Multi-company HR governance is the single hardest problem in group HR, and it is the problem that Western HRIS platforms were never designed to solve. A Saudi holding company running five to fifty legal entities needs an HR system that lets the Group Head of HR see consolidated workforce metrics, lets each entity's HR Manager administer only their own employees, and lets the group CHRO oversee the entire structure without ever leaving a single connected system. The default answer from single-entity HRIS vendors — separate tenants per entity, or one shared admin account across the group — both fail: the first breaks Nitaqat consolidation and doubles the licence bill, the second is an NDMO audit failure waiting to happen. This guide walks through the four best-practice components of multi-company HR governance — the Organizations → Companies → Departments model, RBAC with Permissions & Roles, centralized Approval Workflows, and People Analytics across entities — and how U HR implements each as a native capability.

The multi-company governance problem #

Multi-company HR governance has three structural requirements that single-entity HRIS platforms cannot meet. First, the data model must represent the holding group's hierarchy — Organization at the top, Companies as legal entities, Departments within each — so that each employee, attendance record, and payslip is correctly scoped. Second, the access-control model must be granular enough to scope each HR administrator to their entity or department, with create, edit, delete, and fetch rights enforced per module — not a single 'admin' role applied uniformly. Third, the approval and analytics layers must span entities: a leave request from a Company A employee may need approval from a Company A manager and a group-level HR review, and the group CHRO must see consolidated workforce metrics without manually consolidating reports from each entity. These three requirements are visible in the first 90 days of any multi-entity HR implementation: if any of them is missing, the group ends up with parallel Excel systems, a quarterly consolidation email cycle, and an audit trail that breaks the moment an HR Manager at one entity touches another entity's data. U HR's design addresses all three natively, which is why multi-entity holdings are its core market.

The Organizations → Companies → Departments model #

The Organizations → Companies → Departments hierarchy is the foundation of multi-company HR governance in U HR. An Organization is the top-level owner — typically the holding group, the family business, or the parent company. Below the Organization, one or more Companies are added — each Company is a separate legal entity with its own commercial registration, GOSI establishment code, MHRSD establishment code, and Nitaqat band. Within each Company, Departments carry a code, an org scope, and a reporting line — and serve as the natural unit for attendance oversight, approval routing, and Nitaqat weighting by job family. This three-level hierarchy is what enables per-entity Nitaqat computation, per-entity GOSI contribution schedules, per-entity WPS file generation, and per-entity MHRSD reporting — all critical for a Saudi holding group. The hierarchy also enables the access-control model: an HR Manager scoped to Company A can see only Company A's employees, attendances, and payslips, while the group CHRO sees the consolidated view. This is the structural difference between U HR and a single-entity HRIS retrofitted with a 'locations' or 'divisions' workaround — those workarounds cannot model separate legal entities, which means Nitaqat and GOSI cannot be computed correctly per entity.

RBAC with Permissions & Roles #

Role-based access control (RBAC) is the second pillar of multi-company governance, and U HR's Permissions & Roles module is built specifically for the multi-entity use case. Every screen in U HR is registered as an access-control object through the Modules feature; Permissions & Roles lets the Group Head of HR grant create, edit, delete, or fetch rights per module per role; HR Accounts manages the administrator accounts themselves and the roles attached to them. A typical multi-entity configuration has three role tiers: an Entity HR Manager role with full CRUD rights scoped to a single Company; a Group HR Business Partner role with read-only access across multiple Companies; and a Group CHRO role with full visibility across all entities. Each role is scoped per Company or per Department, so an HR Manager at Company A literally cannot see Company B's salary structures — the access-control pattern that NDMO auditors expect when personal data is in scope. For multi-entity groups pursuing NDMO certification, this granular RBAC is not optional; it is the access-control evidence that the certification audit requires.

Centralized approval workflows #

Centralized approval workflows are the third pillar of multi-company governance. In a Saudi holding group, every leave request, advance, permit, level change, skill endorsement, and payslip batch should route through a defined approval chain that respects both entity boundaries and group oversight. U HR's Approval Workflows feature in the Employee Manager app lets the Group Head of HR define these chains centrally: a leave request from a Company A employee routes first to their line manager (Company A scoped), then to the HR Manager of Company A, and may optionally route to a Group HR Business Partner for cross-entity visibility. Payslip batches route through the Entity HR Manager (generator), the Entity Finance Manager or CFO (approver), and the Group CFO (oversight). Skill and level changes route through the relevant reviewer via the Approval Management screen in the U HR Manager app, with calibration through Skills & Calibration in the Employee Manager app. Every approval carries a reviewer stamp, a timestamp, and an optional note — the audit trail that MHRSD, GOSI, and NDMO auditors expect. The centralization is what matters: defining the approval policy once, at the group level, and applying it consistently across all entities — rather than letting each entity define its own approval policy and producing a fragmented audit trail.

People Analytics across entities #

People Analytics is the fourth pillar — the executive dashboard that closes the visibility gap for multi-company holdings. The Employee Manager app's People Analytics feature surfaces attendance, skills, and career-health metrics across all entities, with the Org-Wide Visibility view providing the consolidated picture and per-entity drill-down available on demand. A group CHRO can see total headcount, Saudization ratios per entity, attendance trends per entity, skill-coverage gaps per entity, and payslip-cycle status per entity — all in a single dashboard, all in real time, and all without emailing five HR Managers for spreadsheets. The People Analytics view also surfaces trends over time: headcount growth per entity, Saudization-band movement per entity, attendance-exception rates per entity. This is the data foundation for the group CHRO's quarterly board report, and it is what replaces the consolidation-email cycle that most multi-entity HR teams still rely on. For mega-project procurement owners — NEOM, Red Sea, Aramco frame agreements — the People Analytics view is also the evidence base for the contractor's HR-compliance packet: Saudization ratios per entity, GOSI history per entity, WPS submission history per entity, and the competence matrix from the Skill Catalog. Producing this packet in minutes rather than weeks is a competitive advantage that compounds with every cycle.

Building the governance operating model #

The four pillars — hierarchy, RBAC, centralized approvals, and People Analytics — are necessary but not sufficient. The fifth component is the operating model that wraps around them: who owns the group HR policy, who owns each entity's HR operations, how often calibration happens, and how the board consumes the analytics. A practical starting point is to designate a Group Head of HR as the policy owner, an Entity HR Manager per Company as the operations owner, a quarterly cross-entity calibration meeting for skills and levels, and a monthly executive dashboard review with the group CHRO. U HR's three-app model supports this operating model naturally: the U HR Manager app is where the policy is configured, the Employee Manager app is where the executive review happens, and the U HR Employee app is where the workforce experiences the result. The combination of the right system and the right operating model is what makes multi-company HR governance tractable — neither alone is enough.