Skip to main content

Authorization roles - Employee

Employee authorization role

Written by Marko Klopčič

An authorization scheme defines what a user can see and do in All Hours. The Employee scheme is the default for staff who only need access to their own data

Default settings of the Employee scheme

Views

The employee has four views available, all limited to their own data:

View

What it shows

Home

Home page with the time registration widget. This is where they clock in and out.

One person

Monthly timesheet with the daily record and balances.

Employee day

Daily timesheet with individual registrations.

Calendar one person

Full-year calendar with an overview of absences.

Registration and mobile rights

Setting

What it means

Web clocking

The employee can clock in via the web app. Access can be restricted to a specific IP address.

Clocking on mobile app

The employee can clock in via the mobile app.

Require location before clocking an event

Registration is only possible once the app has obtained the device's location.

Geofencing

Registration is only possible inside a defined geographic area.

More on this:


Adding registrations and absences

You set the employee's freedom of entry separately for registrations and for absences. Both offer the same four options:

Option

What it means

Disabled

The employee cannot add an entry. A forgotten registration or an absence is entered by the manager or administrator.

Require approval

The entry is recorded as a request and only takes effect once an approver confirms it. Recommended setting — the manager has oversight of every change.

Approve automatically

The entry goes through the same approval process but is approved automatically. A record of the entry stays in the history and the approver is notified. Suitable when you trust employees but want an audit trail.

Allow and bypass the approval process

The entry takes effect immediately and never enters the approval process. The least traceable option — use it only in exceptional cases.

The difference between Approve automatically and Allow and bypass the approval process: both let the employee enter data without waiting, but the first keeps a record and a notification, the second does not.

Editing and deleting existing records

Besides adding, you can also let the employee change records that already exist. These are three separate rights:

Right

What it allows

Edit/delete registrations

The employee can correct the time of an existing registration or delete it — for example a wrongly registered clock-out.

Edit/delete absences

The employee can change or remove an absence already entered, e.g. move vacation to another date or cancel it.

Add/edit/delete corrections

The employee can enter and change corrections themselves — manual adjustments to balances such as the overtime balance and the vacation balance.

Recommendation: in the Employee role these three rights should normally be switched off. Editing and deleting do not go through the approval process, whatever the employee changes takes effect immediately, and the previous value is no longer visible. The right to corrections is particularly sensitive, as it lets employees change their own overtime or vacation balance.

If an employee needs a fix, it is safer for them to submit a new entry with Require approval set, and to have the manager correct the existing record.

Absence planning

The Absence planning right lets employees see entered absences in advance, for future dates, typically annual leave several months ahead for all coworkers. They can plan their absences, so the whole team is not absent at the same time.

A planned absence:

  • is visible in the calendar and in the team overview, so the manager can see who is expected to be away when coordinating;

  • is taken into account in the records once the date arrives and is deducted from the vacation balance.

Did this answer your question?