People, organisation, policies and system administration

An administrator can do everything every other role can, org-wide. Those flows are documented once, in the companion guides — this guide covers only what is admin-only:
| Topic | Where it's documented |
|---|---|
| Everyday portal use (time, leave, requests…) | Employee Web Guide |
| Leave approvals, balances, vacation reports | Vacation Manager Guide |
| Time matrix, corrections, approvals, devices | Time Manager Guide |
| Shift rosters: the board, series, breaks | Shift Manager Guide |
| Access requests, provisioning, systems catalogue | Access Manager Guide |
| Face terminals: setup, pairing, enrollment, OTA, troubleshooting | Face Terminal Manual (covers the web's Terminals & Enrollments pages too) |
What remains — and what this guide walks through — is: users and their lifecycle, the organisation structure, teams, leave policy (vacation types), GDPR consent texts, system settings, webhooks, the audit log, import, and billing.
As an admin your Dashboard gains an Org view: live company KPIs (working now, late today, on vacation, pending requests, active users), a pending-approvals panel with inline actions, the events feed, and Recent warnings — the latest Warning/Critical audit entries, one click from the full log.

Users has two tabs. List is the directory: name, department, office, role chips, vacation balance, joined date, status (ACTIVE / BLOCKED / PENDING) and last-seen. Filter by text, position, role, office or status. Report is the composition report below — admin-only, because it is built from gender and date of birth.

Invite creates the account — first and last name, e-mail, office, one or more teams (at least one, with an optional Mark as team leader tick) and, optionally, the position assigned right there. The person receives an e-mail link to set their own password, then enrols at a terminal. Tracks work time is off by default on an invite: switch it on for anyone who is expected to check in, otherwise they get no dashboard and no time report. The other fields — phone, gender, address, birthday, joined date, locale — are optional and editable later; Joined may be left empty when the start date is genuinely unknown.
The edit page tabs: Profile, Position (assignment history, work-time overrides), External IDs, plus Access/Equipment (for access/asset managers) and Offboard log after offboarding.
Roles & permissions — six toggles on the profile:
| Role | What it grants |
|---|---|
| HR Admin | Everything: directory, org structure, system settings, billing. |
| Time manager | Time reports, corrections, approvals. |
| Shift manager | Shift rosters — the board, the drawer, series and each shift's break. Narrowed to people on a shift schedule; an admin manages every shift regardless. |
| Vacation manager | Leave approvals and balances. |
| Access manager | Access governance and the systems catalogue. |
| Asset manager | Equipment inventory: assign, return, retire. |
Team lead is not a toggle — it comes from team membership (the "Leader" mark on a team). You can't edit your own roles or e-mail.
Header actions: Block/Unblock, Reset face (wipes the terminal faceprint), Withdraw consent (GDPR), Reset password (e-mails a one-time link and signs out all devices).

Users → Report answers who the company is made of, as of a date you pick: headcount in scope, the split by gender, and the distribution across age and tenure bands with a median under each. Bars are counts, not shares — the gridline legend says what one step is worth.
The Offboard wizard walks a departure through five steps: Start → Physical & biometric → Digital access → Equipment → Finalize. Each step is a checklist — face reset, terminal removal, keycard and building access, per-grant access revocation, per-asset equipment return — and you can't continue until everything applicable is ticked. Finalizing blocks the account and writes the full case to the Offboard log tab.
Offboarding does not cut a leaver off mid-shift. The offboarding report that goes to every system owner names the exact cutoff in bold — the last working day plus the hours in force that day (a part-timer's own end-of-day wins over the office default) — with a plain "keep this open until X, remove it after" line. Integrations get the same answer automatically: rather than firing at offboard time, the access.revoke_due webhook is held until office-local midnight after that last day and released from there. A reinstated leaver cancels their own pending event. An ordinary manual revoke, outside offboarding, still fires immediately.
Delete is a soft removal that keeps history. Anonymize irreversibly strips personal data (GDPR erasure) — it has a 10-second countdown for a reason. Both are offboard-first: as soon as a person has any position history, the buttons stay disabled ("Offboard this user first") until the wizard has been finalized. Only a never-employed account can be removed straight away.

Organization gathers the whole structure in five tabs: Offices, Departments, Positions, Working days and Announcements.

Each office carries the rules its people inherit: working hours and break (changes are effective-dated, with history), work days (Mon–Sun picker), timezone, and the vacation allowance — days per year for the first year and subsequent years. Optionally: a map pin with a geofence radius, and the office network (below). The pin and radius are stored for the coming mobile app — today nothing is decided by distance: whether a punch counts as in-office is settled by the IP address alone. An office may also name a parent office for working-day inheritance — it then observes all of that office's holidays and overrides on top of its own (see Working days below), so a country branch can follow the HQ calendar without re-entering every holiday.
The office network is what tells a punch it was made in the office: a DynDNS host that resolves to the current address, and/or Fixed IP addresses for a static address or a whole NAT pool — each rule may carry its own expiry date. This is the list both check-in policies match against (section 6), and it is what decides in-office versus remote on a phone or browser punch.
Unpunched break is a three-way choice for a day where nobody punched a break at all: None leaves it alone; Deduct the default break charges the office break once the day is worked to at least 75% of its norm (this can dip the day below the norm); Deduct from overtime only also requires no punched break, but only trims the excess worked past the norm — the norm itself is never reduced. Any punched break, however short, opts the day out of either mode. It is None by default; switching to either deducting mode changes what everyone's totals mean, so announce it before you do. This settles office-schedule days only: a shift carries its own break and its own rule on the shift row, and only borrows these as the starting values when a shift manager creates one.
Office announcements are not edited on the office card — they live in Organization → Announcements and each one may target several offices at once (leave the selection empty and it reaches everybody).
Departments form a drag-to-reorganise tree; a department can't be deleted while it still has children or people. Positions define the schedule type — office hours or shifts — and may override the office vacation allowance per office.

