+33 (0)1 87 66 00 65 · Monday to Friday, 9am–6pm Free audit (15 min)
● B2B offer — HR & personnel administration

Employee records: documents filed, deadlines met

A complete employee record is both an obligation and a peace of mind: contract, variations, medical check-ups, authorisations, training. Your agent files each document received in the right place, flags what is missing against your internal rules and tracks renewal dates. Hosted in France: your employees' data stays with you. The HR team decides what to do about each flag.

Hosted in France Staff data protected GDPR & AI Act: governed deployment Human oversight

Updated on

Deployed in a few weeks
HR document management · hosted in France
Which employee records are incomplete?
Eleven records are missing a document against your internal rules.
For each: the document expected, the rule that requires it and the date it has been outstanding since.
Four concern an authorisation whose renewal date is approaching: they are put at the top.
🔗 Sourced · employee records and internal rules
Prepare the requests for the documents.
Requests drafted to each employee concerned, with the document expected and its deadline.
They are put to the HR team before sending: a letter to staff commits the employer.
✎ Action · requests to read over, sending decided by you
Local inference · no data outside the EU
Files hosted in France
Sovereign by designLocal inference or hosting in France
GDPR & AI Act: governed deploymentTraceability & human oversight
TurnkeyDesigned, installed and operated for you
The human resources team decidesThe agent prepares, never rules
✦ In brief

A Blue Lemon Agent HR document agent files the documents in employee records, flags those missing against your internal rules and tracks renewal dates — medical check-ups, authorisations, mandatory training. Requests for documents are prepared and read over before sending. It runs on local inference or is hosted in France: your employees' data stays with you, architecture designed to reduce exposure to extraterritorial legislation, location alone not being enough to guarantee immunity.

100%
hosted in France in the target architecture
0
transfer outside the EU in the target architecture
6
HR uses ready to deploy
0
decision taken without human approval

These figures describe our offer, not results measured at a client. How large the gain is on your number of employees and documents tracked is confirmed by a pilot.

The context

What does an AI agent bring to your employee records?

A complete record and deadlines seen in advance mean time given back to the HR team and compliance kept without a last-minute scramble.

! The issue

Keeping an employee record rests on two routine acts: filing the document received and checking what is missing. Multiplied by the headcount, they take up a real share of HR time. The agent takes them on, drawing on your internal rules, and sets out renewal dates before they arrive.

Our answer

The HR team sees at a glance the records to complete, the rule that requires it and the deadlines approaching. Requests for documents are prepared but read over: a letter to staff commits the employer. Local inference or an isolated resource hosted in France: your employees' data, among the most sensitive the company holds, is entrusted to no third party.

The decisive point

Your employees' personal data: sovereignty & compliance

Employee records concentrate personal data, sometimes health data. Here is how the architecture of our agents protects it.

Local inference

The agent can run on a machine belonging to your organisation: no document and no employee data leaves the network.

Hosting in France

Otherwise, a dedicated and isolated resource hosted in France, under French law — your employee records and your mandatory documents: processing and access within the European Union targeted by the architecture.

Reduced extraterritorial exposure

For your employees' personal data, the architecture aims to reduce exposure to the Cloud Act and FISA 702; being located in France or in the European Union does not, on its own, guarantee immunity.

Isolated resource

No pooling: an environment strictly dedicated to your company and its internal rules.

Every flag tied to a rule

Any document flagged as missing refers back to the internal rule that requires it; encryption, role-based access, logging of consultations and purging at the retention periods you set.

AI Act: governed deployment

The agent is strictly in support; no letter is sent and no decision about an employee is taken; traceability and human oversight from end to end.

What depends on the architecture chosen These points are not general guarantees: they are settled deployment by deployment, in the quotation.

  • The applicable location is that of the architecture set out in the quotation and verified before commissioning.
  • Local execution is announced only for the configuration explicitly described and accepted in the quotation.
  • The applicable isolation depends on the deployment mode set out in the quotation; no dedicated isolation is presumed.
  • Roles and permissions are configured and accepted for the identities and systems actually connected.
  • The events logged, their content, their retention period and who may access them are defined for the deployment chosen.
For health documents, disciplinary files and sensitive individual situations, SecNumCloud and reinforced hosting are options depending on your requirements. A single architecture is designed to answer both the GDPR and extraterritorial exposure. Designed for deployment in line with the GDPR and the AI Act, after the processing, roles and context-specific risks have been assessed.
Demonstration

See the agent at work

4 real situations, taken from those that come up most often. Pick one: the exchange unfolds as it would in your organisation.

