User Roles & Permissions
Who can do what in TempClock: the agency console presets (Coordinator, Payroll, Read-only, Super admin), client dashboard roles, client portal roles with site limits, and two-factor sign-in.
Overview
Three consoles, each with its own roles.
TempClock has three places people sign in: the agency console (your own staff), the client dashboard (for clients who manage their own workers) and the client portal (your clients' supervisors and approvers). Access is checked on the server for every page and every action: a page a user cannot open is hidden from their menu and answers "Access denied" if they try the address.
Agency Console Presets
Start from a preset, then adjust.
| Preset | Can | Cannot |
|---|---|---|
| Super admin | Everything, including users, security settings and updates. Only a super admin can grant it. | Nothing is restricted |
| Coordinator | Runs the day: shifts, timesheets (approve and edit), exceptions, live view, workers, attendance, availability, reports and backfill. | Change pay rates, delete time, run payroll or manage users |
| Payroll | Pays people: payroll, Sage and Xero export, close the week, financial locks, reports. | Edit rate rules or timesheets (read-only) |
| Read-only | Look at the dashboard, live view, attendance, timesheets, shifts, workers and reports. | Change anything |
| Admin (custom) | Full access by default; untick pages and actions to restrict. | Security, automation and updates (super admin only) |
| Viewer (custom) | Only the pages you tick. | Change data |
Changing a worker's pay or charge rate needs the rate permission, and deleting time needs the delete permission, whatever page the user is on. A Coordinator can still save a worker as long as the rates stay the same.
Adding a User
Agency console.
Open Users
Go to Setup > Users.
Enter the details
Fill in Full Name, Email and Password, and choose the Access level. The description under the preset says what it allows.
Create
Click Create User. Use Edit later to change the preset or the page ticks. Nobody can promote themselves.
Client Dashboard Roles
For clients that manage their own workers.
| Role | Typical use |
|---|---|
| Admin | Settings, users, close week, Sage export, locations and kiosk devices, plus everything below. |
| Manager | Day-to-day running: shifts, timesheets, workers, backfill, exceptions and payroll views. |
| Viewer | Looks at dashboards, timesheets, attendance and reports without changing them. |
Client dashboard users are managed on Setup > Users in the client dashboard.
Client Portal Roles
For your clients' staff.
| Role | Can |
|---|---|
| Approver | Approve and dispute timesheets, request workers, see charges. |
| Supervisor | Raise disputes and request workers. Cannot approve or see charges. |
| Viewer | Look at timesheets and attendance. Cannot change anything. |
When you add or edit a portal user (Clients > Portal users), you can also limit them to named sites, so they only see the workers and hours at those sites. Pay rates are never shown in the portal.
Two-factor Sign-in
On every console.
What Is Logged
Every change has a name on it.
Sign-ins, two-factor events, permission changes, approvals, corrections and exports are written to the audit log with who did it and from which console. The audit log is read-only. See Audit Trail.
Know who turned up, and pay every hour right.
Face-verified clock-ins, live geofencing and payroll-ready timesheets in one system. Tell us how your shifts run and we will show you how it fits.
App hosted in the UK · Onboarding led by a pilot site · No app needed to clock in