Appearance
User Roles & Access
The system is designed to make sure each person sees and does only what's appropriate for their job. A payroll officer can manage salaries; a regular employee can view their own payslip but not anyone else's. This protects sensitive information, supports privacy and compliance, and keeps the system simple for each user.
This page explains how access works in plain terms — no technical knowledge required.
The Big Idea: Roles
Access is organized around roles — bundles of access that match a job. Instead of setting permissions one person at a time, an administrator gives someone a role, and that role carries the right access with it.
Common examples:
| Role | Typical access |
|---|---|
| HR Administrator | Broad access to manage people, pay, and settings across the organization. |
| Manager / Department Head | Access to their own team's records, requests, and approvals. |
| Recruiter | The hiring pipeline — job posts, candidates, and interviews. |
| Payroll Officer | Salary structures, payslips, and pay-related data. |
| Employee | Their own information and self-service tasks. |
Roles can be created and adjusted to match how each organization is structured.
What "Access" Means
For each area of the system, access is about what a person can do:
- View — see information.
- Create — add new records (e.g. a new candidate).
- Edit — change existing records.
- Remove — delete records.
A role can include any mix of these across different areas. For example, a recruiter might create and edit candidates but have no access to payroll at all.
Managers Get Team Access Automatically
The system understands your reporting structure. When someone is set as another employee's manager, they automatically gain the access they need to support their team — for example, reviewing their team members' records or approving their leave — without an administrator having to grant it manually.
Worth knowing
Because this access follows the reporting structure, changing who reports to whom also changes what managers can see. It's good practice to review reporting lines when people change jobs.
There are also specialized manager roles for specific areas — such as the manager of a particular recruitment drive, or a designated leave approver — who get access scoped to just that responsibility.
Each Company's Data Stays Separate
The system can run multiple companies in one system. Information is kept separate by company: people generally see only the data for the company they belong to. A user with access to more than one company can switch between them, seeing one company's data at a time.
This separation is especially important when serving multiple clients / branches from a single system — each client's information stays private to them.
Self-Service for Employees
Every employee has a personal, secure view of their own information. Without needing special permissions, they can typically:
- Request time off and check their balances.
- View their payslips.
- Update personal details.
- Raise support requests through the helpdesk.
This reduces routine work for HR while giving employees control over their own information.
How Access Is Managed
An administrator manages access from within the system's settings, using simple on-screen tools — no technical work involved. From there they can:
- Create roles and choose what each role can access.
- Assign people to roles.
- Grant an individual a specific extra capability when needed.
- Set who reports to whom (which drives manager access).
Changes take effect immediately.
Good Practices
- Give the least access needed. Start narrow; add more only when required.
- Use roles, not one-off permissions. Roles keep access consistent and easy to review.
- Review access when people change jobs. Update roles and reporting lines so access always matches responsibilities.
- Limit top-level administrators. A small number of trusted people should hold full system access.
Right access, right people — by design.

