Doing your HRM dissertation inside the organisation you already work for is common and usually faster than finding an external site, but it carries a specific set of access, confidentiality and objectivity problems a generic methodology chapter does not cover. Six steps, from the first conversation with your manager to the data-ownership clause in your final write-up.
Step 1: Get written permission from someone with actual authority to grant it
A verbal go-ahead from a friendly line manager is not the same as organisational permission to conduct research involving other employees, and South African university ethics committees typically ask for a formal gatekeeper letter before granting approval. Identify who in the organisation actually has the authority to approve research involving staff — often HR, sometimes a specific research-and-development or transformation function, and in a smaller organisation possibly the owner or managing director directly — and get written confirmation, on a letterhead if possible, before you approach any potential participants. State plainly in your request what data you need, how participants will be recruited, and what the organisation gets to see (or not see) once the study is complete. This organisational permission sits alongside, not instead of, the general South African ethics-clearance process the site’s explainer on what ethics clearance involves covers; your university’s own research ethics committee still needs to see the gatekeeper letter as part of your application, not treat it as a substitute for the committee’s own approval.

Step 2: Name the insider-research bias risk explicitly, and say what you did about it
Being an employee-researcher inside your own organisation is a genuine methodological consideration, not something to minimise or leave unstated. Two risks recur in HRM insider research specifically: colleagues may answer differently because they know you personally or know your role (social-desirability bias, amplified by familiarity), and you yourself may unconsciously interpret findings in a way that protects the organisation, your department, or your own standing rather than reporting what the data actually shows. A defensible methodology chapter names both risks and states the specific step taken against each — for example, using an anonymous online survey tool rather than face-to-face collection to reduce the familiarity effect, and having a supervisor or an independent coder check a sample of your qualitative coding for consistency with your own. Naming the risk and the mitigation is stronger than pretending insider status is not a factor at all.
Step 3: Manage the power-distance problem if you outrank (or are outranked by) your participants
If you hold a management role over some or all of your potential participants, direct recruitment by you personally can feel coercive even where no explicit pressure is applied — an employee may agree to participate, or answer in a particular way, because you are their manager, not because they freely chose to. Where this applies, route recruitment through HR or a neutral third party rather than approaching subordinates directly, make clear in the consent process that participation (and how they answer) has no bearing on performance evaluation, and consider whether a self-administered anonymous instrument is more appropriate than a face-to-face interview you would personally conduct. The reverse problem — researching your own superiors or senior management — carries a different risk: participants may give a more guarded or socially desirable answer knowing a subordinate is asking, which is worth naming as a limitation rather than assuming it away.

Step 4: Handle colleague confidentiality and POPIA obligations together
Colleagues’ survey responses, interview transcripts and demographic data are personal information under the Protection of Personal Information Act (POPIA): section 1 defines personal information as information relating to an identifiable, living natural person, and its list expressly includes employment history and the personal opinions, views or preferences of the person. That is the same POPIA layer South African research ethics guidance already applies to other fields’ informed-consent processes, and it applies here with an added complication: in a small department, an “anonymised” quote can still be identifiable to colleagues who know the team, even with a name removed. Beyond standard anonymisation (no names, no directly identifying details), consider aggregating or lightly disguising role-specific details in any quoted material where the team is small enough that a specific quote could be attributed, and state in your consent process exactly who will and will not see individual (as opposed to aggregated) responses — explicitly excluding your own manager or HR from seeing raw individual data unless a participant has separately agreed to that.
Step 5: Settle data ownership and organisational sign-off before you submit, not after
A common late-stage problem in insider HRM research is discovering, at submission, that the organisation expects to review or approve findings before they can be included in a publicly accessible dissertation — particularly where findings are less flattering than a sponsor hoped. Settle this at the permission stage, in writing: whether the organisation gets to review a draft, whether any findings are commercially sensitive and need to be generalised or anonymised at the organisation level (not just the individual level) in the final document, and what happens if the organisation objects to a finding once it exists. University ethics committees generally expect the dissertation itself to remain the student’s own academic work, not subject to an employer’s editorial veto, but the practical relationship with an organisation you still work for after submission is worth managing proactively rather than discovering the hard way.
