Administration
Manage users, permissions, organisation settings, and system configuration.
Overview
The Administration module provides:
- User and access management
- Role and permission configuration
- Organisation structure
- System settings
- Audit logging
- Data management
User Management
User Dashboard
View all users:
- Active users count
- Pending invitations
- Recent activity
- License usage
Adding Users
Inviting a New User
- Enter user details:
- Email address
- First and last name
- Role assignment
- Department (optional)
- Manager (optional)
- User receives email with setup link
User Setup Process
- User clicks invitation link
- Sets their password
- Configures two-factor authentication (if required)
- Completes profile information
- Account is activated
Managing Users
User Profile
Each user record includes:
Editing Users
- Open user record
- Modify details as needed
- Save changes
Deactivating Users
- Open user record
- Confirm action
- User loses access immediately
- Their data is preserved
Reactivating Users
- Filter users to show inactive
- Open the user record
- User can log in again
Deleting Users
Note: Deleting is permanent. Consider deactivating instead.
- Open user record
- Confirm deletion
- Historical references are preserved
User Settings
Password Policies
Configure password requirements:
- Minimum length (8+ recommended)
- Require uppercase letters
- Require lowercase letters
- Require numbers
- Require special characters
- Password expiry period
- Prevent password reuse
Session Management
- Session timeout duration
- Maximum concurrent sessions
- Remember me duration
- Force logout after password change
Two-Factor Authentication
Options:
Supported methods:
- Authenticator app (TOTP)
- SMS verification
- Email verification
Roles and Permissions
Understanding Roles
Roles define what users can access and do:
- Group permissions together
- Assign to users
- Control module access
Default Roles
Managing Roles
Creating a Role
- Enter role name and description
- Select permissions
- Save the role
Editing Roles
- Save changes
- All users with this role are updated
Mployr's built-in roles can be edited directly. The first time you change one, Mployr takes a copy for your business and edits that, so your changes are yours and future updates to the shipped role can't overwrite them.
Cloning Roles
- Open existing role
- Modify as needed
- Save as new role
Per-Person Overrides
Where one person needs slightly more or less than their role gives them, set per-profile permission overrides on their profile rather than creating a role for one person. Overrides are specific capabilities layered on top of the role, and are visible on the person's profile so they can be reviewed later.
The Permission Matrix
Permissions in Mployr are fine-grained. Rather than a single switch per module, each sub-resource within a module has its own permissions - so you can, for example, let a role view people but not their bank accounts, or manage rosters without touching payroll.
How It Works
- You'll see a matrix of modules and their sub-resources down the side, and actions across the top
- For each row, grant the actions the role should have:
Default-Deny
Access is default-deny: if a role hasn't been granted a permission, it doesn't have it. This means new modules and sub-resources are safe by default - you opt roles in rather than scrambling to lock things down. Buttons and pages a person can't use are hidden from them.
Permissions are enforced on the server for every request, not only in the interface - so a page someone can't see is also a request they can't make. Lists are filtered to the records the viewer is actually entitled to, rather than showing everything and hiding the buttons.
Record-Level Access
Some records grant access through involvement rather than only through roles:
This is deliberate: the people doing the work shouldn't need an administrator to widen their role first.
User Groups
User groups let you grant the same access to several people at once, instead of assigning roles person by person.
- Add people to the group
- Grant the group its access
Changing the group updates everyone in it - useful for teams whose access should always match.
Module Access
Beyond individual permissions, you can switch whole modules on or off for a role under Admin > Modules. If a role doesn't need Recruitment or Accounting, turn those modules off and they disappear from that role's navigation entirely - keeping the interface focused on what each person actually does.
Permission Categories
Module Permissions
Control access to modules:
Feature Permissions
Specific feature access:
- Run reports
- Approve requests
- Manage workflows
- Access admin settings
Data Permissions
Control data visibility:
Permission Inheritance
How permissions cascade:
- Role permissions apply first
- User-specific overrides second
- Deny takes precedence over allow
Organisation Structure
Business Settings
Company Profile
- Configure:
- Business name
- ABN/ACN
- Address
- Phone and email
- Website
- Industry
Branding
Customise the system appearance:
- Upload company logo
- Upload letterhead image
- Set brand colours
- Configure email templates
Regional Settings
- Date format (DD/MM/YYYY, MM/DD/YYYY)
- Time format (12-hour, 24-hour)
- Timezone
- Currency
- First day of week
- Financial year start
Departments
Creating Departments
- Enter:
- Department name
- Department code
- Parent department (for hierarchy)
- Department head
- Save
Department Hierarchy
Build organisational structure:
- Parent and child departments
- Multi-level nesting
- Visual org chart
Locations
Adding Locations
- Enter:
- Location name
- Address
- Phone
- Timezone
- Primary location flag
Location Settings
Per-location configuration:
- Public holidays
- Work hours
- Time tracking rules
- Leave policies
System Settings
General Settings
Application Settings
- Application name
- Support email
- Default language
- Session timeout
- Maintenance mode
Feature Toggles
Enable or disable features:
- Recruitment module
- Projects module
- CRM module
- Accounting module
Email Configuration
Mployr sends your business's mail - payslips, invoices, campaigns - through your own email accounts, so it arrives from your domain. Set these up under Email > Accounts and verify your sending domains under Email > Domains; see the Email guide for the full picture.
