Permissions
In the Folks application, access is managed through roles that can be predefined or customized. Managing human resources information is a critical task to ensure the strict protection of employee and company data.
Default roles
The roles available in Folks are:
- Employee: Limited access to their own information.
- Manager/Supervisor: Access to information of employees under their supervision.
- Payroll: Access to certain employee information to track time and other requests.
- Full Access: Access to all company information.
Learn more about suggested roles.
Special Role
- Company Administrator: Limited to only one person per company, this role has all administrative rights and can configure the application according to the company’s needs.
Role-Based Access Management
Role-based access management allows restricting the visibility of information based on various criteria such as the employee, structure, or specific module. Here are some examples:
- An employee is limited to their own information.
- A manager can see information for the employees they supervise.
- An employee may have read-only access to certain modules.
- A payroll manager can see the timesheets of all employees at an working site.
Using roles allows for better overall access management and minimizes individual exceptions. It is also easier to update, adjust, and track access when it is linked to roles.
Assigning a Role and Traceability
It is strongly recommended to assign roles and permissions to individual email addresses (for example j.doe@abc.com) and not to distribution groups or other shared addresses (for example: hr@abc.com). This not only helps limit the chances of a breach but also allows for more precise identification of who has access to what.
If it is necessary to provide an address based on a group, for example hr@abc.com, it is important to manage access to this address rigorously, notably through password management and/or limited-time sharing.
Key Resources
To better understand the implementation and management of permissions in Folks, access the following resources: