Payroll · HR · Time — for the global enterprise

Enterprise payroll & HR, engineered for global scale 

HRMSTONE runs multi-country payroll, core HR and time & attendance for large, regulated organizations — where every change is a governed, audited, effective-dated transaction, and the numbers are statutory-accurate in every country you operate.

  • Multi-country statutory packs
  • Governed, audited transactions
  • Multi-currency · multilingual · RTL
Live

Payroll run · June 2026

Net pay

USD0

3.1%

246 payslips calculated with per-line logs · 2 flagged for review — awaiting Payroll Manager approval.

248
Payslips
4
Countries
100%
Balanced
Statutory-accurate, country by country
Run payroll worldwide
30+ languages · RTL · multi-calendar
Localized everywhere
SaaS · BYO-DB · On-prem
Deploy your way

Built for large, regulated, multi-entity organizations across the region

  • Banks & financial services
  • Government & public sector
  • Holdings & conglomerates
  • Oil, gas & energy
  • Telecom
  • Retail & FMCG
  • Healthcare
  • Construction

One estate, four products

A modular monolith of monoliths

Buy one product or run the whole estate. Each is a .NET modular monolith with its own database, sharing one identity, one workflow engine and one audit trail through the Stoneme platform.

Payroll

Multi-country salary calculation, statutory math and bank files — retroactive and off-cycle by design.

  • Deterministic calc with per-line logs
  • End-of-service, social security, tax & WPS
  • Retroactive deltas & off-cycle runs

Time & Attendance

Schedules, attendance and leave that feed payroll — with GCC weekends and holiday calendars.

  • Rosters, clock-in & overtime
  • Accrual ledgers & encashment
  • Timesheets & approval workflows

HR

The canonical employee record, org structure and the hire-to-onboard loop.

  • Employee directory & org tree
  • Talent acquisition → onboarding
  • Lifecycle changes as transactions

Stoneme platform

The shared core: identity, the transaction & workflow kernel, documents, country packs and audit.

  • RBAC + ABAC identity & SSO
  • Workflow & approval engine
  • Documents, packs & notifications

Depth, not breadth alone

Every payroll & HR domain, in one platform

The reference system spans 2,500+ endpoints across 176 functional areas. HRMSTONE rebuilds that ambition as clean, governed modules — here are the domains it covers.

Salary calculation

Run, post, unpost; retroactive deltas and off-cycle runs.

Transactions & workflow

Approval chains, committees, delegation and escalation.

Compensation & scales

Salary scales, grades, bands and entitlement templates.

Vacation & leave

Accrual ledgers, balances, requests and encashment.

Loans

Types, schedules, budgets, guarantors and stoppers.

End of service

Tiered gratuity slices and final settlement.

Social security & tax

Contribution engines and authority filing.

Residence & visa

Iqama renewal, exit/re-entry and air tickets.

Letters & vouchers

Bilingual documents, certificates and GL vouchers.

Self-service

Payslips, balances, requests and approvals.

Security & admin

Roles, privileges, branches and audit logs.

Reporting & BI

Headcount, cost and statutory reporting.

The governance engine

Every change is a governed, audited transaction

Most HR apps let you edit records in place. HRMSTONE doesn't. Every change — a raise, a transfer, a leave request, a loan — is a typed transaction that moves along two independent axes: a workflow status and a posting status. Posted is immutable; corrections are reversing or retroactive entries, never silent edits.

  • Two-axis lifecycle

    Workflow (Draft → Pending → Approved) × posting (Unposted → Posted). Posted = locked, accounting-style.

  • Approval engine

    Ordered steps, committees, delegation, consultation and SLA escalation — segregation of duties by design.

  • Effective-dated & retroactive

    Back-date a change and the engine computes the exact delta as arrears — it never corrupts history.

  • Provable & audited

    Per-line calculation logs explain every number; an immutable trail records who did what, when.

How the transaction kernel works
Transactions & workflowTXN-48213

The transaction kernel every change rides

  1. 1Draft
  2. 2Pending
  3. Approved

Posted · immutable

Corrections are reversing or retroactive entries — never edits.

  1. 1

    Draft

  2. 2

    Approve

  3. 3

    Post

  4. 4

    Reflect

MENA & GCC statutory, built in

Statutory-accurate pay in every market you operate

Each jurisdiction is a versioned, effective-dated country pack — so a law change next year never rewrites last year, and the figures published always match the figures paid.

End-of-service gratuity

Tiered accrual slices (e.g. 21 days/yr for years 1–5, 30 after), average-salary basis and per-country base components.

Social security & filing

Employee/employer contribution engines with ceilings, plus authority batch filing — GOSI, GPSSA, ETA.

Residence & visa lifecycle

Iqama/residence renewal, exit/re-entry, dependents and air-ticket entitlement, with expiry-driven alerts.

Wage protection & GL

WPS-format bank files for KSA/UAE and journal vouchers that bridge straight into your finance system.

Tax engines

Bracket/exemption engines as a calc-pipeline stage — PAYE for the Levant, disabled where there's no income tax.

Versioned country packs

Concurrently active, effective-dated config — adding a jurisdiction is data, never a fork.

Payslip · JordanJOPack v3
Gross salary
1,200.000
Social Security (−)
84.000
Income tax (−)
12.500
Net payJOD 1,103.500

Statutory pack matches the published reference

Countries in scope

  • SASaudi Arabia
  • AEUAE
  • QAQatar
  • KWKuwait
  • BHBahrain
  • OMOman
  • JOJordan
  • EGEgypt
  • LBLebanon

Jordan is production-grade; other packs are clearly flagged until confirmed with each authority.

