Access Control

Role matrix

Server-enforced role gates for every portal surface and API boundary.

RoleDefault portalAllowedRestricted
Employee/mPunch in/out, leave request, personal timelineBilling, owner portal, super portal, tenant management
HR Admin/app/projectsEmployees, attendance, leave, payroll export, settingsOwner tenant controls, super admin controls
Owner / MSP/owner, /mspTenant list, usage, read-only impersonation, exportsSuper-admin only actions
Super Admin/superPlatform health, license QA controls, global tenant oversightCustomer-tenant write actions outside approved controls