Email Settings
- SMTP server
- Port and encryption
- Authentication
- From name and address
Email Templates
Customise system emails:
- Invitation emails
- Password reset
- Signature requests
Integrations
Business-wide integrations are managed here; individuals manage their own connected apps and preferences in the Settings guide.
Available Integrations
Setting Up Integrations
- Find the integration
- Follow authentication steps
- Configure sync options
Personal and Business Connections
Connections are scoped as either personal or business:
This matters when someone leaves: a business connection survives, a personal one doesn't. Connect shared services as business connections.
Managing Connections
- View connection status
- Re-authenticate if needed
- Configure sync frequency
- View sync logs
Where an integration holds data of its own, that data is kept separately from yours rather than merged on arrival. You can diff the two, see exactly where they disagree, and apply the changes you want.
Data Management
Import Data
Importing Records
- Select record type
- Download CSV template
- Fill in your data
- Upload file
- Map columns to fields
- Preview import
- Confirm import
Import Tips
- Use templates for correct format
- Validate data before import
- Start with small test batch
- Check for duplicates
Export Data
Exporting Records
- Go to the module
- Apply filters if needed
- Select format (CSV, Excel)
- Choose fields to include
- Download file
Scheduled Exports
Set up automatic exports:
- Configure export parameters
- Set schedule (daily, weekly)
- Choose delivery method (email, storage)
Data Cleanup
Merge Duplicates
- Review potential duplicates
- Select records to merge
- Choose primary record
- Confirm merge
Archive Old Data
- Select record types - leads, quotes, orders, activities, projects and several others can be archived
- Set date range
- Preview affected records
- Archive data
Archiving takes records off the working lists without deleting them - they stay searchable and reportable. You can also set archiving to run nightly against your own rules, so lists stay tidy without anyone remembering to do it.
Audit and Compliance
Audit Log
Viewing Audit Trail
- View all system activity:
- User actions
- Record changes
- Login attempts
- Admin changes
Filtering Logs
Filter by:
- Date range
- User
- Action type
- Record type
- Module
Audit Details
Each log entry shows:
- Timestamp
- User who performed action
- Action type (create, update, delete)
- Record affected
- Old and new values
- IP address
Security
Security Dashboard
Monitor security status:
- Failed login attempts
- Unusual activity
- Permission changes
- Two-factor status
IP Restrictions
Limit access by IP:
- Add allowed IP addresses
- Enable restriction
- Users outside IPs are blocked
Session Management
View active sessions:
- All logged-in users
- Session duration
- IP addresses
- Force logout capability
Support and Help
Getting Help
In-App Help
- Search help articles
- View feature guides
Support Contact
For technical issues:
- Describe your issue
- Attach screenshots if helpful
- Submit ticket
Knowledge Base
Access documentation:
- User guides
- Video tutorials
- FAQs
- Best practices
System Information
About
View system details:
- Version number
- Last update
- License information
- Environment status
Health Check
Monitor system health:
- Database status
- Cache status
- Queue status
- Storage usage
Best Practices
User Management
- Use roles instead of individual permissions
- Review access quarterly
- Deactivate rather than delete
- Enable two-factor for admins
- Document role purposes
Security
- Enforce strong passwords
- Enable two-factor authentication
- Review audit logs regularly
- Limit admin access
- Keep software updated
Data Management
- Regular backups
- Test restore procedures
- Archive old data annually
- Clean up duplicates
- Document data policies
Frequently asked questions
Someone can't reach a page they should be able to
Check three layers in order: whether the module is switched on for their role, whether the role has the specific permission for that sub-resource, and whether the role's data scope reaches the records in question - a manager scoped to their own team won't see another team's. Per-profile overrides on the person can also be at play.
Can I edit Mployr's built-in roles?
Yes. The first time you change a shipped role, Mployr copies it for your business and edits the copy, so your changes are safe from future updates to the original.
One person needs a single extra permission - do I need a new role?
No. Use a per-profile permission override on their profile rather than creating a role that only ever has one member.
What happens to integrations when the person who set them up leaves?
Business-scoped connections keep working; personal connections don't. Connect anything shared - accounting, storage, shared mailboxes - as a business connection.
Tips
- Start with default roles, customise later
- Use departments to organise users
- Set up approval workflows for changes
- Review audit logs for compliance
- Test integrations in sandbox first
- Keep contact info current
- Prefer per-profile overrides to single-member roles
