, controlled transfer, expiring access, and copy inventory. Give both workflows equal information and time. Evaluate correctness, access, serious errors, unresolved work, and duration; speed alone is not success.
Scenario design. Seed a duplicate allowance, shifted effective date, stale population, and bank-change row outside the approved lane. Near cutoff, make the preparer unavailable and grant time-bounded coverage. Inspect inherited groups and downloads after expiry; checksum the approved package and alter a nonfinancial field. Require evidence for each transition and preserve late or conflicting signals. The correct response to ambiguity is the named route, not the researcher’s preferred answer.
Evidence drill 1 focuses on cycle token. Compare cycle token against source version at the declared event time, then test whether access role supports or contradicts that relationship. Preserve export before asking the accountable owner to resolve any conflict involving checksum. Reperform the check after a version change and after a delayed acknowledgment. Record the specific source, permissible action, uncertainty, downstream effect, and stop condition instead of replacing the evidence with a yes-or-no completion flag.
Evidence drill 2 focuses on purpose. Compare purpose against preparer at the declared event time, then test whether grant supports or contradicts that relationship. Preserve change ID before asking the accountable owner to resolve any conflict involving receiving acknowledgment. Reperform the check after a version change and after a delayed acknowledgment. Record the specific source, permissible action, uncertainty, downstream effect, and stop condition instead of replacing the evidence with a yes-or-no completion flag.
Evidence drill 3 focuses on field class. Compare field class against reviewer at the declared event time, then test whether expiry supports or contradicts that relationship. Preserve approval before asking the accountable owner to resolve any conflict involving exception. Reperform the check after a version change and after a delayed acknowledgment. Record the specific source, permissible action, uncertainty, downstream effect, and stop condition instead of replacing the evidence with a yes-or-no completion flag.
Evidence drill 4 focuses on source version. Compare source version against access role at the declared event time, then test whether export supports or contradicts that relationship. Preserve checksum before asking the accountable owner to resolve any conflict involving and revocation. Reperform the check after a version change and after a delayed acknowledgment. Record the specific source, permissible action, uncertainty, downstream effect, and stop condition instead of replacing the evidence with a yes-or-no completion flag.
Evidence drill 5 focuses on preparer. Compare preparer against grant at the declared event time, then test whether change ID supports or contradicts that relationship. Preserve receiving acknowledgment before asking the accountable owner to resolve any conflict involving cycle token. Reperform the check after a version change and after a delayed acknowledgment. Record the specific source, permissible action, uncertainty, downstream effect, and stop condition instead of replacing the evidence with a yes-or-no completion flag.
Evidence drill 6 focuses on reviewer. Compare reviewer against expiry at the declared event time, then test whether approval supports or contradicts that relationship. Preserve exception before asking the accountable owner to resolve any conflict involving purpose. Reperform the check after a version change and after a delayed acknowledgment. Record the specific source, permissible action, uncertainty, downstream effect, and stop condition instead of replacing the evidence with a yes-or-no completion flag.
Evidence drill 7 focuses on access role. Compare access role against export at the declared event time, then test whether checksum supports or contradicts that relationship. Preserve and revocation before asking the accountable owner to resolve any conflict involving field class. Reperform the check after a version change and after a delayed acknowledgment. Record the specific source, permissible action, uncertainty, downstream effect, and stop condition instead of replacing the evidence with a yes-or-no completion flag.
Evidence drill 8 focuses on grant. Compare grant against change ID at the declared event time, then test whether receiving acknowledgment supports or contradicts that relationship. Preserve cycle token before asking the accountable owner to resolve any conflict involving source version. Reperform the check after a version change and after a delayed acknowledgment. Record the specific source, permissible action, uncertainty, downstream effect, and stop condition instead of replacing the evidence with a yes-or-no completion flag.
Evidence drill 9 focuses on expiry. Compare expiry against approval at the declared event time, then test whether exception supports or contradicts that relationship. Preserve purpose before asking the accountable owner to resolve any conflict involving preparer. Reperform the check after a version change and after a delayed acknowledgment. Record the specific source, permissible action, uncertainty, downstream effect, and stop condition instead of replacing the evidence with a yes-or-no completion flag.
