An authorization scheme defines what a user can see and do in All Hours. The Employee scheme is the default for staff who only need access to their own data
Default settings of the Employee scheme
Views
The employee has four views available, all limited to their own data:
View | What it shows |
Home | Home page with the time registration widget. This is where they clock in and out. |
One person | Monthly timesheet with the daily record and balances. |
Employee day | Daily timesheet with individual registrations. |
Calendar one person | Full-year calendar with an overview of absences. |
Registration and mobile rights
Setting | What it means |
Web clocking | The employee can clock in via the web app. Access can be restricted to a specific IP address. |
Clocking on mobile app | The employee can clock in via the mobile app. |
Require location before clocking an event | Registration is only possible once the app has obtained the device's location. |
Geofencing | Registration is only possible inside a defined geographic area. |
Adding registrations and absences
You set the employee's freedom of entry separately for registrations and for absences. Both offer the same four options:
Option | What it means |
Disabled | The employee cannot add an entry. A forgotten registration or an absence is entered by the manager or administrator. |
Require approval | The entry is recorded as a request and only takes effect once an approver confirms it. Recommended setting — the manager has oversight of every change. |
Approve automatically | The entry goes through the same approval process but is approved automatically. A record of the entry stays in the history and the approver is notified. Suitable when you trust employees but want an audit trail. |
Allow and bypass the approval process | The entry takes effect immediately and never enters the approval process. The least traceable option — use it only in exceptional cases. |
The difference between Approve automatically and Allow and bypass the approval process: both let the employee enter data without waiting, but the first keeps a record and a notification, the second does not.
Editing and deleting existing records
Besides adding, you can also let the employee change records that already exist. These are three separate rights:
Right | What it allows |
Edit/delete registrations | The employee can correct the time of an existing registration or delete it — for example a wrongly registered clock-out. |
Edit/delete absences | The employee can change or remove an absence already entered, e.g. move vacation to another date or cancel it. |
Add/edit/delete corrections | The employee can enter and change corrections themselves — manual adjustments to balances such as the overtime balance and the vacation balance. |
Recommendation: in the Employee role these three rights should normally be switched off. Editing and deleting do not go through the approval process, whatever the employee changes takes effect immediately, and the previous value is no longer visible. The right to corrections is particularly sensitive, as it lets employees change their own overtime or vacation balance.
If an employee needs a fix, it is safer for them to submit a new entry with Require approval set, and to have the manager correct the existing record.
Absence planning
The Absence planning right lets employees see entered absences in advance, for future dates, typically annual leave several months ahead for all coworkers. They can plan their absences, so the whole team is not absent at the same time.
A planned absence:
is visible in the calendar and in the team overview, so the manager can see who is expected to be away when coordinating;
is taken into account in the records once the date arrives and is deducted from the vacation balance.