A scripted demonstration. These exchanges show how the agent behaves — its sources, its refusals, what it leaves to your teams. Nothing is sent from this page, no model is queried here, and the matters named are fictional. That is precisely what we promise your data.
The behaviours shown here — monitoring, automation rules, routing and reminders — are configured with you during deployment, from your tools, your rules and your thresholds.
The architecture points named in these exchanges — location, local execution, isolation, encryption, role-based access, logging — are not a guarantee attached to the demonstration: they are those of the architecture set out in your quotation, and verified before commissioning.

HR document management · hosted in France
Four flags this morning on your personnel files.
· Forty-one contract amendments carry no employee signature. Eleven concern a change of pay.
· Thirty-four medical documents sit in ordinary personnel files, reachable by seven people. I restricted them this morning; I opened none of them.
· Nine disciplinary items exceed the retention period set by your note of 03/03/2025, the oldest by six years.
· Two hundred and twelve documents are filed as "miscellaneous". I could not say what they were, and I did not guess. morning-watch_4-flags.pdf34 documents restricted · 0 opened
⛓ Source · 214 personnel files, procedure note of 03/03/2025, access rights
You restricted 34 documents without opening them? How?
By what is written on them and around them, never by what they contain.
What I read: the file name, the issuer where it appears in the letterhead, the form type, and the folder it sits in. A fitness certificate carries a heading, a sick note has a known layout, a doctor's letter has a letterhead.
What stays closed, and it is what makes the filing usable: the body of the document. A reason for absence, a fitness restriction, a diagnosis enter no index — the 34 items are filed, named and dated without a single health datum changing hands.
What I did this morning, on my own: I brought their access from seven people down to those your note designates. It is the only action I take without asking, and it always goes the same way: less access.
What goes out prepared and waits for your click: opening an access, moving a document out of the file, deleting it. The request arrives written — who, which file, what reason, until when — and it is approved in one click: the 12 requests this month were each settled in under two hours. Restricting wrongly is repaired in a minute; opening wrongly is not — the document has been seen, and that is the only reason that particular click is yours.
What I supply: the list of 34, by type and by file, without one line of their content. 34-documents_restricted-unopened.pdf7 accesses → those the note designates
⛓ Source · headings and letterheads, note of 03/03/2025, access log
How did you spot all that? And who do you tell?
I watch, continuously, what you have opened to me: personnel files, access rights, your procedure note, and the dates the documents carry.
Routing follows what can be repaired: an unsigned amendment goes to HR, and nobody else — it is a contractual matter; a misfiled medical document to HR, with the restriction already in place; a disciplinary item beyond its period to the same person, never to the employee's manager; a document I could not classify to whoever files, marked "undetermined".
With a chase: 48 h on over-wide access, 7 days on the rest. Then a monthly summary: by document type and by gap, never by employee.

