Payroll on infrastructure you own
Run pay and payroll records on hardware you own, wired to HR and finance, with staff personal data kept inside the company.

Payroll is the most sensitive data set most companies hold, and most companies hand it to someone else to process. Our payroll studio runs pay cycles and keeps every payroll record on hardware you own, inside your own network. Staff personal data stays in the company, the pay run posts straight to finance, and every action is logged.
It is one studio on the MICKAI sovereign operating system. Not a hosted service you log into, not a bureau you send a spreadsheet to. Studios that share your own data, on machines you control, with one assistant across all of them.
What a pay run touches
Run payroll and you have gathered, in one place, the things a person most wants kept private. Full name and home address. Bank account and sort code. National Insurance or tax number. Salary, bonus, deductions, pension, any attachment of earnings. For a firm of any size that is a concentrated file of exactly the data a regulator, a court and a criminal all care about.
The common arrangement is to send that file out. To a payroll bureau, a hosted payroll product, an outsourced provider. The data leaves the building every cycle so a third party can do the arithmetic and the filing. It sits on their systems, under their access controls, exposed to their staff and their subcontractors, subject to whatever jurisdiction their servers happen to be in.
Our payroll studio does the arithmetic and the filing where the data already lives. In your building.
On hardware you own
The studio runs on your own machines. The employee records, the pay history, the calculation, all of it stays on infrastructure you can point at. That is the plain control case. If the personal data of your staff never leaves your premises to run a pay cycle, the surface an attacker or a curious insider at a vendor can reach is smaller by design.
It is air-gapped by default. A pay run needs no connection to the outside world to compute gross to net, apply tax codes, run deductions and produce payslips. The studio does that offline. When the cycle is done and you need to file with the tax authority or issue payment instructions to the bank, you open one channel, for that task, and it is logged. Then it closes. The default state is disconnected, not connected.
That is the difference from a hosted payroll product. There the data is on someone else's server as a condition of the software working at all. Here the software works on your server, and the network is opened deliberately, briefly, and on the record.
Wired to HR and finance
Payroll errors mostly come from the gaps between systems. A starter is added in HR but not in payroll. A leaver is paid a cycle too long. A salary change lands in one place and is re-keyed wrong into another. A bonus approved in a spreadsheet never reaches the pay run.
On our operating system, HR, finance and payroll are studios reading the same records. A new starter entered once in HR is known to payroll. A leaver is a leaver everywhere at once. A pay rate change approved by a manager flows through without a second entry. There is no overnight file transfer between separate products and no re-key, because there are not separate products. There is one company data set and different studios working on it.
When a pay cycle completes, it posts to the finance ledger in the same place. The wage cost, the tax and pension liabilities, the net payments, all land in the accounts the moment the run is approved. Month end is shorter because the reconciliation was never broken in the first place.
Every action on the record
Payroll is where accusations get made. A payment went to the wrong account. A rate was changed without approval. A bonus appeared that no one signed off. In a tribunal or an internal investigation, the question is always the same: who did what, and when.
The studio writes every action to the Open Audit Record. Not a vague daily log, an action-level record. Who ran the pay cycle. Who changed a pay rate, from what to what. Who approved a payment run. Who exported a payslip. Each entry carries the person and the timestamp. When someone asks how a figure came to be, the answer is on the record rather than in memory.
This is the part that goes beyond keeping the data private. Private deployment, running software on your own kit, is the baseline. The value is what sits on top of it: a tamper-evident account of every action taken against the most sensitive data you hold, kept in your building, ready for whoever has the right to ask.
The jurisdiction case
Where your payroll data physically sits decides which laws reach it. Send it to a bureau or a hosted product and it may rest on servers in another country, under another government's power to compel, inside a supply chain you did not choose and cannot fully see.
Keep it on hardware you own and the answer to "where is our staff personal data" is a location you can walk to. For a firm handling UK employee data that is a cleaner data residency position and a shorter, more honest answer in a data protection assessment. You are not mapping a vendor's subprocessors across three continents. The data is here.
What owning it saves
Outsourced payroll is a recurring cost. Bureaux commonly charge a base fee plus a per-payslip or per-employee charge each cycle. Hosted payroll products charge per employee per month, often with tiers and add-ons for filing and pensions. Published pricing varies by provider and market, so use the method rather than a headline number: take the per-employee monthly figure a provider lists, multiply by your headcount, multiply by twelve, and that is the annual rent for the same job.
Worked plainly, a firm of 200 staff on a hosted payroll product listed at a given per-employee monthly rate multiplies that rate by 200, then by 12, to see the yearly figure. Add the bureau's per-payslip fees where a bureau also runs the cycle. That number recurs every year and rises with headcount and with each price change the provider chooses. Owning the studio ends the per-employee, per-payslip meter. You run pay on kit you already own and the data never leaves to be charged for.
We do not publish a MICKAI price here. The point is the shape of the saving: a rented, per-head, per-cycle cost against an owned capability that does not bill you by the payslip.
One assistant across it
The same assistant that works across the operating system works in payroll. Ask it to show every pay change made this quarter and who approved each one. Ask it to flag any employee paid after their leaving date. Ask it to reconcile this run against last month and explain the difference. It reads the payroll records, the HR records and the finance ledger because they are on one system, and it answers with the audit trail behind it. It runs on your hardware with the rest of the stack. It does not send your payroll out to answer a question.
Built, and yours to run
The payroll studio is one of 87 studios built on the operating system. HR, finance, the assistant, the audit record, the studios named here run on the same platform, on hardware you own. We hold 104 filed UK patent applications across 2,340 claims covering the architecture underneath.
Payroll is the clearest case for owning your stack rather than renting it. It is your most sensitive data, your legal exposure, your staff's trust. Run it in your building, on your machines, wired to the systems it depends on, with every action on the record. Not sent out. Kept in.
Frequently asked questions
Where does staff payroll data live?
On hardware you own, inside your company network. Names, addresses, bank details, National Insurance numbers and salaries stay in your building. Nothing is copied to an outside payroll bureau or a vendor cloud to run a pay cycle.
Can it work air-gapped?
Yes. The payroll studio runs air-gapped by default. It processes a pay run with no outbound connection. When you need to file with the tax authority or send bank payment instructions, you open a single, logged channel for that task and close it again.
How does it connect to HR and finance?
They are studios on the same operating system, reading the same records. A new starter in HR, a leaver, a salary change or a bonus flows into payroll without a re-key or an overnight sync. Each pay run posts to the finance ledger in the same place.
Does every change get recorded?
Yes. Every action, who ran the pay cycle, who changed a pay rate, who approved a payment, is written to the Open Audit Record at the action level. It is your evidence trail for an auditor, a tribunal or an internal review.
Do we still need a payroll bureau?
Many firms use one to move the data and carry the risk. Owning the studio removes that. You run pay in the building, keep the records, and file directly. The recurring bureau or per-payslip fee stops.
What about the tax authority filings?
The studio prepares the returns your jurisdiction requires and submits them through the one logged channel. The submission, the figures and the timestamp are held in your records, not on a third party's system.