# ASHR-L2-P — practical brief

**Credential:** ASHR-L2, ASHR.work Partner — Implementation and Migration
(Practitioner), track `ashr-partner-l2`.
**Rubric version:** `ashr-l2-p.v1-draft`. A draft until the SME panel confirms
it; the academy's check specs stay drafts until then.
**Who reads this:** the candidate (sections 1 to 5) and the human checker
(sections 6 and 7).

This is the task sheet for the practical half of ASHR-L2. You configure a
synthetic company in an ASHR.work sandbox the way you would for a real customer,
then hand it over. When you submit, read-only checks look at the sandbox and
write a check report. A person confirms that report and records your result. No
agent passes or fails you on its own.

The check ids **A1 to A7** below are the ids the ASHR-L2 check spec uses. Each
task names the check that grades it, its weight and whether it must pass.

---

## 1. Your sandbox

- **One ASHR.work sandbox workspace per attempt**, holding synthetic data only.
  The target is a partner demo tenant seeded from the gold seed framework.
  **That seeding flow is not built yet.** Until it is, the sandbox is a partner
  NFR workspace granted by a super-admin. Either way it allows **at most 10
  users**.
- **A fresh sandbox for every retake.** Retakes follow the academy rule: a
  14-day cooldown and at most 3 attempts in 365 days.
- **Act as the customer's implementer.** You hold the admin role in the
  sandbox, and you may give other synthetic logins the roles and grants the
  scenario asks for.

## 2. Your exam bundle

The bundle is issued with the sandbox:

| File | What it holds |
|---|---|
| Scenario sheet | The synthetic company: its shape, the one state its staff are taxed in, the payroll month, the leave and attendance policy it wants, who runs payroll, and who should be able to sign in |
| `employees.csv` | The people, in the format the old HRMS exported them |
| `leave-balances.csv` | Opening leave balances |
| `holidays.csv` | The year's holiday list |
| `assets.csv` | The asset register |
| `salary-structures.csv` | Annual CTC per person, with effective dates |
| `org-chart.csv` | Who reports to whom |

The files are **deliberately not in ASHR.work's template format**, and some
rows are deliberately wrong. Mapping them onto the templates and dealing with
the bad rows is part of the test.

**The bundle is not built yet.** Until the partner demo tenant seed ships, the
checker prepares it from the six import templates (Admin → Import data →
download template) with synthetic rows only.

## 3. Rules — breaking any of these voids the attempt

1. **Synthetic data only.** Never put a real person, real company or real
   identifier into the sandbox: no real names, emails, PAN, Aadhaar, UAN, bank
   accounts or phone numbers. Use only what the bundle gives you. A real record
   in the sandbox voids the attempt, whatever else is green.
2. **Do not email synthetic people.** Set `send_invite` to `false` for everyone
   who does not need a login. Invites also count against the 10-user limit, so
   rows past the limit come back skipped.
3. **Do not mark the payroll run paid and do not lock it.** Locking cannot be
   undone and releases payslips. Approving the run is allowed, and Task 7
   needs it.
4. **Do not change the plan, billing or partner details.**
5. **Write down every decision you make that the scenario sheet does not
   settle.** You hand these in with the handover note (Task 8).

## 4. Tasks

### Task 1 — Tenant setup · check **A1** · weight 10 · not must-pass

1. Set up the organisation:
   - its profile;
   - the workforce types the scenario uses;
   - the employee-ID format.
2. Load the holiday calendar (the holiday import counts).
3. Make sure every imported employee has a department.
4. Assign roles on least privilege:
   - the HR lead is an **admin**;
   - people with reports are **managers**;
   - the payroll lead holds the **finance** grant on top of their base role;
   - everyone else is an **employee**.
5. Switch off any module the scenario says the customer does not want at
   launch.

### Task 2 — Import all six entity types · check **A2** · weight 20 · **must pass**

1. Import all six: **employees, holidays, leave balances, org chart, salary
   structures and assets**. Use Admin → Import data, one template per type.
2. **Import employees first.** Leave balances, salary structures, the org chart
   and asset assignment all refer to people by email.
3. Read every dry run. Fix the errors **in your file** and re-upload. Re-runs
   match rows by natural key, so they update rather than duplicate.
4. **No rejected row may be left unexplained.** This covers errors, skips
   (seat limit, a holiday date conflict, an org-chart loop) and warnings you
   chose to accept. For each one, the handover note gives:
   - the file and the row number;
   - what was wrong;
   - what you did about it.
5. Payroll history has no importer. If the scenario includes it, say how you
   would handle it. Do not try to force it in through another template.

### Task 3 — Payroll statutory configuration · check **A3** · weight 20 · **must pass**

1. In Payroll → Settings, set PF, ESI and Professional Tax. Start from the
   pre-filled India defaults, and give every change an effective date that
   covers the payroll month.
2. In the PT slab editor, **pick the preset for the scenario's state**. Check
   its bands against the state notification the scenario sheet quotes.
3. Choose the TDS mode (manual or auto) on Payroll → Income tax. Record each
   employee's regime as the scenario sheet gives it.
4. Assign every employee a salary structure. The salary-structures import
   counts.