What is already secured this morning: 34 medical documents have gone from seven readers to those your note designates, without one of them being opened; 41 unsigned amendments are out of the shadows, 11 of them on pay; 9 disciplinary items beyond their retention period are dated and listed. Across 214 files, that is a completeness check that no longer happens file by file, but continuously.
Sovereignty here is a setting, not a promise: access is opened by role, logged, withdrawn on a word, and nothing leaves the company — local inference or an isolated resource hosted in France. The only move I make on my own always goes the same way: less access, and it is undone in a minute.
What follows is yours, and it is ready: chasing the 41 signatures, refiling the 212 "miscellaneous", purging the 9 items beyond their retention period — that last one cannot be undone, so it waits for a mandate that names the 9 items, one by one. On a written, capped, dated mandate, revocable on a word, the rest is carried out within minutes, with the log to show for it, and your HR team reads one statement instead of reopening 214 files.
✎ Framework · restrict alone, never open alone, never delete
And what is missing from the files — do you know that?
Yes, and never "against good practice": against your rules, the ones in your procedure note of 09/01, article by article.
Across 212 personnel files, your note requires nine documents per employee — fourteen for posts requiring an authorisation. There are 147 missing documents, and they are very unevenly spread:
· 61 medical examination certificates absent from the file, 38 of them for employees you told me had attended: this is the document that exists and never reaches the file;
· 34 proofs of qualification required by article 4 of your note;
· 28 mandatory training certificates for posts that require them;
· 19 bank details predating the last declared change;
· 5 signed copies of the staff handbook.
Every flag carries the rule that grounds it, quoted — "procedure note of 09/01, article 4, paragraph 2" — and the person who holds the document. A gap with no rule quoted gets argued about for six months; a gap with its rule is closed in a week.
What is not counted as missing: 23 documents are present but illegible or unsigned. They are counted separately — asking again for a document is not the same errand as getting the one you already have signed.
✎ Framework · missing documents against your written procedure, rule quoted
And the medical checks and authorisations coming up for renewal?
Renewal dates are tracked across the three families your note names: medical examinations, authorisations, mandatory training.
What falls due over the next six months, in date order:
· 14 electrical authorisations expire, 3 of them within 30 days. Those block an assignment the day they lapse — the one case where a renewal cannot be caught up afterwards;
· 29 periodic medical examinations, 6 of them already more than two months overdue;
· 17 mandatory training courses to retake, 9 of which concern the same team and can be grouped into one session — 4 training days saved if you group them, and the grouping calendar is already proposed.
Reminders go out at 90, 45 and 15 days, to the HR manager and the line manager, never to the employee directly — that is your rule, not mine. Each reminder carries the expiry date, the source document and the cycle that sets it.
What the tracking caught over twelve months: no authorisation expired without a renewal under way, against 7 the previous year, and two assignments postponed rather than cancelled.
A figure that does not suit me: 11 due dates were calculated from the wrong date, all medical examinations whose file carried the appointment date rather than the certificate date. The certificate date now overrides any other date in the file, and all 11 were recalculated — 3 were in fact overdue and went out as reminders the same day. And nothing is deleted in the process: an expired document stays on file, it only changes state.
⛓ Sourced · dates on the file documents, renewal cycles from your note
Local inference · no data outside the EU

Your case is not here? That is exactly what a 15-minute conversation is for. Book the free audit

Use cases

What does the agent actually do?

One agent, the whole document cycle of an employee record. All these uses work in support, subject to your approval.

Included in your agent The 4 capabilities essential to this promise are included, at no extra cost.
From 710 € excl. VAT / month

Filing the documents

Puts each document received in its place in the record concerned.

Missing documents

Flags what is missing against your internal rules, with the rule cited.

Renewal dates

Tracks medical check-ups, authorisations and mandatory training.

File and index HR documents

To extract the data from the documents received, a dedicated document agent completes the picture.

Controls and safeguards These 5 controls are built into the agent: they frame what it does, whatever plan you pick. They are not chosen and are not added to your order.
Human validation, exceptions and escalation Status, safe closure and audit trail Apply transparent criteria and avoid automated decisions Preserve human validation, recourse and audit trail Protect HR data with fine-grained access and retention periods
What the agent must be connected to This connection is required for the agent to work. It concerns your information system and is scoped during the audit.
Integrate with the HR information system/ATS and measure quality, turnaround time and fairness
The gain

How much time can an HR team give back to people?

By taking on the filing and the checking, the effort shifts towards supporting employees. How large the gain is depends on your volume and remains to be confirmed by a pilot.

Filing the documents received
Today · done by hand
Documents filed
Checking completeness
Today · done by hand
Gaps flagged
Tracking mandatory deadlines
Today · done by hand
Deadlines set out
Indicative figures, not contractual, to be confirmed by a pilot on your number of employees and documents tracked. A letter to staff commits the employer: requests for documents are read over by the HR team before sending.
How it works

The stages of your AI agent project

1

Audit & scoping

15 minutes to target the use case with the best return.

2

Quote or direct sign-up

A catalogue offer is bought online; a specific need gets a costed quote.

3

Design

We design the agent and its guardrails.

4

Integration & testing

We connect your tools to the agent, which is itself hosted in France.

5

Rollout

Going live and training your team.

6

Operation

Continuous supervision and improvement.

Pricing

One package, one agent

An HR document agent (filing, completeness, deadlines), installed and operated for you.

