One complaint stands out as narrower and more specific than the rest: 'security levels are not flexible.' This is a different category of pain than general customization. Security role configuration — who can see which employee records, who can run which reports, who can edit compensation data — is the kind of thing that changes constantly: a new HR business partner joins, a manager gets promoted and needs a different access level, a compliance audit requires demonstrating that only certain people can see salary bands.

In most enterprise HR systems, security role management is either locked down entirely (requiring vendor support to change) or so deeply buried in admin settings that only the original implementation consultant knows how it works. The people who need to change it — HR admins, not IT — frequently can't, and the people who technically can (IT or ADP support) don't understand the HR context well enough to configure it correctly. This mismatch is structural: the buyer who negotiated the contract cared about features, not permissions architecture.

The result is either over-permissioned access (everyone gets manager-level visibility because it's too hard to restrict) or under-permissioned access (a new HRBP can't see the records they need to do their job). Both are compliance risks. Both waste time. Neither gets fixed because the ticket queue at the vendor is long and the urgency isn't obvious until an audit.

A dedicated tool that maps the existing security role structure of an HR system, presents it visually as a permissions matrix, lets an HR admin make changes in a controlled interface, and logs every change with a timestamp and justification creates an audit trail that didn't exist before — and removes the vendor support dependency for a task that happens every time headcount or org structure shifts.

This is a business because security role drift is continuous, not one-time. Every new hire, every promotion, every department restructure is a potential permissions event. And the compliance exposure from getting it wrong — particularly around compensation data visibility — means buyers have a concrete dollar figure to attach to the risk.

What to build

Build a permissions management dashboard that connects to ADP Workforce Now or similar Core HR systems via API, reads and visualizes the current security role assignments as a matrix by role type and data domain, lets HR admins propose and apply role changes with required justification notes, and exports a timestamped change log for compliance audits.

Where to start

Target healthcare HR teams first — they face HIPAA-adjacent access control requirements, have compliance officers who understand the audit log value immediately, and are large enough to pay but not so large that they have a dedicated HRIS team that would build this themselves.

The hard part

Getting read and write access to security role configuration via API is not uniformly supported across HR vendors — you may find that ADP exposes enough to make this work for one product tier but not another, which limits your addressable market until you've done the painful API archaeology.

How it makes money

Annual subscription per HR tenant, priced at $3,000–$8,000/year depending on employee count, with a one-time onboarding fee that covers the initial permissions audit and role mapping — the audit alone is worth paying for, which reduces early sales resistance.

See the evidence. The complaints behind this idea, the products they came from, and similar ideas in Core HR.

More ideas in Core HR