What this module is for
Manage employees, departments, designations, roles, permissions, staff login, self-service, attendance, leave, timetable, and payroll.
Prerequisites
- Staff permissions assigned
- Employee records created
- Roles and permissions planned before enabling login access
Main screens
Step-by-step workflows
Enable staff login
- Create or verify the employee record.
- Assign a role with required permissions.
- Open Staff Login Access.
- Enable login and issue temporary access details through the approved workflow.
- Staff must change the temporary password on first login.
Use staff self-service
- Staff logs in from the staff login page.
- Complete forced password change if required.
- Open My Account.
- Use attendance, leave, timetable, and payroll self-service cards according to permissions.
Run payroll
- Configure payroll settings.
- Generate payroll for eligible staff.
- Review salary slip.
- Update status or print/export only through permitted payroll actions.
Operational detail
Permission checkpoints
- Employee records, staff login access, roles, permissions, self-service pages, leave, timetable, attendance, and payroll are separately controlled.
- Staff authentication uses staff login routes while preserving the existing school/admin login behavior.
- Global student search and module shortcuts must be hidden from staff unless the assigned role permits them.
Field guidance
Keep employee code, contact details, department, designation, staff type, and employment status accurate.
Enable staff login only after the employee record is ready and the role has been reviewed.
Grant the smallest set of permissions needed for the staff member job function.
Temporary passwords must be changed by the staff member before normal self-service use.
Staff can use attendance, leave, timetable, payroll, and account pages only where the role allows access.
Payroll generation, salary slip review, and status updates should follow the payroll lifecycle and approval expectations.
Validation and system feedback
- Staff login access must reference an active employee from the authenticated school.
- Email and contact values should not be duplicated unnecessarily when the employee master already stores them.
- Password rules are enforced during first-login change and later password updates.
- Permission checks run server-side even when sidebar entries are hidden.
Common mistakes to avoid
- Giving a broad admin-like role to ordinary staff.
- Leaving temporary passwords unchanged.
- Expecting staff to see global search without student access permission.
- Changing payroll state outside the payroll workflow.
Recommended next steps
Screenshot plan
Final public screenshots will use synthetic QA data only. Sensitive values such as names, phone numbers, emails, admission numbers, document numbers, credentials, cookies, tokens, and internal IDs must be removed or redacted.
Important safety notes
Use normal Schoolixa workflows
Public docs explain user workflows only. They do not expose internal IDs, direct database operations, credentials, provider prompts, or private system configuration. Permission visibility in the interface does not replace server-side permission checks.