Enterprise localization

Five locale axes — resolved independently

Localization isn't "translate the buttons." A user in Riyadh can read English, see Hijri dates, format in SAR, on Riyadh time, under KSA rules — all at once. HRMSTONE models each axis separately and resolves it per user.

One user · Riyadh

Five axes, resolved independently

  • UI languageEnglish / العربية
  • Formatting regionSAR grouping
  • CalendarHijri (Umm al-Qura)
  • TimezoneAsia/Riyadh
  • Data jurisdictionKSA country pack

Per-user preferences

Each person chooses their language, calendar, timezone, digits and theme — and their own payslip renders that way.

Hijri ⇄ Gregorian

Switch calendars as a reversible display conversion over a UTC instant; dual-display and legal-output locks supported.

Currency-correct money

JOD, KWD, BHD and OMR carry 3 decimals — a Money type uses currency-driven precision so payroll never silently rounds wrong.

Digit shaping

Eastern-Arabic ٠١٢٣ or Western 0123, per context — Arabic UI often keeps Western digits for money and IDs.

True RTL mirroring

Full layout mirroring via CSS logical properties, mirrored directional icons and bidi-isolated mixed content.

Bilingual documents

Letters, payslips and notifications render in the recipient's locale — Arabic + English side-by-side where required.

What makes it enterprise

Not a CRUD app with a payroll formula

Enterprise isn't a feature you add — it's a set of deliberate properties that let one system serve large, regulated, multi-entity organizations without custom code per customer.

Configurable engine

Builder + Transaction split and a formula engine — a new allowance or country is configuration, not a code change.

Multi-everything

Multi-tenant, -company/branch/site, -country, -currency, -lingual and built to run payroll over tens of thousands of employees.

Governance & audit

Everything is a transaction, posted is immutable, and transaction-level permissions enforce who may create vs. approve.

Money correctness

Effective-dating, retroactive deltas, per-line logs, idempotency keys and settlement stoppers — provably right under change.

Security

SSO/JWT, RBAC + ABAC scoped by tenant/branch/manager-chain, two personas, and field-level PII encryption.

Built to last

A modular monolith per product, own PostgreSQL, schema-per-module, with CI-enforced boundaries — not microservice sprawl.

Deployment & data sovereignty

One codebase. Deployed on your terms.

From managed SaaS to a fully air-gapped install — the same product, with the control posture banks and governments require.

Hosted

Managed SaaS

We host and operate it, multi-tenant. Every workspace gets its own isolated database; tenancy is resolved from the token and fails closed.

  • Per-tenant database isolation
  • Region-pinned for residency
  • JIT, consented break-glass support
Sovereign

BYO-Database + your keys

Bring your own PostgreSQL and customer-managed keys. We run the app; you hold the encryption key — revoke it and access stops instantly.

  • Customer-managed keys (BYOK/CMK)
  • Envelope-encrypted PII
  • Revocable kill-switch
Banks & gov

On-prem / air-gapped

Host the entire stack in your data center, single-tenant. Zero standing vendor access; support is escorted and customer-recorded.

  • Signed, air-gap release bundles
  • Zero standing vendor access
  • You own keys, backups & restore

Agent-ready by architecture

Let AI draft. Keep your people in control.

Because every change is a typed transaction that routes for approval, an AI agent can prepare a payroll run, onboard a joiner or answer a request — then hand it to the right approver. Nothing reaches your records without a human decision, and every step is logged.

  • Agents draft, people approve

    Agents stage transactions through the same submit → approve → post → reflect kernel your team uses. No silent writes.

  • Contract-first API

    Every capability is a typed, OpenAPI-described operation — the same contract your apps, integrations and agents call.

  • Every action audited

    An append-only history records who — or which agent — did what, when, and what it changed.

  • Scoped by permission

    Agents inherit the same RBAC + ABAC as people, scoped by tenant, branch and manager-chain — never more.

Read the API docs
agent · payroll.run

→ resolve_employees(country: "JO") · 248 active

→ calculate_payroll(period: "2026-06") · pack JO v3

✓ 246 payslips balanced · per-line logs written

⏸ submit_for_approval(role: "Payroll Manager")

● awaiting human approval — nothing posted

  1. 1

    Plan

  2. 2

    Act

  3. 3

    Approve

  4. 4

    Post

How it works

Live in weeks, not quarters

  1. 1

    Provision & configure

    Spin up an isolated tenant (or install on-prem), load your country packs, org structure and role matrix.

  2. 2

    Bring your people in

    Import employees into the canonical directory and connect payroll, time and leave — bilingual from day one.

  3. 3

    Run, approve, post

    Run payroll, route changes through approvals, post immutable results and file with the authorities. Every step is logged.

Trust & compliance

Standards we build against

Security and compliance are part of the architecture, not an afterthought.

ISO/IEC 27001:2022SOC 2 (Trust Services Criteria)OWASP Top 10Database-per-tenant isolationCustomer-managed encryption keysImmutable audit trail

Get started

Run payroll and HR for your whole group — on one governed platform.

Book a demo and see HRMSTONE run multi-country payroll, statutory filing and approvals — as SaaS, or on-premise for banks and government.

  • Statutory-accurate, MENA & GCC
  • SaaS or on-prem, your keys
  • Arabic & English, Hijri & RTL