Evidence drill 10 focuses on export. Compare export against checksum at the declared event time, then test whether and revocation supports or contradicts that relationship. Preserve field class before asking the accountable owner to resolve any conflict involving reviewer. Reperform the check after a version change and after a delayed acknowledgment. Record the specific source, permissible action, uncertainty, downstream effect, and stop condition instead of replacing the evidence with a yes-or-no completion flag.
Evidence drill 11 focuses on change ID. Compare change ID against receiving acknowledgment at the declared event time, then test whether cycle token supports or contradicts that relationship. Preserve source version before asking the accountable owner to resolve any conflict involving access role. Reperform the check after a version change and after a delayed acknowledgment. Record the specific source, permissible action, uncertainty, downstream effect, and stop condition instead of replacing the evidence with a yes-or-no completion flag.
Evidence drill 12 focuses on approval. Compare approval against exception at the declared event time, then test whether purpose supports or contradicts that relationship. Preserve preparer before asking the accountable owner to resolve any conflict involving grant. Reperform the check after a version change and after a delayed acknowledgment. Record the specific source, permissible action, uncertainty, downstream effect, and stop condition instead of replacing the evidence with a yes-or-no completion flag.
Evidence drill 13 focuses on checksum. Compare checksum against and revocation at the declared event time, then test whether field class supports or contradicts that relationship. Preserve reviewer before asking the accountable owner to resolve any conflict involving expiry. Reperform the check after a version change and after a delayed acknowledgment. Record the specific source, permissible action, uncertainty, downstream effect, and stop condition instead of replacing the evidence with a yes-or-no completion flag.
Evidence drill 14 focuses on receiving acknowledgment. Compare receiving acknowledgment against cycle token at the declared event time, then test whether source version supports or contradicts that relationship. Preserve access role before asking the accountable owner to resolve any conflict involving export. Reperform the check after a version change and after a delayed acknowledgment. Record the specific source, permissible action, uncertainty, downstream effect, and stop condition instead of replacing the evidence with a yes-or-no completion flag.
Case construction detail. Translate this scenario into individual test cards: Seed a duplicate allowance, shifted effective date, stale population, and bank-change row outside the approved lane. Near cutoff, make the preparer unavailable and grant time-bounded coverage. Inspect inherited groups and downloads after expiry; checksum the approved package and alter a nonfinancial field. On each card, show only the information that the real role would possess at that moment. Withhold later events until their timestamp arrives. This prevents hindsight from improving a classification and reveals whether the operating record can support the decision when it is actually needed. Keep the hidden expected route, serious-error class, and permitted evidence beside the answer key, not in the reviewer interface.
Causal review. For every incorrect or delayed result, trace the chain through these required elements: cycle token, purpose, field class, source version, preparer, reviewer, access role, grant, expiry, export, change ID, approval, checksum, receiving acknowledgment, exception, and revocation. Identify the earliest unsupported transition instead of blaming the final user. Classify whether the cause was an unavailable source, ambiguous definition, stale version, excessive permission, missing acknowledgment, incorrect mapping, or action outside the written boundary. Re-run only the affected cases after a versioned correction and retain the first result so improvement is measurable rather than reconstructed.
Decision usefulness. The buyer should receive evidence about unnecessary exposure, incompatible duties, expired access, exports, version errors, review independence, transfer integrity, acknowledgment, and exception closure. Convert those measures into a decision table that shows the observed fact, denominator, uncertainty, consequence, accountable owner, and proposed next test. Do not roll serious boundary violations into one average score. A fast median can coexist with a small number of unacceptable disclosures or decisions, while a slower result may reflect appropriate stops on ambiguous cases. State both the operational benefit and the control cost.
Boundary challenge. Apply adversarial examples to this division of responsibility: Coordinators may assemble approved fields, maintain versions, record access, apply checks, and transfer approved packages. Payroll, finance, HR, security, privacy, legal, and system owners decide need, entitlement, adjustments, release, retention, and incidents. Ask reviewers what they can prepare, what they may observe, what requires approval, what must stop, and what should never enter the routine record. Score the evidence trail as well as the answer. A correct escalation with no preserved source or recipient acknowledgment is incomplete; a perfectly documented action outside the permitted lane is still a failure.
