HR views an employee-shared certificate photo
Current corporate owner/HR role and fresh passkey required. Explicit per-photo submission consent, active employee, unexpired photo and non-withdrawn request required. Every successful read is audited without photo content. No public URL or email attachment.
Authorization
bearer In: header
Path Parameters
^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$uuid^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$uuidResponse Body
application/json
curl -X GET "https://example.com/v1/partner/tenants/497f6eca-6276-4993-bfeb-53cbbbba6f08/leave/497f6eca-6276-4993-bfeb-53cbbbba6f08/certificate"{ "mimeType": "image/jpeg", "expiresAt": "2019-08-24T14:15:22Z", "base64": "string"}HR leave review and operational counts for an authorised corporate workspace GET
Includes only employee-submitted leave for active members, never drafts or health-passport data. Counts include all non-draft states in the requested date window, independent of the list status filter. Day totals are calendar days overlapping that window, not working days, paid leave or remaining entitlement.
Record an HR decision on a submitted request POST
Requires a current corporate owner or HR-admin membership, denies self-review, and permits only a pending request. Decisions are immutable. Reuse the decision UUID with identical content after a lost response. The decision records the employer's workflow; it is not a legal or medical eligibility determination.