Module · in every plan

System Administration

Control who can do what, and keep a record

As a company grows, access tends to spread quietly and sensitive details end up on the wrong screens. DeeHr360 makes every change to access a request that someone else signs off. You choose who may see each sensitive field, and every action is logged.

How it works

5 steps, from start to finish

  1. Set up roles

    Create roles that are separate from job positions, so a promotion never brings access that nobody decided to give.

  2. Propose access changes

    Tick permissions for a role or roles for a person, see what would change, then submit it for approval.

  3. Approve through chains

    Changes go through approval chains you design, with rules that pick a chain and steps for a manager, unit head, role, position or named person.

  4. Protect sensitive fields

    Choose which roles may see fields such as national ID, salary or bank account, and how each field is masked for everyone else.

  5. Review the audit trail

    Look up who did what, when and from where, along with every sign-in attempt.

What it does best

Built for the way HR really works

Access changes need approval

Changes to a role's permissions or to who holds a role are staged first, and the old access stays until the change is signed off.

Configurable approval chains

Each type of request, such as leave, transfers, payroll runs or asset requests, has its own rules and ordered approval steps.

Approve, reject or return

Approvers work from one inbox and can approve, reject or send a request back for changes, and you decide how self-approval is handled.

Field-level masking

Sensitive values are hidden, partly shown, reduced to the year or left out, depending on the viewer's role, and everyone sees their own record in full.

Controlled integrations

Register outside apps with their own tokens, allowed IP addresses, integration points and rate limits, such as careers pages or clocking devices, and suspend them at any time.

Bulk uploads with a dry run

Upload employees, structure, salaries, leave balances and more from spreadsheet templates, with a preview of errors before anything is saved.

What's included

Everything in System Administration

  • Roles & PermissionsCreate roles, propose permission and role-holder changes with a preview of what changes, and apply them only after approval.
  • IntegrationsRegister outside apps, issue and revoke tokens, restrict IP addresses and integration points, and review the calls each app makes.
  • ApprovalsOne approval inbox, plus chains for each request type, using rules and steps for managers, unit heads, roles, positions or named people.
  • Data ProtectionA grid of roles against sensitive fields, with a classification and masking choice for each field.
  • SettingsSeparate view and update rights for settings, so only the roles you choose can change them.
  • AuditA searchable log of every action by user, module and type, plus sign-in attempts and who is online now.

Who uses it

Each person sees their part

Administrators

Manage roles, permissions, integrations and sensitive-field access, and review the audit logs.

HR

Design approval chains and bulk-upload records when moving from another system.

Managers

Approve, reject or return the requests waiting in their approvals inbox.

Employees

Follow the requests they have raised and cancel them before a decision is made.