Modules

Admin

Ask AI about this page

Admin is where owners and administrators set up the organisation: its structure of units and teams, its members, the roles they hold and the permissions that decide which pages and modules each person can use. It also holds devices, usage, access reviews and the audit records. Admin sits in the General group at the bottom of the sidebar, above Settings and Help, and appears only if you may open at least one of its pages.

Who uses it

RoleWhat they do in Admin
OwnerEverything an administrator does, and manages administrators.
AdministratorCreates units and teams, invites members, assigns roles and permission sets, sets manager scopes, runs access reviews, reads audit records.
ManagerUsually nothing here. A manager’s reach comes from a role and a scope that an administrator gives them. Some managers review access items assigned to them.
HRMaintains people and units when their role allows it; HR settings are under Settings.
AuditorIf your organisation creates such a role, reads audit records and reports without changing anything.
EmployeeDoes not see Admin, except pages a permission explicitly opens for them.

Main screens

Admin pages are tabs at the top of the page. Pages that do not fit are under More.

ScreenWhat it shows
Organisation adminCounters for units, active members (and how many have no unit), active delegations and open access reviews; a People per unit chart; a Waiting panel with joiners and leavers awaiting approval, review items assigned to you and external access ending within 14 days; links to every admin page.
Tracking settingsThe recording policy: schedule, screenshots, idle, retention and category rules. See Settings.
UsersMembers with their role and joining date, pending invitations and Invite Members.
RolesThe roles in order, with level, members and description, and Create Role.
DevicesEnrolled desktop apps with their employee, version, enrolment date, last seen, status and the Revoke action.
UsageUsage per meter, day by day, with monthly budgets and Download CSV.
Roles & permissions (More)Permission sets, assignments, field policies, Explain access, the registry and changes waiting for a second administrator.
Sign-in, Group mappings (More)Sign-in providers, connected directories and which directory group gives which role or unit.
External access, Access reviews, Audit records (More)Contractors, access review campaigns and the log of privilege and configuration changes.
Organisation admin page with counters for units, active members, active delegations and open access reviews, a people-per-unit chart and a Waiting panel
Admin → Organisation admin: units, members, delegations and open reviews at a glance.

The structure itself is edited in the People section: Units shows the tree of units and Org chart the reporting lines on any date.

Organisation structure page with a date picker and a units tree of a company, its departments and teams
People → Units: the organisation as a tree of units, on today’s date or any other date.

Key tasks

Build the organisation structure

A unit has a kind: company, region, branch, division, department or team. Teams are units too, placed under their department.

Open the units

Choose People → Units, or select Create unit on Organisation admin.

Create the unit

Select Create unit. Enter the name, choose the kind and the parent unit.

Set the effective date

Enter the Effective date and a reason, then select Create unit. The unit takes effect from the start of that day in the organisation’s time zone.

Check the result

Pick a date and select Show to see the structure on that day. Moving a person to another unit is recorded as a transfer, so their history stays correct.

Invite members

Open Users

Choose Admin → Users.

Invite

Select Invite Members, enter the email address and choose a role. Member is preselected.

Send the invitation

Select Send Invite. The invitation stays pending until the person accepts it with the same email address. There is no open sign-up.

Users page with the Members list showing member, role and joined date, and the Invite Members button
Admin → Users: members, their roles and the button to invite more.

Create a manager role and give it a scope

Owner, Admin and Member are built in. A manager is not a fourth built-in role: you create it, then limit it to the people it may manage.

Create the role

Choose Admin → Roles and select Create Role. Give it a name and a description. Custom roles take their place in the role order between the built-in ones.

Give it permissions

On Roles & permissions, create or choose a permission set (for example one that approves leave or reviews tasks) and assign it to the role.

Set the scope

On the workforce page (Settings → Workforce & recording), give the manager a scope: which unit or team they may review, and for which dates. Reviewing another person needs both the permission and a valid scope.

Assign the role

On Admin → Users, give the role to the person.

Roles page listing the default Owner, Admin and Member roles and custom roles with their level, members and description
Admin → Roles: role order, members and the Create Role button.

Decide who can use which module

Each module (time, projects, people, customers, finance and so on) publishes the areas and actions it offers. A person can use a module page only when an action of that page is granted to them.

Open Roles & permissions

Choose Admin → More → Roles & permissions. The Registry lists every area and action the modules publish.

Build a permission set

Select New permission set and choose the actions it bundles. Only listed actions can be chosen.

Assign it

Under Assignments, give the set to a person, a role, a directory group or a service account, optionally for a limited period. Sets with administrative rights wait in Waiting for approval for a second administrator.

Check the result

Explain access shows, for one person, every permission they hold and where it comes from.

Roles and permissions page with the sections Waiting for approval, Permission sets, Assignments, Field policies, Explain access and Registry
Roles & permissions: permission sets, who holds them, field policies and changes waiting for a second administrator.
How a person gets access to a module page

Run an access review

Create the campaign

On Access reviews, select New campaign, choose what to review (a unit, a role, everyone with administrative rights, contractors or service accounts), set the due date and select Create draft.

Open it

Select Open campaign. The access in scope is recorded and handed to reviewers, who find it under My work → My access reviews.

Download the results

When the campaign closes, download the results as CSV or Excel. See Organisation and access.

Permissions

  • Owners and administrators cover the whole organisation. An owner can administer administrators; nobody can use Admin to give themselves a role they do not already hold.
  • Changes involving administrative rights, and loosening a field policy, wait for a second administrator. The person who asked cannot approve their own request. Removing a set or retiring one takes effect at once.
  • Managers act only within their scope. A role alone does not decide which people a manager sees; the scope does.
  • Sidebar: each section and page appears only if you may open it. Hiding is a convenience, not the protection: every page checks your access again and says so if you are refused.
  • Support sessions can read Admin pages but cannot create, change, approve or delete anything. A support session does not inherit an administrator’s access.

What the AI can do here

Admin pages have no AI that changes access. You can still ask the assistant (Ask AI) questions about records you are allowed to see, and administrators decide who may use AI at all, with seats, monthly limits per person and an emergency stop, under Settings › AI › Access & usage. AI token use appears on Admin → Usage. See AI access and tokens and What assistance can see.

FAQ

On this page