← All guidesDownload PDF

Administrator Guide

People, organisation, policies and system administration

Admin dashboard

For users with the HR Admin role. This guide covers the admin-only pages; day-to-day flows live in the companion guides (section 1).

Applies to HR.Click Web  ·  Document v1.2 · September 2026

HR.Click · Administrator GuideAdministering HR.Click

1Your role, and where everything else is

An administrator can do everything every other role can, org-wide. Those flows are documented once, in the companion guides — this guide covers only what is admin-only:

TopicWhere it's documented
Everyday portal use (time, leave, requests…)Employee Web Guide
Leave approvals, balances, vacation reportsVacation Manager Guide
Time matrix, corrections, approvals, devicesTime Manager Guide
Shift rosters: the board, series, breaksShift Manager Guide
Access requests, provisioning, systems catalogueAccess Manager Guide
Face terminals: setup, pairing, enrollment, OTA, troubleshootingFace Terminal Manual (covers the web's Terminals & Enrollments pages too)

What remains — and what this guide walks through — is: users and their lifecycle, the organisation structure, teams, leave policy (vacation types), GDPR consent texts, system settings, webhooks, the audit log, import, and billing.

The Org dashboard

As an admin your Dashboard gains an Org view: live company KPIs (working now, late today, on vacation, pending requests, active users), a pending-approvals panel with inline actions, the events feed, and Recent warnings — the latest Warning/Critical audit entries, one click from the full log.

Org dashboard
The Org view — the company at a glance.

2Users and their lifecycle

Users has two tabs. List is the directory: name, department, office, role chips, vacation balance, joined date, status (ACTIVE / BLOCKED / PENDING) and last-seen. Filter by text, position, role, office or status. Report is the composition report below — admin-only, because it is built from gender and date of birth.

Users list
The directory — roles, balances and statuses in one table.

Inviting and editing

Invite creates the account — first and last name, e-mail, office, one or more teams (at least one, with an optional Mark as team leader tick) and, optionally, the position assigned right there. The person receives an e-mail link to set their own password, then enrols at a terminal. Tracks work time is off by default on an invite: switch it on for anyone who is expected to check in, otherwise they get no dashboard and no time report. The other fields — phone, gender, address, birthday, joined date, locale — are optional and editable later; Joined may be left empty when the start date is genuinely unknown.

The edit page tabs: Profile, Position (assignment history, work-time overrides), External IDs, plus Access/Equipment (for access/asset managers) and Offboard log after offboarding.

Roles & permissions — six toggles on the profile:

RoleWhat it grants
HR AdminEverything: directory, org structure, system settings, billing.
Time managerTime reports, corrections, approvals.
Shift managerShift rosters — the board, the drawer, series and each shift's break. Narrowed to people on a shift schedule; an admin manages every shift regardless.
Vacation managerLeave approvals and balances.
Access managerAccess governance and the systems catalogue.
Asset managerEquipment inventory: assign, return, retire.

Team lead is not a toggle — it comes from team membership (the "Leader" mark on a team). You can't edit your own roles or e-mail.

Header actions: Block/Unblock, Reset face (wipes the terminal faceprint), Withdraw consent (GDPR), Reset password (e-mails a one-time link and signs out all devices).

User edit
The profile — fields, locale, and the five role toggles.

The composition report

Users → Report answers who the company is made of, as of a date you pick: headcount in scope, the split by gender, and the distribution across age and tenure bands with a median under each. Bars are counts, not shares — the gridline legend says what one step is worth.

  • Scope follows the office filter in the top bar; Include offboarded people adds leavers so you can compare a period with its own history.
  • People with no birthday, no start date or no current position are not silently dropped — each gets its own labelled band, so the total always adds up.
  • Click a band to list the people behind the number; the search box inside filters that list.
  • Export XLSX saves the whole report for a board pack.

Offboarding

The Offboard wizard walks a departure through five steps: Start → Physical & biometric → Digital access → Equipment → Finalize. Each step is a checklist — face reset, terminal removal, keycard and building access, per-grant access revocation, per-asset equipment return — and you can't continue until everything applicable is ticked. Finalizing blocks the account and writes the full case to the Offboard log tab.

Offboarding does not cut a leaver off mid-shift. The offboarding report that goes to every system owner names the exact cutoff in bold — the last working day plus the hours in force that day (a part-timer's own end-of-day wins over the office default) — with a plain "keep this open until X, remove it after" line. Integrations get the same answer automatically: rather than firing at offboard time, the access.revoke_due webhook is held until office-local midnight after that last day and released from there. A reinstated leaver cancels their own pending event. An ordinary manual revoke, outside offboarding, still fires immediately.

Delete vs anonymize

Delete is a soft removal that keeps history. Anonymize irreversibly strips personal data (GDPR erasure) — it has a 10-second countdown for a reason. Both are offboard-first: as soon as a person has any position history, the buttons stay disabled ("Offboard this user first") until the wizard has been finalized. Only a never-employed account can be removed straight away.

Offboard wizard
Offboarding — nothing is forgotten.

3Organisation — offices, departments, positions, working days

Organization gathers the whole structure in five tabs: Offices, Departments, Positions, Working days and Announcements.

