Skip to main content

Roles & Permissions

Administration → Roles & Permissions — decide exactly what each role can do in the Employee module. Requires employee:admin.

Role Permissions pageRole Permissions page
Role Permissions — editing the EMPLOYEE role

The permission matrix

  1. Pick a role with the Change selector (e.g. EMPLOYEE, MANAGER, HR, ADMIN — roles come from your identity provider).
  2. Toggle individual permissions on or off. Permissions are grouped (Employee Records, Leave & Attendance, Attendance Management, Workflow Setup, …) with a coverage bar per group; each carries a READ or MANAGE scope badge.
  3. Use the All / Granted / Restricted filter or search to find a permission.
  4. Click Save Permissions. Changes apply on the users' next page load.

Reset discards unsaved edits; Clear all removes every grant from the role (before saving).

Guidelines

  • Follow least privilege: grant *:read before *:manage, and treat employee:pii:* and employee:admin as sensitive.
  • The full permission list and what each unlocks is summarized in the Administrator Overview.
  • Permission changes are recorded in the Audit Logs.