Roles and access
Three things decide what somebody can do: the role they hold, the departments that role is scoped to, and any capability granted to them by name. All three are checked in the database, not in the interface — a hidden button is a courtesy, and a refused write is the control.
The roles you start with
A company can rename these, change what each may do, and add roles of its own. What it cannot do is leave itself without an owner: the database refuses to remove or demote the last one.
- Owner
- Everything an HR admin can do, and the final approver above them.
- HR administrator
- The whole company: people, leave rules, settings and roles.
- Department administrator
- Their own departments: people, approvals and dashboards.
- Team lead
- Their direct reports: records and first-step approvals.
- Employee
- Themselves: their own record, leave and payslips.
Capabilities
A capability is one named thing somebody may do. Roles carry them, and HR can grant a single capability to a single person without moving them to a different role — which is how one bookkeeper sees pay without becoming an administrator.
Hiring
- See hiring
hiring.view - Read openings, the people who applied and where each of them got to. Reading, not running: this is what an interviewer needs.
- Run hiring
hiring.manage - Open a vacancy, move somebody through the stages, and decide. Includes seeing it.
Ask Staffena
- Ask Staffena
assistant.use - Ask the assistant how something works. It answers from this product’s documentation, in the terms of whoever asked, and never about anybody’s data.
Payroll
- See pay
payroll.view - Read salaries and published payslips for other people.
- Run payroll
payroll.manage - Open a run, edit its figures, and publish payslips. Implies seeing pay.
- See advances and claims
money.view - Read what other people have asked the company for.
- Decide advances and claims
money.manage - Approve or refuse a loan, an advance or an expense claim.
Leave
- Leave administration
leave.admin - Book leave for somebody else, adjust an entitlement, and decide a request outside the usual chain.
Attendance
- Correct attendance
attendance.manage - Add, edit and remove punches for anybody this person can see.
Work logs
- Work log setup
worklog.configure - Add activities and the fields they capture, for everybody.
- Correct work logs
worklog.manage - Change an entry somebody else wrote. The correction says who made it.
People
- Documents
documents.manage - Hold visas, insurance and contracts for other people, and act on what expires.
- Announcements
announcement.publish - Address other people. Which audiences are offered still depends on scope.
- Imports
import.run - Load people or pay from a sheet. Company-wide by nature.
- Company assets
assets.manage - The register of what the company owns, and handing it out or taking it back.
- Letters
letters.manage - Write the company's templates, and issue a letter on its paper.
- Joining and leaving
boarding.manage - The lists a company runs when somebody starts or goes, and each process.
- Assign tasks
tasks.assign - Put something on somebody else's list, with a date it is wanted by.
Policies
- Handbook
handbook.manage - Write policies, publish versions, and set the checks on them.
Wellbeing
- Wellbeing board
wellbeing.moderate - Hide a post. Nobody, at any level, can see who wrote one.
Department scope
A department administrator holds their capabilities inside their own departments and nowhere else, and a team lead sees the people who report to them. Scope is applied to the rows themselves: a query for “everybody” returns the people that person may see, so a report, an export and a screen cannot disagree about it.
What nobody can do
- Change their own role, department, manager, salary or entitlement.
- Approve their own request, at any level.
- Edit a decision once it is made — decisions are appended, never rewritten.
- Read another company’s data, whatever their role: every row carries its company.
- Trace an anonymous wellbeing post to a person: there is no author to trace.
When we look
Support staff at Staffena can enter a company to diagnose a problem. Entering is itself an audited act: it records who entered, when, and the reason they gave, and the company can read that record on its own audit screen. What we cannot do is sign in as one of your people, or set anybody’s password.

