← Back to Deck
D myDOSZ HCM

All Modules & Integrations

One ERP-grade HCM + Operations system built for a multi-company group — from staff check-in, through each entity's own payroll & LHDN tax filing, to management decisions.

📱 App + Web + PWA🏢 7 companies, one system🇲🇾 LHDN tax payroll🏪 1,000 outlets🤖 AI OCR + Explainer
9
Module groups
35+
Modules & sub-modules
460+
REST API endpoints
16
Integrations / services
New

Group structure: employer ≠ payer

In a real group, the company that employs someone is not always the company that pays them. The system holds those as two separate facts — and every report knows which one it must follow.

Staff of company A Salary paid by company B Payslip & LHDN forms follow B· Org chart & chat follow A
Follows the EMPLOYER (who they work for)Follows the PAYER (who releases the money)
Org chart & reporting linesPayslip letterhead + stamp & signature
Chat segregation between companiesStatutory contributions (EPF · SOCSO · EIS · PCB)
Employee directory & HR reportsLHDN forms — EA · E · CP39 · C.P.8D
Performance appraisal & tasksSalary payment list + bank file (CSV)
Module Map

Nine groups, one system

Every module shares one database & one API layer — app, web and PWA all see the same data.

🏢

Group Structure

5
  • Subsidiary companies
  • Employer ≠ payer
  • Employer numbers per entity
  • Stamp & signature per entity
  • Bank account per company
🕒

Attendance & Time

7
  • Tap Check-in/out
  • Outlet Geofence (1,000)
  • Anti Fake-GPS
  • Outlet Visit (area manager)
  • Live GPS Tracking
  • Breaks
  • Daily/Monthly Reports
💵

Payroll & Tax (LHDN)

11
  • Salary · Payslip
  • EPF·SOCSO·EIS·PCB
  • Lindung 24 Jam
  • Statutory per company
  • LHDN forms per entity
  • Payment list + bank CSV
  • Bulk salary & bank entry
  • AI Payslip Explainer
  • Roster-Payroll
📝

Leave & Requests

3
  • Leave (assign/apply/history)
  • Approvals inbox
  • Claims + receipt OCR
🧾

Fill-in Forms

5
  • Expense
  • Meeting
  • Appointments
  • Visit
  • Travel
👥

People & Talent

6
  • Employee Directory
  • Onboarding & Offboarding
  • Performance Appraisal (auto-score)
  • Reporting lines (manager)
  • Training
  • Org Chart
📋

Projects & Tasks

3
  • Project Management (boards)
  • Task Board (Kanban)
  • Work Tracker
  • Rule automation
💬

Communication

5
  • Chat segregated by company
  • Team Chat + DM
  • Notices (received PDFs)
  • Broadcast + scheduled
  • Shared calendars
⚙️

Admin & Config

7
  • Subsidiary Companies
  • Statutory Config
  • Attendance Rules
  • Outlet Geofence
  • OCR AI Settings
  • Employer Tax Numbers
  • Roles & Permissions
Integration Architecture

Every service, and its job

Everything revolves around one core — the Laravel 12 REST API — so modules, mobile clients, and external systems all speak the same language.

🔗
Laravel 12 REST API
Central core — every module, mobile client & the POS→performance feed connect here
460+ endpoints
Service / IntegrationRole in the platformType
Group StructureEach entity carries its own name, SSM number, address, employer numbers, stamp & bank account — payslips and tax forms follow the paying entityPlatform
POS ↔ HCMOperator mapping + POS sales feed → performance appraisal + auto-syncs new outlets into the geofence (daily cron)Integration
AI Receipt OCRAuto-fills amount / date / merchant on expense claims — AI-poweredAI
Local OCR (offline)Free on-server OCR — fallback when AI is off / to keep data privateFree
AI Payslip ExplainerExplains each payslip in plain language — AI-poweredAI
Statutory + LHDN EngineEPF·SOCSO·EIS·PCB (official Computerised method, validated) — computed per paying companyCompliance
Bank file (CSV)Salary payment list ready to upload to the bank — one file per paying companyFinance
Firebase Cloud MessagingReal-time push notifications to staff phonesCloud SDK
OpenStreetMap + LeafletLive location map — free, no per-call feesMap (free)
Device GPS / GeolocatorAttendance geofencing & field trackingNative
WebView SSO BridgeOpens web modules auto-logged-in inside the app (HMAC token)Bridge
pdf.js (self-hosted)Renders notice / payslip PDFs in-app — privateViewer
Laravel SanctumAPI token authentication + SPA / PWA sessionsAuth
stancl/tenancyData isolation per company / tenantPlatform
App Store Connect + Google PlayAutomated app build, review & distribution (iOS + Android)Store
Security & Compliance

Built to be trusted

Anti-fraud controls on every check-in, and an architecture aligned with Malaysian security & privacy standards.

🛰️

Anti Fake-GPS

  • Mock-location detection
  • "Impossible travel" alerts
  • Outlet-radius geofence
⏱️

Anti Time-Amendment

  • Timestamps = server time
  • Phone clock can't alter records
🔒

Anti Brute-Force

  • Login rate-limit (30/min)
  • Single-Device Login
  • Sanctum tokens
🔐

Data & Privacy

  • HTTPS + bcrypt passwords
  • Data separated between companies
  • Action audit logs
StandardPlatform approach
Malaysia PDPADesigned to PDPA principles — consent, data minimisation, in-country hosting, published privacy policy
NACSASecurity practices aligned to NACSA guidelines (access control, audit, incident readiness)
ISO/IEC 27001Architecture following ISO 27001 best practices (access control, encryption, audit trails)
Honest note: the platform is designed to the principles above — formal certification (if required) is a separate audit process.
myDOSZ HCM · All modules share one Laravel 12 REST API & one database · updated 1 August 2026