Offices
Offices — one card per site.

Offices

Each office carries the rules its people inherit: working hours and break (changes are effective-dated, with history), work days (Mon–Sun picker), timezone, and the vacation allowance — days per year for the first year and subsequent years. Optionally: a map pin with a geofence radius, and the office network (below). The pin and radius are stored for the coming mobile app — today nothing is decided by distance: whether a punch counts as in-office is settled by the IP address alone. An office may also name a parent office for working-day inheritance — it then observes all of that office's holidays and overrides on top of its own (see Working days below), so a country branch can follow the HQ calendar without re-entering every holiday.

The office network is what tells a punch it was made in the office: a DynDNS host that resolves to the current address, and/or Fixed IP addresses for a static address or a whole NAT pool — each rule may carry its own expiry date. This is the list both check-in policies match against (section 6), and it is what decides in-office versus remote on a phone or browser punch.

Unpunched break is a three-way choice for a day where nobody punched a break at all: None leaves it alone; Deduct the default break charges the office break once the day is worked to at least 75% of its norm (this can dip the day below the norm); Deduct from overtime only also requires no punched break, but only trims the excess worked past the norm — the norm itself is never reduced. Any punched break, however short, opts the day out of either mode. It is None by default; switching to either deducting mode changes what everyone's totals mean, so announce it before you do. This settles office-schedule days only: a shift carries its own break and its own rule on the shift row, and only borrows these as the starting values when a shift manager creates one.

Office announcements are not edited on the office card — they live in Organization → Announcements and each one may target several offices at once (leave the selection empty and it reaches everybody).

Departments & positions

Departments form a drag-to-reorganise tree; a department can't be deleted while it still has children or people. Positions define the schedule type — office hours or shifts — and may override the office vacation allowance per office.

Office edit
An office — hours, allowance, work days, parent office for inheritance, geofence.

Working days

The calendar of exceptions: holidays, short days and working-day overrides, scoped to one office, several offices, or global. These drive everything — vacation previews skip them, the terminal and reports respect them. An office that names a parent (above) also inherits the parent's exceptions; its own entry on a date always wins over an inherited one, which wins over a global one.

Working days
Working days — holidays and overrides, per office or global.
Teams

Teams (Admin section) is where team leads are made: create a team, add members, tick Leader on at least one. Leaders approve their team's leave (TL stage) and see team-scoped views. A team with zero leaders gets a warning in the list.

4Vacation types — your leave policy

Vacation types define what employees can request and how it behaves:

  • Type — name, short code, calendar colour, and an icon (a FontAwesome class, e.g. fa-sharp fa-solid fa-umbrella-beach) that then stands next to the type everywhere it is named — request form, list, calendar legend, day drawer. Leave it empty for a plain colour dot.
  • Balance — paid/unpaid; effect deduct / accrue / none; optionally pause accrual while away (typical for unpaid leave).
  • Approval — the TL / VM toggles compose the flow: both, one, or auto-approved.
  • Limits — max consecutive working days and minimum notice; each limit is either soft (over-limit requests are flagged for manual approval and auto-reject on a deadline) or hard (blocked at submit).
  • Restrict auto approve/reject — takes this type out of the timeout crons: requests of it are never auto-approved when a stage times out, and a flagged one is never auto-rejected on the deadline. Someone has to decide. Use it for the types where silence must not become a decision (unpaid, long-term, parental).

Changing a balance-affecting rule offers a reconcile preview so existing vacations are recalculated deliberately, not silently.

Vacation type
A vacation type — balance effect, approval flow, limits.

Consent texts manages the biometric-consent documents employees sign at terminal enrolment, versioned per country and language. The lifecycle is strict: a draft is editable → Publish makes it active (and immutable) → Deprecate retires it. To change wording, create the next version. Each version links to its signatures — who accepted, when, where.

Consent texts
Consent versions — draft, active, deprecated.

6System settings

System settings holds the instance-wide switches, each with its own save state and a "last changed by" audit line:

  • Security — enable/disable passkey sign-in org-wide; require passkeys for admins; and the JWT signing secret with a Rotate action — rotating signs everyone out within about an hour (your incident lever).
  • Single sign-on — Google Workspace / Microsoft Entra status, read-only here (configured by the operator in the instance config).
  • Data retention — how many years of personal data to keep (GDPR cleanup honours it).
  • Vacations — the stage timers (hours) for flagged-request handling per TL/VM stage.
  • Time tracking — where a phone, the browser extension, or the HR.Click dashboard itself may clock in from. Three independent policies, same three values (see below). The face terminal ignores them entirely: it always records an in-office punch. The same group holds missed-punch requests (see below).
Policy valueWhat it means
Office network onlyA punch is accepted only from an IP address registered to one of your offices (section 3). Anything else is refused. This is the default for phone check-in.
AnywhereAccepted from any address. A punch made outside a known office network is recorded as remote, not in-office — it still counts as worked time.
DisabledThat channel cannot clock in at all. This is the default for browser check-in and site check-in; with browser check-in off, the extension keeps showing the day read-only and the time strip disappears from everyone's new-tab page. With site check-in off, the dashboard shows no check-in buttons at all.