### Task 4 — A payroll run to review · check **A4** · weight 20 · **must pass**

1. Create the run for the scenario's payroll month and **process** it so it
   reaches Review.
2. Statutory lines must be present on the items: PF, ESI where the employee is
   eligible, PT and TDS.
3. Read the anomaly flags and resolve or explain each one in the handover note.
   The flags cover:
   - a missing structure;
   - missing bank details;
   - a negative net;
   - a net-pay swing of more than 25%.
4. **Do not mark the run paid and do not lock it.**

### Task 5 — Leave policy · check **A5** · weight 10 · not must-pass

Set up the leave policy the scenario sheet asks for:

- the leave types it uses, including any custom type;
- accrual;
- the carry-forward cap.

The leave year is the calendar year, and the opening balances you imported must
fit that.

### Task 6 — Attendance policy and one approved fix · check **A6** · weight 10 · not must-pass

1. In Attendance → Settings, set:
   - the working days, the hours, the late grace and the full-day and half-day
     thresholds;
   - the sync switches, so approved leave and company holidays never score as
     absent.
2. Raise one attendance-fix (regularisation) request for a synthetic employee.
   A person must **approve** it: you as admin, or the employee's manager. Do not
   leave it pending.

### Task 7 — Statutory exports · check **A7** · weight 10 · not must-pass

1. **Approve** the run from Task 4. Exports are offered only on an approved
   run.
2. Generate:
   - the EPFO ECR file;
   - the ESIC return;
   - the Form 24Q annexure working data for the quarter.
3. These are filing aids. Do not file anything on any government portal.

### Task 8 — Handover note · read by the checker, not a weighted check

Submit a short written handover to the customer's HR admin, covering:

- the roles and grants you assigned, and who holds finance;
- the import explanations from Task 2 and the anomaly notes from Task 4;
- the decisions you made that the scenario did not settle;
- the Slack and single sign-on state, read from Admin → Integrations. Install
  Slack only if the scenario provides a Slack workspace. Single sign-on is a
  deployment setting: report its state, do not try to change it;
- every login you created, so the customer can keep or remove each one.

## 5. How you pass

You pass the practical when:

- **every must-pass check (A2, A3 and A4) is met**; and
- **your weighted score is 80 or more out of 100.**

A must-pass check that cannot be measured counts as not yet passed, until a
person measures it by hand. You also need the secured theory exam at the cut
score to hold ASHR-L2.

## 6. The checks (for the checker and the check spec)

| Check | What is met | Weight | Must pass | Where it is read |
|---|---|---|---|---|
| A1 | Org profile set; holidays present; every employee has a department; roles assigned on least privilege, with finance held by the payroll lead | 10 | no | tenant modules, holidays, profiles and grants |
| A2 | All six importers committed; every rejected, skipped or warned row explained in the handover note | 20 | yes | the import ledger (`import_jobs`) per importer, plus the handover note |
| A3 | PF, ESI and PT set with an effective date covering the run month; the PT preset matches the scenario state; TDS mode set; regimes recorded | 20 | yes | payroll settings, including the PT state and slabs |
| A4 | One run for the scenario month **reached Review** with statutory lines present, and is **not paid and not locked** | 20 | yes | payroll run status and run items |
| A5 | Leave types, accrual and carry-forward cap as the scenario asks | 10 | no | leave types and leave balances |
| A6 | Attendance policy set; one regularisation approved by a person | 10 | no | attendance settings and regularisations |
| A7 | EPFO ECR, ESIC return and 24Q annexure generated from the approved run | 10 | no | export events |
| — | **Integrity:** synthetic data only (rule 3.1) | gate | voids the attempt | a human reads the sandbox |

Weights total 100.

## 7. Notes for the checker, and known gaps

- **Read A4 as "reached Review, not paid, not locked"** (status Review or
  Approved). Do not read it as "status is exactly Review". Task 7's exports
  need an approved run: the product refuses to export from a draft or review
  run. So a candidate who completes A7 has, correctly, moved the run past
  Review. A spec that demanded exactly Review would fail every candidate who
  finished Task 7.
- **The import ledger may be missing.** The `import_jobs` table (migration 167)
  is staged and not applied in every environment. The importers still work
  without it; they just leave no job row. If the ledger is absent, A2 is
  **unmeasured**. The checker then measures it by hand: are the records of all
  six types present, and does every missing row have an explanation in the
  handover note?
- **The 24Q export fails closed** if any month of the quarter has a run still in
  draft or review. Give the candidate a quarter with no other open runs.
- **The 10-user limit is real.** An `employees.csv` that invites everyone will
  hit the seat limit. That trap is part of A2, not a defect in the sandbox.
- **Must-pass fails always get a full human review.** So does any check that a
  grading model contributed to. The checker records the final result; nothing
  here sets a cut score, approves a partner or issues a credential.
