Permissions
Purpose
The Permissions screen allows administrators to control access to features within the Thulo Attendance & Leave Management module. Permissions can be assigned either to an entire employee role or to specific employees, ensuring that users only have access to the functions and data required for their responsibilities.
By configuring permissions, organizations can maintain data security, enforce access controls, and support delegated management responsibilities.
Administrators have unrestricted access to all Attendance & Leave Management features and can create, modify, or remove permissions for roles and employees.
Create
To create a new permission set:
Step 1: Open Permissions
-
Navigate to Timesheets & Leave from the left sidebar.
-
Click Settings.
-
Select Permissions.
Step 2: Add a New Permission
-
Click the Add button.
-
The Permissions form will open.
Step 3: Configure Permission Settings
-
Select a Role if the permission should apply to all employees assigned to that role.
-
Select a Staff Name if the permission should apply only to a specific employee.
-
Enable the required permissions based on the employee's responsibilities.
Step 4: Save
-
Click Save to create the permission configuration.
View
Users can access Attendance & Leave Management features only when the corresponding permissions have been granted.
The level of access depends on the assigned permissions and whether organization-wide (Global) permissions have been enabled.
Edit
To modify an existing permission set:
-
Navigate to Timesheets & Leave → Settings → Permissions.
-
Locate the permission record you want to update.
-
Click Edit.
-
Update the required permissions.
-
Click Save to apply the changes.
Delete
To remove a permission set:
-
Navigate to Timesheets & Leave → Settings → Permissions.
-
Locate the permission record.
-
Click Delete.
-
Confirm the deletion when prompted.
Once deleted, users associated with that permission set will immediately lose the corresponding access rights.
Field Descriptions
| Field | Description |
|---|---|
| Role | Assigns the permission set to all employees belonging to the selected role. |
| Staff Name | Assigns the permission set to a specific employee. |
| Timesheet - Attendance - View | Allows users to check in, check out, view their own attendance records, and export their attendance data. When the HR Record module is enabled, managers can also view attendance records of employees they manage. |
| Timesheet - Attendance - View (Global) | Allows users to view attendance records for all employees in the organization. |
| Timesheet - Leave - View | Allows users to create and delete their own leave requests. When the HR Record module is enabled, managers can also view and delete leave requests submitted by employees they manage. |
| Timesheet - Leave - View (Global) | Allows users to view, create, and delete leave requests for all employees. |
| Work Routes - View | Allows users to create work routes for themselves and, when the HR Record module is enabled, for employees they manage. |
| Work Routes - View (Global) | Allows users to create work routes for all employees. |
| Timesheet - Additional Work Hours - View | Allows users to create their own additional work hour records. When the HR Record module is enabled, managers can view and delete additional work hour records for employees they manage. |
| Timesheet - Additional Work Hours - View (Global) | Allows users to view and delete additional work hour records for all employees while still creating their own records. |
| Timesheet - Additional Work Hours for Specific Employee - Create | Allows users to create additional work hour records for any employee in the system. |
| Timesheet - Work Shift Table - View | Allows users to view shift categories and shifts. Users cannot create, edit, or delete shifts. They can view their own work shift schedules and those of employees they manage when the HR Record module is enabled. |
| Timesheet - Work Shift Table - View (Global) | Allows users to create, edit, delete, and manage shift categories and shifts for all employees. |
| Timesheet - Report - View | Allows users to view their own attendance and leave reports. When the HR Record module is enabled, managers can also view reports for employees they manage. |
| Timesheet - Report - View (Global) | Allows users to access reports for all employees. |
| Timesheet - Workplace Management - View | Allows users to view workplace records and workplaces assigned to them. Users cannot create, edit, or delete workplace records. When the HR Record module is enabled, managers can view workplace assignments for employees they manage. |
| Timesheet - Workplace Management - View (Global) | Allows users to create, edit, delete, and assign workplaces for all employees. |
Workflow Rules
Permission Assignment Rules
-
Permissions may be assigned to either a role or an individual employee.
-
Role-based permissions apply to all employees assigned to that role.
-
Employee-based permissions override role-based access when configured separately.
-
Administrators have unrestricted access to all Attendance & Leave Management functions.
Manager Access Rules
When the HR Record module is enabled:
-
Managers can access records of employees assigned under their supervision.
-
Manager visibility depends on the specific permission granted.
-
Managed employee access may include attendance records, leave requests, reports, work routes, workplace assignments, and additional work hour records.
Global Permission Rules
-
Permissions marked as Global provide organization-wide access.
-
Global permissions allow users to view or manage records belonging to all employees.
-
Users with Global permissions are not restricted to their own records or subordinate employees.
Attendance Access Rules
-
Attendance View permission allows access to personal attendance information.
-
Attendance View (Global) provides access to attendance information for all employees.
Leave Access Rules
-
Leave View permission allows users to manage their own leave requests.
-
Leave View (Global) provides organization-wide leave management capabilities.
Shift Management Rules
-
Standard View permissions allow read-only access.
-
Global Shift permissions grant full shift administration rights, including creating, editing, and deleting shifts and shift categories.
Workplace Management Rules
-
Standard View permissions allow workplace visibility only.
-
Global Workplace permissions grant full workplace administration capabilities.
Additional Work Hours Rules
-
Standard permissions allow users to submit their own additional work hour records.
-
Additional permissions may grant authority to manage records for other employees.
Synchronization
Permission settings are synchronized with:
-
Employee Management
-
HR Record Module
-
Attendance Management
-
Leave Management
-
Shift Scheduling
-
Workplace Management
-
Additional Work Hours Management
-
Attendance Reports
-
Leave Reports
Changes to permissions take effect immediately across all connected Attendance & Leave Management features.
Important Notes
-
Only administrators should be granted full Global permissions.
-
Permissions control both data visibility and operational actions within the system.
-
Access to subordinate employee records depends on the HR Record module being activated and properly configured.
-
Users without the required permissions cannot access restricted menus, records, or actions.
-
Deleting a permission record immediately revokes the associated access rights.
-
Granting Global permissions should be carefully reviewed to maintain data security and privacy.
-
Permission configurations should align with organizational roles and internal approval policies.