Agility

Setup + controlled subscription

7,825 € excl. VAT setup
then 710 € excl. VAT/month — you invest at installation and pay a reduced subscription. Ideal for keeping the cost under control over time.
  • Installation, configuration and training for your teams
  • Operation, human oversight, updates and support
  • Sovereign hosting in France, a dedicated and isolated resource
Order →
The simplest Serenity

All inclusive, no setup fee

1,145 € excl. VAT /month
all inclusive, immediate start. No upfront investment: a single subscription. Ideal for starting quickly and simply.
  • Setup included (installation, configuration, training)
  • Operation, human oversight, updates and support
  • Sovereign hosting in France, managed end to end
Order →
100% Sovereign

On site, you own it

11,815 € excl. VAT setup
then 931 € excl. VAT/month · + hardware from 2,491 € (one-off purchase, in addition) — a sovereign computer installed on your premises, maintained remotely. Models run locally, your data returned at the end of the contract. 36-month commitment.
  • Hardware installed on your premises (you own it)
  • French / European AI models run locally
  • Secure remote maintenance (Pro support included)
Order →
Not included in the packages: AI consumption (model tokens), re-invoiced at real cost with no margin, and tracked in real time in your client area. Maintenance and supervision subscription for an initial term of 12 months for the Agility package, 24 months for the Serenity package and 36 months for the 100% Sovereign package, renewable; support levels (SLA 72 h / 24 h / 4 h) optional. Bespoke development, additional integrations or exceptional volumes are quoted separately. Support Monday to Friday, 9am to 6pm. Prices exclude VAT.
AI model: none of the AI models offered currently carries a fixed surcharge. When the selected model carries a cost, that cost is shown when you choose it, before you order, and re-invoiced at the cost incurred, with no mark-up; usage is billed at the publisher's price. Publishers' prices are published in US dollars: the amount re-invoiced is the amount in euros actually borne by Blue Lemon Agent on the publisher's invoice, at that invoice's exchange rate, with no commission or mark-up.
Included components and additional components Components included in the base offer: the Blue Lemon Agent software foundation, the AI models listed in the order journey, the standard channels (Microsoft Teams, Slack, WhatsApp Business, email, website chat, calendars, Microsoft 365 / Google Workspace, file storage, market VoIP telephony, professional social-media pages and accounts, Google Business Profile), hosting in France for the package chosen, backups, supervision, updates and support. If adapting the AI agent to your constraints, your needs or your requests requires other paid components — a third-party publisher's software licence, paid API access to one of your applications, hosting of health data, for which French law requires an HDS-certified host (art. L. 1111-8 of the French Public Health Code), SecNumCloud-qualified hosting, a speech synthesis service, particular hardware —, they are offered to you as an option or on quotation and re-invoiced at the cost incurred; nothing is committed without your written agreement. Where the artificial intelligence model you choose entails an additional cost, that cost is shown to you before you order and re-invoiced to you at the cost incurred, with no margin.
What to expect
Go-live 2 to 3 weeks
Agent designed, channels connected, team trained.
Steady state 4 to 7 weeks
After a few weeks of real use, once the agent's behaviour matches what you expect. Indicative estimate, adjusted to the options you keep. It is not a delivery commitment.
Our commitment

Four guarantees that matter to your employee records

Your employees' data stays with youLocal inference or an isolated resource hosted in France; no document and no employee data entrusted to a third party, no data used to train a model.
Data in France, under French lawYour employees' personal data: minimisation and location in France, architecture designed to reduce exposure to extraterritorial legislation, location alone not being enough to guarantee immunity.
The human resources team keeps the decisionThe agent produces employee records that are complete and up to date, which can be checked and altered; no approval is automated.
Human oversight & traceabilityOn your number of employees and documents tracked: systematic logging and tracking, in line with the AI Act.
Frequently asked questions

Your questions, our answers

Does the agent take decisions about an employee?
No. It files, checks completeness and tracks deadlines. Anything that follows from a flag rests with the HR team.
What is the list of expected documents based on?
On your internal rules, as you have set them out. Every document flagged as missing refers back to the rule that requires it.
How are health documents handled?
They are among the categories you can place under restricted access from the design stage, with stricter partitioning than the rest of the record.
How long are the documents kept?
For the periods you set, with automatic purging at the deadline, in line with the GDPR.
Is our employees' data protected?
Yes. The agent is hosted in France, on local inference or an isolated resource, with the deployment objective of processing and access operated within the European Union and an architecture designed to reduce exposure to extraterritorial legislation, location alone not being enough to guarantee immunity. That data is not used to train a third-party model.
How long does it take to deploy this agent?
A few weeks as a rule, depending on the headcount and the integration with your HR information system, after a free audit then a phase of design, integration and testing.
Let's talk

Let's size up the potential in your employee records

15 minutes to frame your headcount and your internal rules — hosted in France, supervised, with no commitment.