Built-in Roles

Octal HR ships with four seeded roles covering common HR responsibilities. You can edit their permissions or create additional custom roles alongside them.

Super Admin is an access type, not a role. Users created with Access Type = Admin in Admin → Users have unrestricted access and do not need a role assigned.
HR Manager HR
Full HR operations: employee records, leaves, attendance, documents, and HR reports.
Payroll Officer Payroll
Payroll processing, salary structures, loans, and payroll reports.
Manager Manager
Manage direct reports: approve leaves, view attendance, and view team information.
View Only Read
Read-only access to permitted modules. Useful for auditors and observers.

Permission Matrix

✓ = full access  |  Own/Dept = restricted to own records or department  |  — = no access.

CapabilityHR ManagerPayroll OfficerManagerView Only
View all employees✓✓Direct✓
Edit employee profile✓———
Run payroll—✓——
View payslips✓✓—✓
Approve leave✓—Direct—
Approve loans—✓——
View reports✓✓Direct✓
Manage HR settings————

The above reflects the default permissions seeded for each role. A Super Admin (Access Type = Admin) has full access to every capability and is not shown in the matrix.

Custom Roles

Create a custom role when the seeded roles are too broad or narrow — for example a Payroll Only role for an outsourced agent, or a Compliance Auditor role with read-only access.

1
Go to Admin → Roles & Permissions → + New Role.
2
Enter a role name and optional description.
3
Toggle permissions on/off per module and action. Permissions are grouped by module (HR, Payroll, Leaves, Loans, Reports, Settings).
4
Click Save Role. The role is now available for assignment.
Apply the principle of least privilege. Avoid giving a role both "Edit Employee" and "Manage Settings" unless admin-level access is genuinely required.

Assigning Roles

Roles are assigned per user from Admin → Users → [User Name] → Role or when creating the user. Each user is assigned a single role, which defines their permissions.