People

Employee Portal

What an employee on the Staff role can reach — their own record, their own payslips, their own requests, and nothing else.

Employees sign in to the same application as everyone else. The Staff role turns it into a self-service view of their own record. There is no separate portal and no second login.

The Staff dashboard — one card per granted feature, and nothing that belongs to anyone else.

What they see

The sidebar collapses to their own dashboard. Every feature you have granted them appears as a card on it, rather than as extra navigation.

Granted featureWhat the employee gets
PayrollPayslips — their own, from approved pay runs only. See My payslips.
Requisitions (Spend)Their own requests, and the ability to raise new ones.
PersonnelTheir own employee record.
(always)My details — propose changes to their contact, emergency and bank details.

The word Payslips is used throughout for employees. They never see "Payroll", "Pay schedule" or "Pay run".

What they can do

ActionNotes
View their own payslipsApproved runs only. Never Draft.
Download a payslipThe same PDF a manager would download for them.
View their own payment historyWhat they have been paid, and when.
View their own recordPersonal, employment, banking and emergency contact details.
Propose changes to their detailsThrough My details. HR confirms before anything lands.
Raise Spend requestsPayment requests and advances, where the feature is granted.
Track their own requestsProgress shown as a stage, not a list of approvers.

What they cannot do

🚨Reporting is never available to Staff

No Trial Balance, no P&L, no Balance Sheet, no General Ledger, no Cash Flow, no account statements, no analytics — under any condition, for any feature grant, on any surface. This boundary is enforced on the server, not by hiding menu items.

⚠️Never another employee's data

Staff cannot see anyone else's payslip, pay, personnel record or requests. Every read is scoped to their own record on the server — passing someone else's id in a URL does not widen it. Attempts are logged.

Staff also cannot create or edit pay runs, add or remove people from a run, post payroll, or reach any administrative screen.

Their payslips in detail

The payslips surface is a page in its own right — the latest payslip, net pay over time, the year to date, and the full history. See My payslips.

/people/pay-schedules/:id used to be the admin pay schedule page. For an employee on the Staff role it now opens their own payslip for that run. For everyone else it forwards to the pay-run workspace.

Giving someone portal access

Every employee record carries an email address — it is required on the hire page — and a Staff portal login is provisioned for that address when the record is created. If someone cannot sign in, check the email on their record first — see Hiring an employee.

Deactivating an employee disables their portal login while keeping every payslip and payment on record.