An administrator runs the organisation. That is not an honorary title: by default they see hourly rates, produce the pre-payroll and read the audit trail.
Which is why the form ends in a row of switches. “Administrator” is not a block to take or leave: it is a base you carve up, right by right, at the moment of the invitation.
Before you start
- Being the account holder, or an administrator with the “Manage members and access” permission.
- 1
Pick the right role before you start
“Team → Admins” lists the people who administer the organisation. The button opens a blank record: but before filling it in, ask yourself the question of the role.
A supervisor runs a crew: they approve hours, they touch neither decrees nor billing. An administrator starts with full access. Getting the role wrong here costs more than getting one permission wrong.
Administrator accounts are free, up to ten per account, more than enough for a real management team. At the eleventh, the application invites you to write to us: raising the limit is free as well, it simply goes through our team.
The three lists (admins, supervisors, employees) live under the same “Team” section. - 2
Identity and invitation
The email serves twice: it is the login, and the address the invitation goes to.
Leave the password empty. The box on the right says it: with no password entered, the person gets an email and picks their own. You never have to know somebody else's password.
The “Username” field is for the case where the person has no usable email address. - 3
Position, and a reminder of scope
The position is a free label; the department is required: it is the person's attachment inside the organisation.
The green box under those fields repeats what “administrator” means. It is there because this is the last chance to turn back before handing out rights.
“In post since” dates the access, not the hire: this is an administration record, not a payroll one. The alternative is named explicitly: for limited access, a supervisor is what you create. - 4
Set the permissions
Rights are grouped into four families: operations and field, commercial relations, confidentiality and finance, administration and security. Each switch carries its own explanation: what it opens, and what remains possible without it.
Note how several of those helps are worded: without the right to manage schedules, “the calendar stays readable, but read-only”. Removing a right does not hide the screen, it takes your hand off it.
Only the account holder sets these switches: and they cannot remove their own. The switch's help says exactly what disappears, and for whom. “See financial data” goes further than a mask
Without that permission, amounts are not merely hidden on screen: the server does not send them. That is the difference between greyed-out information and absent information: the one that counts if someone opens their browser's developer tools.
- 5
Carve up access to the audit trail
Giving access to the log does not oblige you to show everything. Categories are ticked one by one: schedules, timesheets, team records, clients, projects, payroll and decrees, accounts and settings, billing.
What is not ticked appears neither on screen nor in the files this person exports.
“Untick all” is the starting point when access has to stay very narrow. - 6
Create the account
Saving creates the record and sends the invitation in the same move. The chosen permissions apply from the first login: there is no window during which the person would see more than intended.
Permissions can then be changed at any time from the same record. - 7
Check
The person appears in the list with their position and status. Until they open their invitation, the account stays pending: the record exists, the access is not yet live.
The trash, next to “Active”, keeps revoked accesses rather than erasing them.
What to remember
Every permission change is logged
Changing someone's rights writes an entry in the audit trail, with the count of permissions granted and the number of audit categories made visible. Nobody grants themselves access in silence.
Removing access does not erase the person
A removed administrator goes to the trash: their record and their audit trace remain. That is deliberate: a log whose authors can be made to disappear is worth nothing in an inspection.
The account holder stands apart
The holder is the only one who can set these switches, and they cannot remove their own rights. That is what keeps an organisation from ending up with nobody able to take back control.
Go further
Adding an employee
Create a complete record in one pass: identity, attachment, decree class, and the invitation that lets the person punch their hours.
LireReading and exporting the audit trail
Find who did what and when, narrow the search to one person, one action or one record, then pull the log out for an inspection.
LireCan't find what you're looking for?
Our team can answer your technical questions and support your rollout.

