System Administrator Guide
This guide is for system administrators responsible for configuring global settings, role-based security permissions (RBAC), multi-site configurations, and audit oversight in BonardaHR.
1. Role-Based Access Control (RBAC) & Permissions​
BonardaHR features a granular permissions engine that governs what each user role can view, create, edit, or delete.
Managing Roles & Permissions​
- Navigate to Access Control → Roles.
- Select an existing role (e.g.,
HR_MANAGER,LINE_MANAGER) or click + Create Custom Role. - Toggle permission check-boxes organized by domain:
- Employees: View all, view department only, create, update personal details, update compensation.
- Attendance: Approve timesheets, modify punch records, edit policies.
- Time Off: Approve team requests, adjust leave balances, create holiday calendars.
- Documents & E-Sign: Send envelopes, upload company files, view confidential archives.
- System: View audit logs, edit global settings, use impersonation mode.
- Click Save Permissions. Changes take effect on the next token refresh or session reload.
2. Sites, Locations & Holiday Calendars​
Setting Up Multi-Site Offices​
- Go to System Config → Sites & Locations.
- Click Add Site to define physical branches (e.g., London HQ, Berlin Tech Hub, New York Office, or Remote).
- Set timezones, currency, and local working hour defaults.
Configuring Public Holiday Calendars​
- Go to Admin → Holiday Calendars.
- Assign calendars to specific sites (e.g., UK Bank Holidays for London, Federal Holidays for US).
- When employees request time off, dates falling on official public holidays are automatically recognized as non-working days and are not deducted from annual leave quotas.
3. Custom Profile Fields & Dynamic Sections​
BonardaHR allows admins to create custom data fields without modifying database schemas:
- Go to System Config → Custom Fields.
- Select the target profile section (e.g., Personal Information, Work Equipment, Uniform Sizes, Certifications).
- Click Add Field and configure:
- Field Label (e.g., "Laptop Serial Number").
- Field Type: Text, Number, Dropdown Select, Multi-Select, Date, Toggle, or File Attachment.
- Visibility & Editability: Who can view (Employee, Manager, HR only) and who can edit.
- Required / Optional.
- Save to immediately update employee profile forms across the system.
4. Admin Impersonation Mode (Support Troubleshooting)​
For diagnosing user issues or testing permission configurations:
- System administrators with
ADMIN_IMPERSONATEprivileges can search for any employee. - Click Impersonate User.
- A persistent top banner indicates you are viewing the application from that user's perspective.
- All actions performed during impersonation are securely tagged in the system audit logs with your real admin identity.
- Click Exit Impersonation to return to your normal administrator view.
5. Security & System Audit Logs​
- Navigate to Admin → Audit Logs.
- Filter logs by Date Range, Action Type, Actor, or Target Record.
- Review full historical change records (e.g., salary updates, permission changes, timesheet overrides, and document access).