Organisation, Roles, and Permissions
Use Organisation to create reusable departments and work locations before assigning employees. Department and location codes should be stable and meaningful because they support fi...
Use Organisation to create reusable departments and work locations before assigning employees. Department and location codes should be stable and meaningful because they support filtering, reporting, and Payroll alignment.
HR access is granular. Separate permissions control the dashboard, employee records, sensitive employee data, contracts, documents, leave administration, leave approval, workflows, reports, exports, settings, and portal administration. Give users only the access required for their duties. Sensitive access covers protected personal details and must be restricted carefully.
Workspace access and functional permissions are separate. module.hr.access opens the HR workspace, but it does not by itself allow an employee, document, leave request, or report action. Assign the workspace permission together with only the capabilities the role needs:
| Permission | Access granted |
|---|---|
module.hr.access |
Open the HR workspace and its manual |
hr.dashboard.view |
View permission-filtered HR dashboard information |
hr.employees.view |
View employee records and Organisation |
hr.employees.create |
Create employee records |
hr.employees.edit |
Edit employee profiles and review Payroll readiness |
hr.employees.archive |
Archive employee profiles |
hr.employees.sensitive |
View and handle protected employee information |
hr.contracts.view / hr.contracts.manage |
View or create and issue employment contracts |
hr.documents.view / hr.documents.manage |
View or manage private employee documents |
hr.leave.view / hr.leave.manage |
View leave or create and manage requests |
hr.leave.approve |
Approve or reject leave independently |
hr.workflows.view / hr.workflows.manage |
View or manage onboarding and offboarding |
hr.reports.view / hr.reports.export |
View HR reports or export controlled datasets |
hr.portal.manage |
Invite, revoke, and administer employee portal access |
hr.settings.manage |
Configure HR, retention controls, and working calendars |
A cross-module permission does not automatically expose that module. For example, an HR role with an embedded Payroll-related capability still needs module.payroll.access before a Payroll workspace shortcut or screen becomes available.
The user manual itself is available to authorized business users whenever HR is enabled. Its screen shortcuts are permission-aware and do not bypass route authorization.