Give your agent HR recordswith the rules built in.
31 MCP tools for reading and writing people, leave, assets, hiring and exits. The rules live in the server, not in your prompt, and every refusal is a sentence your agent can act on.
Where HR agents go wrong.
01
Rules in the prompt
A policy written into a system prompt is a suggestion the model can talk itself past.
02
Errors with nothing to act on
A 400 with no reason leaves the agent guessing what to change.
03
No record of what it did
Changes made by an agent look the same as changes made by a person.
Scenarios
What your agent sees.
How OpenHR answers
The refusal lists the legal moves from the current status, so the next call is right.
How OpenHR answers
Leave is an auditable record, so a request with no reason is refused.
How OpenHR answers
run_query accepts SELECT only, on a read-only connection.
What changes.
- Rules you don't re-implementBalances, custody and state machines are the server's job.
- Refusals that teachEach one says what was wrong, and often what is allowed.
- A record of every writeThe audit log commits with each change.
- Small to runSQLite and one Python process, under Apache 2.0.
Controls.
Leave can't go negative
A tracked balance never drops below zero, and overlapping requests are refused.
One holder per asset
A second open assignment is refused by the service and by a database index.
Exits gate on custody
Asset clearance can't be signed off while kit is out.
Audit log
Every change writes an audit row in the same transaction.
Read-only SQL
run_query accepts SELECT statements only.
Self-hosted
One SQLite file on infrastructure you control.
Questions.
Which clients work?
Claude Desktop and Claude Code over stdio, and any MCP client that speaks streamable HTTP or SSE.
Can I use it from Claude on the web?
Only as a remote server behind a tunnel, and with no auth that exposes every record. The repo's connector guide covers the risk.
Does it have sign-in?
Not yet. The open-source server has no sign-in or roles, and its HTTP transports bind to localhost by default. Keep it off shared networks. API keys with employee, manager and HR-admin roles are planned for v0.2, and Attri adds sign-in and roles in managed deployments.
Let your agents handle the HR admin.Keep the rules on the server.
Run OpenHR on a demo company in minutes, or have Attri deploy it inside your environment with sign-in, roles and approval rules.