Skip to content

Documentation

Roles and access

Three things decide what somebody can do: the role they hold, the departments that role is scoped to, and any capability granted to them by name. All three are checked in the database, not in the interface — a hidden button is a courtesy, and a refused write is the control.

The roles you start with

A company can rename these, change what each may do, and add roles of its own. What it cannot do is leave itself without an owner: the database refuses to remove or demote the last one.

Owner
Everything an HR admin can do, and the final approver above them.
HR administrator
The whole company: people, leave rules, settings and roles.
Department administrator
Their own departments: people, approvals and dashboards.
Team lead
Their direct reports: records and first-step approvals.
Employee
Themselves: their own record, leave and payslips.

Capabilities

A capability is one named thing somebody may do. Roles carry them, and HR can grant a single capability to a single person without moving them to a different role — which is how one bookkeeper sees pay without becoming an administrator.

Hiring

See hiringhiring.view
Read openings, the people who applied and where each of them got to. Reading, not running: this is what an interviewer needs.
Run hiringhiring.manage
Open a vacancy, move somebody through the stages, and decide. Includes seeing it.

Ask Staffena

Ask Staffenaassistant.use
Ask the assistant how something works. It answers from this product’s documentation, in the terms of whoever asked, and never about anybody’s data.

Payroll

See paypayroll.view
Read salaries and published payslips for other people.
Run payrollpayroll.manage
Open a run, edit its figures, and publish payslips. Implies seeing pay.
See advances and claimsmoney.view
Read what other people have asked the company for.
Decide advances and claimsmoney.manage
Approve or refuse a loan, an advance or an expense claim.

Leave

Leave administrationleave.admin
Book leave for somebody else, adjust an entitlement, and decide a request outside the usual chain.

Attendance

Correct attendanceattendance.manage
Add, edit and remove punches for anybody this person can see.

Work logs

Work log setupworklog.configure
Add activities and the fields they capture, for everybody.
Correct work logsworklog.manage
Change an entry somebody else wrote. The correction says who made it.

People

Documentsdocuments.manage
Hold visas, insurance and contracts for other people, and act on what expires.
Announcementsannouncement.publish
Address other people. Which audiences are offered still depends on scope.
Importsimport.run
Load people or pay from a sheet. Company-wide by nature.
Company assetsassets.manage
The register of what the company owns, and handing it out or taking it back.
Lettersletters.manage
Write the company's templates, and issue a letter on its paper.
Joining and leavingboarding.manage
The lists a company runs when somebody starts or goes, and each process.
Assign taskstasks.assign
Put something on somebody else's list, with a date it is wanted by.

Policies

Handbookhandbook.manage
Write policies, publish versions, and set the checks on them.

Wellbeing

Wellbeing boardwellbeing.moderate
Hide a post. Nobody, at any level, can see who wrote one.

Department scope

A department administrator holds their capabilities inside their own departments and nowhere else, and a team lead sees the people who report to them. Scope is applied to the rows themselves: a query for “everybody” returns the people that person may see, so a report, an export and a screen cannot disagree about it.

What nobody can do

  • Change their own role, department, manager, salary or entitlement.
  • Approve their own request, at any level.
  • Edit a decision once it is made — decisions are appended, never rewritten.
  • Read another company’s data, whatever their role: every row carries its company.
  • Trace an anonymous wellbeing post to a person: there is no author to trace.

When we look

Support staff at Staffena can enter a company to diagnose a problem. Entering is itself an audited act: it records who entered, when, and the reason they gave, and the company can read that record on its own audit screen. What we cannot do is sign in as one of your people, or set anybody’s password.