How-to
Administrator permission best practices
On this page
Administrator permissions provide powerful access to organizational data and system configuration. Assigning these permissions thoughtfully helps maintain data security, accountability, and efficient system administration.
This article outlines recommended practices for assigning and managing Administrator access within your organization.
Grant Administrator access only when required
Administrator access should be assigned only to users who are responsible for managing specific business functions or system configurations.
Before granting Administrator access, consider whether the user genuinely needs administrative privileges or can perform their responsibilities using Manager or Employee access.
Follow the principle of least privilege
Grant only the permissions required for a user's role.
For example:
- Payroll administrators may require access to Payroll and Employee modules.
- Leave administrators may require access only to Leave Management.
- Recruitment teams may require access only to the Hiring and Onboarding modules.
Avoid assigning unnecessary permissions simply for convenience.
Restrict access wherever possible
If an Administrator is responsible for only a specific part of the organization, restrict their access accordingly.
Administrator access can be restricted by:
- Location
- Legal Entity
- Business Unit
These restrictions help ensure that administrators can manage only the employees relevant to their responsibilities.
Review Administrator access regularly
Administrator permissions should be reviewed periodically to ensure they remain appropriate.
Consider reviewing access whenever:
- An employee changes roles.
- An employee transfers to another department.
- An employee leaves the organization.
- Organizational responsibilities change.
Removing unnecessary administrative access reduces security risks.
Avoid sharing Administrator accounts
Each Administrator should use their own employee account.
Avoid sharing login credentials between multiple users, as this makes it difficult to identify who performed administrative actions and may compromise account security.
Keep the Super User account protected
The Super User represents the highest level of authority within the organization.
As a best practice:
- Use the Super User account only when necessary.
- Perform day-to-day administrative activities using dedicated Administrator accounts.
- Limit knowledge of the Super User credentials to authorized personnel.
This helps protect the organization's primary administrative account while maintaining clear accountability for routine administrative activities.
Maintain clear administrative responsibilities
Where multiple Administrators exist, assign responsibilities based on business functions.
For example:
- HR Administration
- Payroll Administration
- Recruitment Administration
- Attendance Administration
Clearly defined responsibilities help avoid duplication of work and reduce the risk of unintended configuration changes.
Frequently asked questions
What are the best practices for assigning Administrator access?
Administrator access should be granted only to users who require it, with permissions limited to their responsibilities and reviewed regularly.
Why should Administrator access be restricted by Location, Legal Entity or Business Unit?
Restricting Administrator access ensures users can manage only the employees and data relevant to their responsibilities, improving security and reducing the risk of unintended changes.
Should multiple employees share the same Administrator account?
No. Each Administrator should use their own employee account to maintain security and accountability.
How often should Administrator permissions be reviewed?
Administrator permissions should be reviewed whenever roles or responsibilities change and as part of periodic access reviews.
Is it recommended to use the Super User account for day-to-day administration?
No. As a best practice, routine administrative tasks should be performed using dedicated Administrator accounts, while the Super User account should be reserved for exceptional situations.