Docs
Role guide
Each company workspace in Mcodey HR has five roles. This guide explains who can do what in the admin web panel and the employee mobile app.
How roles work
Each user signs in with email and password. One person can hold one role, or both an admin role and an employee role if provisioned that way.
Admin roles see sidebar modules based on permissions. Menus without permission do not appear.
The employee role cannot access the admin panel — only the mobile app or employee portal.
Your package (Basic / Business / Pro) sets feature gates and limits (employees, users, branches, devices). Roles define what you can do within those limits.
Hierarchy (highest to lowest)
- Level 100 — Company owner: billing requests, settings, all users
- Level 80 — HR manager: full day-to-day HR, billing view only
- Level 60 — Branch manager: branch attendance, leave, tasks
- Level 40 — Attendance operator: devices, sync, attendance records
- Level 20 — Employee: mobile check-in, leave requests, payslips
How to assign roles
The owner or HR manager creates admin users from the Users screen and picks a role.
- Admin panel → Users → Create user
- Enter name, email, password, and role (e.g. HR manager)
- Check package user limit — if full, the owner must request a capacity increase in Billing
- For staff records, use Employees → Create and link the user account to the employee profile
- Mobile app login works only when the user is linked to an employee record with the employee role
Role comparison
| Role | Level | Summary |
|---|---|---|
| Company owner | 100 | Full company access — billing, settings, users, and license management |
| HR manager | 80 | Full day-to-day HR — employees, leave, payroll, reports |
| Branch manager | 60 | Branch attendance, leave, tasks, and staff coordination |
| Attendance operator | 40 | Devices, sync agent, and attendance records |
| Employee | 20 | Mobile check-in, leave, payslips, and self-service |
Browse by role
Level 100
Company owner
Full company access — billing, settings, users, and license management
Read guideLevel 80
HR manager
Full day-to-day HR — employees, leave, payroll, reports
Read guideLevel 60
Branch manager
Branch attendance, leave, tasks, and staff coordination
Read guideLevel 40
Attendance operator
Devices, sync agent, and attendance records
Read guideLevel 20
Employee
Mobile check-in, leave, payslips, and self-service
Read guideWorkflow
Device connection guide
Connect K60 / biometric devices via HR Sync Agent (pull) or ADMS cloud push
Read guideFrequently asked questions
Can one person have two roles?
Yes. For example, an owner can also be an employee and use both the admin panel and the mobile app. For security, consider separate admin and employee accounts.
Can a branch manager see other branches?
Branch managers work at branch level. They do not get company-wide report exports or full HR access.
Can employees sign in to the admin panel?
No. The employee role only includes portal permissions, not admin sidebar modules.
Who can request billing changes?
Only the company owner has billing.request. HR managers can view billing with billing.view.
What happens when a package limit is reached?
You cannot add more employees or admin users. The owner must request a capacity increase in Billing and pay the invoice.