Alternative explanation. Before accepting the primary conclusion, test whether the same result could arise from Folder access is not proof of least privilege, and a second name is not proof of independent review. Downloads, email, automation, and backups can outlive the shared file. Compare that explanation with source timestamps, versions, permissions, and acknowledgments. Mark inference as inference and preserve competing explanations when the evidence cannot choose between them. This discipline matters because a plausible operational narrative can otherwise harden into an unsupported fact that later reviewers, systems, or employee communications repeat.
System-path review. Replay every scenario through the primary record, email, calendar, notification, download, integration, audit log, and backup path that might carry the same information. Record propagation time, mismatched identifiers, stale copies, recipient scope, and acknowledgments. A clean main screen cannot compensate for an uncontrolled export or dependent system still acting on an old state.
Temporal review. Repeat selected cases when a cutoff passes, an owner changes, a source is corrected, or acknowledgment arrives late. State changes only when declared evidence exists. Record the observer, applicable rule version, and dependent-system result. This separates an overdue item from a superseded one and a corrected source from a correction actually received.
Recovery review. Remove a required source, delay an owner, add a duplicate, and interrupt an integration. A controlled workflow preserves last-known state, says what cannot be determined, avoids reconstructing facts from memory, and uses the approved contingency. Work resumes without double action, silent closure, or broader disclosure.
Measurement. Report unnecessary exposure, incompatible duties, expired access, exports, version errors, review independence, transfer integrity, acknowledgment, and exception closure. Give counts with denominators. Separate observed facts, rule classifications, owner decisions, and researcher inference. Preserve disagreement and missing evidence rather than averaging them into a confident-looking score.
Privacy and security. Use invented pay values, workers, banks, and identifiers; never use live account numbers, tax identifiers, credentials, or government numbers. Record who can view, change, export, and delete each artifact. Check whether revoked access survives elsewhere. Stop on unexpected sensitive information and use the approved incident path.
Repeatability. Give a second reviewer written rules and clean cases without coaching. Low agreement indicates unclear definitions, missing evidence, or inconsistent access. Version clarifications and rerun affected cases; do not label every disagreement a training problem.
Acceptance. Set minimum accuracy, maximum unresolved age, acceptable agreement, and zero-tolerance events before opening the answer key. Report each independently. Strong averages cannot offset an unauthorized decision, exposure, or false closure hidden in a total.
Procurement use. Ask a provider to demonstrate a sanitized register, permission view, version history, exception path, acknowledgment, and audit export for this workflow. Every artifact has a date and scope. A policy, demo, or marketing statement is point-in-time evidence, not proof of continuous operation.
Limitations. This does not certify security, determine lawful access, calculate payroll, approve payment, or prove all copies were eliminated. Synthetic cases simplify behavior, platforms, contracts, and cross-border operations. Begin a live pilot with a small approved queue, least-privilege access, named reviewers, monitored exceptions, and a stop rule. The defensible conclusion is whether evidence remains reviewable and uncertainty reaches the correct owner—not whether the workflow guarantees a legal, security, payroll, privacy, employment, or business result.
Sources checked September 28, 2026: National Privacy Commission, “Republic Act 10173 — Data Privacy Act of 2012,” https://privacy.gov.ph/data-privacy-act/; National Privacy Commission, “Implementing Rules and Regulations of the Data Privacy Act of 2012,” https://privacy.gov.ph/implementing-rules-regulations-data-privacy-act-2012/; National Institute of Standards and Technology, “The NIST Cybersecurity Framework (CSF) 2.0,” https://www.nist.gov/publications/nist-cybersecurity-framework-csf-20; Cybersecurity and Infrastructure Security Agency, “Identity and Access Management: Recommended Best Practices for Administrators,” https://www.cisa.gov/sites/default/files/2023-12/ESF%20IDENTITY%20AND%20ACCESS%20MANAGEMENT%20RECOMMENDED%20BEST%20PRACTICES%20FOR%20ADMINISTRATORS%20PP-23-0248_508C.pdf. These sources provide principles, not a finding that a provider complies.