Staff, Payroll & RBAC
Manage employees, departments, designations, roles, permissions, staff login, self-service, attendance, leave, timetable, and payroll.
Overview
Manage employees, departments, designations, roles, permissions, staff login, self-service, attendance, leave, timetable, and payroll.
Before you start
- Staff permissions assigned
- Employee records created
- Roles and permissions planned before enabling login access
Main screens
Step-by-step workflows
Enable staff login
- Create or verify the employee record.
- Assign a role with required permissions.
- Open Staff Login Access.
- Enable login and issue temporary access details through the approved workflow.
- Staff must change the temporary password on first login.
Use staff self-service
- Staff logs in from the staff login page.
- Complete forced password change if required.
- Open My Account.
- Use attendance, leave, timetable, and payroll self-service cards according to permissions.
Run payroll
- Configure payroll settings.
- Generate payroll for eligible staff.
- Review salary slip.
- Update status or print/export only through permitted payroll actions.
Operational detail
Employee master record
Keep employee code, contact details, department, designation, staff type, and employment status accurate.
Login access
Enable staff login only after the employee record is ready and the role has been reviewed.
Role permissions
Grant the smallest set of permissions needed for the staff member job function.
First login password
Temporary passwords must be changed by the staff member before normal self-service use.
Self-service
Staff can use attendance, leave, timetable, payroll, and account pages only where the role allows access.
Payroll
Payroll generation, salary slip review, and status updates should follow the payroll lifecycle and approval expectations.
- Staff login access must reference an active employee from the authenticated school.
- Email and contact values should not be duplicated unnecessarily when the employee master already stores them.
- Password rules are enforced during first-login change and later password updates.
- Permission checks run server-side even when sidebar entries are hidden.
- Giving a broad admin-like role to ordinary staff.
- Leaving temporary passwords unchanged.
- Expecting staff to see global search without student access permission.
- Changing payroll state outside the payroll workflow.
Safe use
These guides explain normal user workflows only. Do not share passwords, OTPs, tokens, cookies, private student identifiers, payment details, raw internal IDs, provider configuration, or stack traces in support messages or screenshots.
- Giving a broad admin-like role to ordinary staff.
- Leaving temporary passwords unchanged.
- Expecting staff to see global search without student access permission.
- Changing payroll state outside the payroll workflow.