Skip to documentation content
Schoolixa Documentation
Campus Operations

Staff, Payroll & RBAC

Manage employees, departments, designations, roles, permissions, staff login, self-service, attendance, leave, timetable, and payroll.

Audience
School admins, HR staff, payroll users, and staff members
Last reviewed
September 2, 2026

Overview

Manage employees, departments, designations, roles, permissions, staff login, self-service, attendance, leave, timetable, and payroll.

Before you start

  • Staff permissions assigned
  • Employee records created
  • Roles and permissions planned before enabling login access

Main screens

Employees Departments Designations Roles Permissions Staff Login Access My Account Self Service Payroll Leave

Step-by-step workflows

1

Enable staff login

  1. Create or verify the employee record.
  2. Assign a role with required permissions.
  3. Open Staff Login Access.
  4. Enable login and issue temporary access details through the approved workflow.
  5. Staff must change the temporary password on first login.
2

Use staff self-service

  1. Staff logs in from the staff login page.
  2. Complete forced password change if required.
  3. Open My Account.
  4. Use attendance, leave, timetable, and payroll self-service cards according to permissions.
3

Run payroll

  1. Configure payroll settings.
  2. Generate payroll for eligible staff.
  3. Review salary slip.
  4. Update status or print/export only through permitted payroll actions.

Operational detail

Permission requirements

  • Employee records, staff login access, roles, permissions, self-service pages, leave, timetable, attendance, and payroll are separately controlled.
  • Staff authentication uses staff login routes while preserving the existing school/admin login behavior.
  • Global student search and module shortcuts must be hidden from staff unless the assigned role permits them.

Employee master record

Keep employee code, contact details, department, designation, staff type, and employment status accurate.

Login access

Enable staff login only after the employee record is ready and the role has been reviewed.

Role permissions

Grant the smallest set of permissions needed for the staff member job function.

First login password

Temporary passwords must be changed by the staff member before normal self-service use.

Self-service

Staff can use attendance, leave, timetable, payroll, and account pages only where the role allows access.

Payroll

Payroll generation, salary slip review, and status updates should follow the payroll lifecycle and approval expectations.

Validation and system feedback
  • Staff login access must reference an active employee from the authenticated school.
  • Email and contact values should not be duplicated unnecessarily when the employee master already stores them.
  • Password rules are enforced during first-login change and later password updates.
  • Permission checks run server-side even when sidebar entries are hidden.
Common mistakes to avoid
  • Giving a broad admin-like role to ordinary staff.
  • Leaving temporary passwords unchanged.
  • Expecting staff to see global search without student access permission.
  • Changing payroll state outside the payroll workflow.

Safe use

Keep documentation and support privacy-safe

These guides explain normal user workflows only. Do not share passwords, OTPs, tokens, cookies, private student identifiers, payment details, raw internal IDs, provider configuration, or stack traces in support messages or screenshots.

  • Giving a broad admin-like role to ordinary staff.
  • Leaving temporary passwords unchanged.
  • Expecting staff to see global search without student access permission.
  • Changing payroll state outside the payroll workflow.