Both are marked High impact: changing either asks for confirmation, spelling out the consequence, and writes a "last changed by" line.

Missed-punch requests

Whether an employee may ask for one forgotten punch to be added, or a wrong one replaced, instead of coming to a manager for every missed check-out. Nothing they file counts until a time manager approves it in Approvals — the queue is the gate, these settings only bound how much reaches it.

SettingWhat it does
Missed-punch requestsThe feature switch. On by default. Off removes the One punch tab entirely, leaving people the whole-day self-report.
How far back a missed punch may be datedDefault 24 hours — a floor, not a ceiling: an office whose shift runs longer than half of it gets twice its own shift length instead, so a 20-hour rotation reaches back 40 hours without you setting anything. Going below a day mostly sends these requests to a manager, because someone who forgets to check out at 18:00 rarely notices before the next morning.
Missed-punch requests per person each monthDefault 5; 0 means no limit. Bounds how much review this can generate. A withdrawn request does not count — nobody reviewed it. Independently, at most three requests may await a decision at once.
Why a window at all

What stops a person inventing a month of attendance is not the window — it is that a request is one punch, that it is only accepted where it fits the day’s existing punches (a check-in cannot follow a check-in), that it needs a written reason, and that a manager approves it. The window exists so the feature stays about forgetfulness rather than rewriting history; anything older stays a manager’s job, and the employee’s date picker simply will not offer it.

System settings
System settings — security, SSO, retention, vacation timers, check-in policies, missed-punch rules.

7Webhooks

Webhooks integrates HR.Click with the outside world, in both directions:

  • Outbound — endpoints that receive HR.Click events (check-ins, vacations, access, shifts…). Each has an HTTPS URL, an HMAC secret (shown once; rotate any time), a checkbox tree of subscribed events, a Send test button, and a Recent deliveries table with per-delivery status and retry. Failing endpoints are badged in the list.
  • Inbound — registered external systems (turnstiles, access control, HRIS) that push signed events into HR.Click via their own slug URL.
Webhooks
Outbound webhooks — endpoints, subscriptions, delivery health.

8The audit log

Every meaningful action lands in the append-only Audit log — sign-ins, edits, approvals, terminal events, privacy actions — with actor, target, result, request id, IP and metadata. Filter by action (wildcards % and _ work, e.g. auth.%), severity, result, actor and time; preset chips cover the common hunts. Export CSV / JSON is rate-limited to one export per minute. Retention: 24 months, UTC.

Audit log
The audit log — filterable, append-only, exportable.

9Import, billing, and the rest

Import

Import onboards a whole company from a spreadsheet: upload (a template is downloadable) → review — the wizard walks Overview → Leave types → Positions → Teams → People, letting you map/merge/skip each item — → commit with a summary. The file can be dropped straight onto the upload area. On the People step each person carries a department picker: nobody lands in a default department by accident, and leaving it untouched keeps whatever the file said. The commit is gated by your seat quota: you can't import more people than the plan allows.

Billing

Billing shows your subscription (plan, status, renewal date and amount) and the two quotas that gate growth: user seats and terminals. When you change plan, the price breakdown also prints the all-in monthly cost averaged per seat per day — the figure to quote when someone asks what HR.Click costs per employee. Payment methods and invoices live in the external billing portal — Manage billing opens it.

Following

Following is a personal convenience for admins and time managers: subscribe to specific colleagues' check-in / break / clock-out events and get pinged when they happen — useful for reception or duty rosters. Pause, edit or unfollow any time.

Billing
Billing — plan and quotas; the portal handles payment.

10Where a check-in came from

A punch made from a phone or the browser extension stores the address it arrived from, and a background sweep resolves that into a country, region and city — plus a VPN/proxy verdict where the provider supplies one. The location shows in the day drawer under the event: a flag, the place, the address itself in the tooltip, and a VPN or Tor tag when the connection is not what it seems. Nothing shows until the lookup has landed.

  • Only some punches carry it. Terminal, imported, webhook and self-reported rows stay empty on purpose — a kiosk reports its own office uplink and a back-fill reports the operator's, neither of which is the employee's location.
  • Only you see it. The block is admin-only, deliberately narrower than the rest of the record: a time manager reads attendance, not where a person physically was. The data is left out of the payload entirely for everyone else, rather than merely hidden on screen.
  • The lookup never blocks a punch. It runs on a schedule, reuses an answer it already holds for the same address, and stops rather than burning rows when the provider fails — so an expired key or an exhausted quota resolves itself on a later run.
  • The provider is wired up by your operator in the instance configuration, not in System settings. With none configured, punches simply carry no location and everything else works unchanged.
Treat it as what it is

This is location history about your staff. Anonymizing a person clears their stored addresses and resolved places while keeping the punches, and a GDPR data export (Art. 15) includes both the locations and any notes the person attached to their punches — because that is exactly what those articles cover. Do not re-purpose the block for anything you have not told your people about.

HR.Click — Administrator Guide · v1.2 · September 2026. Product screens shown with sample data; names of persons are fictitious examples.