Step 6: Write the access and confidentiality section so an examiner can see all of this was handled
An examiner reading an insider-research HRM dissertation checks specifically for whether the student has addressed their dual role, not just conducted the study. A strong methodology section states: who granted organisational access and in what form (the gatekeeper letter from Step 1); the specific insider-bias risks named and the mitigation taken (Step 2); how power-distance concerns were managed if relevant (Step 3); the confidentiality and POPIA-consistent handling of colleague data, including the small-team identifiability risk (Step 4); and the data-ownership and organisational sign-off arrangement (Step 5). Together these five elements are what turns “I did my research at my own company” into a defensible, examinable methodological choice rather than an unaddressed limitation.
A worked example of an access-and-confidentiality paragraph
Illustrative example, not a real study. “Written permission to conduct the study was obtained from the Human Resources Director before recruitment began, and the letter confirmed the researcher’s dual role as an employee and as the study’s principal investigator to the ethics committee. Given the researcher’s supervisory role over four of the twelve potential participants in the payroll department, recruitment for those four was conducted by an HR representative rather than the researcher directly, and all four were informed in writing that non-participation would not affect their performance review. Survey responses were collected via an anonymous online tool with no IP-address logging; qualitative interview transcripts were anonymised by role category rather than named position, given the department’s small size. The organisation agreed in writing to receive only the aggregated final report, not individual response data, and waived any right to pre-approve findings before submission.” Every specific detail is illustrative; the structure — permission, bias mitigation, power-distance handling, confidentiality method, and the ownership agreement — is what belongs in any HRM insider-research methodology section.
What if my whole research question is specifically about my own department?
A dissertation genuinely about a phenomenon in your own department — the effect of a recent restructuring on morale, the uptake of a new performance-management system — is a legitimate and often richer design than an arbitrarily chosen external site, precisely because you have contextual knowledge an outside researcher would need months to build. The trade-off is that every mitigation above becomes more, not less, important: your familiarity with the context is a genuine analytical asset in your literature review and discussion, but it is also exactly the condition under which participants are most likely to tailor answers to what they think you already know or want to hear, and where you are most at risk of interpreting ambiguous data in the direction your own prior involvement in the department already leans. State this dual position explicitly in a short positionality paragraph in your methodology chapter — what your role in the department is, what you already believed about the topic going in, and how the design tries to guard against that prior belief shaping the findings — rather than writing as though you approached the department as a neutral outsider.
How does this differ from the site’s existing HRM content?
The site’s guides to validated scales for an HRM dissertation and choosing an analysis method for an HRM dissertation cover instrument selection and statistical analysis once your data exists; this piece is the first on the site to work through the access and confidentiality problem specifically created by researching your own employer, which comes before either of those decisions and shapes how the resulting data can be collected and reported.
Turning a workable access plan into a full methodology section
Drafting a consent process, a gatekeeper letter and a confidentiality plan that hold together consistently across your whole methodology chapter is exactly the kind of structured writing Tesify helps with, while every decision about your own organisation and your own data stays yours to make and the dissertation stays 100% written by you. Draft your access and methodology section with Tesify.
Frequently asked questions
Do I still need university ethics approval if I already have my employer’s permission?
Yes — your employer’s permission and your university’s ethics committee approval are separate requirements, and South African faculties typically will not allow data collection to begin until both are in place.
Can I research my own direct team without it being coercive?
It is possible, but it requires specific safeguards — routing recruitment through a neutral party, using anonymous self-administered instruments, and being explicit that participation has no bearing on evaluation — rather than assuming a good relationship with your team removes the power-distance concern.
What if HR wants to see individual employee responses, not just the aggregated report?
This should be settled and refused (or explicitly consented to by each individual participant) before data collection begins, not negotiated after the fact; ethics committees generally expect individual response confidentiality from the organisation itself, not only from other employees.
Is insider research considered a weaker design than an external organisation study?
No — it is a well-established design with its own literature and its own standard mitigations. What weakens it is failing to name the insider-bias risk and the steps taken against it, not the choice of an insider site itself.
How do I anonymise a quote in a small department without making it identifiable?
Aggregate or generalise role-specific identifying details (seniority, tenure, a distinctive responsibility) rather than relying on name removal alone, and consider whether a quote is safe to include at all if its content alone would identify the speaker to colleagues.
What happens if the organisation objects to a finding after I have already collected the data?
This is exactly why the data-ownership and sign-off arrangement in Step 5 needs to be settled in writing before data collection, not negotiated afterward; refer back to that written agreement if a dispute arises.
Can I use my own performance data or HR records as part of the study?
Only with the same consent and POPIA-consistent handling as any other participant’s data, and check with your ethics committee whether using your own records introduces an additional conflict-of-interest consideration specific to your dual role.