The calendar of exceptions: holidays, short days and working-day overrides, scoped to one office, several offices, or global. These drive everything — vacation previews skip them, the terminal and reports respect them. An office that names a parent (above) also inherits the parent's exceptions; its own entry on a date always wins over an inherited one, which wins over a global one.

Teams (Admin section) is where team leads are made: create a team, add members, tick Leader on at least one. Leaders approve their team's leave (TL stage) and see team-scoped views. A team with zero leaders gets a warning in the list.
Vacation types define what employees can request and how it behaves:
Changing a balance-affecting rule offers a reconcile preview so existing vacations are recalculated deliberately, not silently.

Consent texts manages the biometric-consent documents employees sign at terminal enrolment, versioned per country and language. The lifecycle is strict: a draft is editable → Publish makes it active (and immutable) → Deprecate retires it. To change wording, create the next version. Each version links to its signatures — who accepted, when, where.

System settings holds the instance-wide switches, each with its own save state and a "last changed by" audit line:
| Policy value | What it means |
|---|---|
| Office network only | A punch is accepted only from an IP address registered to one of your offices (section 3). Anything else is refused. This is the default for phone check-in. |
| Anywhere | Accepted from any address. A punch made outside a known office network is recorded as remote, not in-office — it still counts as worked time. |
| Disabled | That channel cannot clock in at all. This is the default for browser check-in and site check-in; with browser check-in off, the extension keeps showing the day read-only and the time strip disappears from everyone's new-tab page. With site check-in off, the dashboard shows no check-in buttons at all. |
Both are marked High impact: changing either asks for confirmation, spelling out the consequence, and writes a "last changed by" line.
Whether an employee may ask for one forgotten punch to be added, or a wrong one replaced, instead of coming to a manager for every missed check-out. Nothing they file counts until a time manager approves it in Approvals — the queue is the gate, these settings only bound how much reaches it.
| Setting | What it does |
|---|---|
| Missed-punch requests | The feature switch. On by default. Off removes the One punch tab entirely, leaving people the whole-day self-report. |
| How far back a missed punch may be dated | Default 24 hours — a floor, not a ceiling: an office whose shift runs longer than half of it gets twice its own shift length instead, so a 20-hour rotation reaches back 40 hours without you setting anything. Going below a day mostly sends these requests to a manager, because someone who forgets to check out at 18:00 rarely notices before the next morning. |
| Missed-punch requests per person each month | Default 5; 0 means no limit. Bounds how much review this can generate. A withdrawn request does not count — nobody reviewed it. Independently, at most three requests may await a decision at once. |
What stops a person inventing a month of attendance is not the window — it is that a request is one punch, that it is only accepted where it fits the day’s existing punches (a check-in cannot follow a check-in), that it needs a written reason, and that a manager approves it. The window exists so the feature stays about forgetfulness rather than rewriting history; anything older stays a manager’s job, and the employee’s date picker simply will not offer it.

Webhooks integrates HR.Click with the outside world, in both directions:

Every meaningful action lands in the append-only Audit log — sign-ins, edits, approvals, terminal events, privacy actions — with actor, target, result, request id, IP and metadata. Filter by action (wildcards % and _ work, e.g. auth.%), severity, result, actor and time; preset chips cover the common hunts. Export CSV / JSON is rate-limited to one export per minute. Retention: 24 months, UTC.

Import onboards a whole company from a spreadsheet: upload (a template is downloadable) → review — the wizard walks Overview → Leave types → Positions → Teams → People, letting you map/merge/skip each item — → commit with a summary. The file can be dropped straight onto the upload area. On the People step each person carries a department picker: nobody lands in a default department by accident, and leaving it untouched keeps whatever the file said. The commit is gated by your seat quota: you can't import more people than the plan allows.
Billing shows your subscription (plan, status, renewal date and amount) and the two quotas that gate growth: user seats and terminals. When you change plan, the price breakdown also prints the all-in monthly cost averaged per seat per day — the figure to quote when someone asks what HR.Click costs per employee. Payment methods and invoices live in the external billing portal — Manage billing opens it.
Following is a personal convenience for admins and time managers: subscribe to specific colleagues' check-in / break / clock-out events and get pinged when they happen — useful for reception or duty rosters. Pause, edit or unfollow any time.

A punch made from a phone or the browser extension stores the address it arrived from, and a background sweep resolves that into a country, region and city — plus a VPN/proxy verdict where the provider supplies one. The location shows in the day drawer under the event: a flag, the place, the address itself in the tooltip, and a VPN or Tor tag when the connection is not what it seems. Nothing shows until the lookup has landed.
This is location history about your staff. Anonymizing a person clears their stored addresses and resolved places while keeping the punches, and a GDPR data export (Art. 15) includes both the locations and any notes the person attached to their punches — because that is exactly what those articles cover. Do not re-purpose the block for anything you have not told your people about.
HR.Click — Administrator Guide · v1.2 · September 2026. Product screens shown with sample data; names of persons are fictitious examples.