# Admin (https://docs.akollo.com/en/modules/admin)



**Admin** is where owners and administrators set up the organisation: its structure of units and teams, its members, the roles they hold and the permissions that decide which pages and modules each person can use. It also holds devices, usage, access reviews and the audit records. **Admin** sits in the **General** group at the bottom of the sidebar, above **Settings** and **Help**, and appears only if you may open at least one of its pages.

## Who uses it [#who-uses-it]

| Role          | What they do in Admin                                                                                                                                           |
| ------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Owner         | Everything an administrator does, and manages administrators.                                                                                                   |
| Administrator | Creates units and teams, invites members, assigns roles and permission sets, sets manager scopes, runs access reviews, reads audit records.                     |
| Manager       | Usually nothing here. A manager’s reach comes from a role and a **scope** that an administrator gives them. Some managers review access items assigned to them. |
| HR            | Maintains people and units when their role allows it; HR settings are under [Settings](/en/modules/settings#human-resources).                                   |
| Auditor       | If your organisation creates such a role, reads audit records and reports without changing anything.                                                            |
| Employee      | Does not see Admin, except pages a permission explicitly opens for them.                                                                                        |

## Main screens [#main-screens]

Admin pages are tabs at the top of the page. Pages that do not fit are under **More**.

| Screen                                                            | What it shows                                                                                                                                                                                                                                                                                               |
| ----------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Organisation admin**                                            | Counters for units, active members (and how many have no unit), active delegations and open access reviews; a **People per unit** chart; a **Waiting** panel with joiners and leavers awaiting approval, review items assigned to you and external access ending within 14 days; links to every admin page. |
| **Tracking settings**                                             | The recording policy: schedule, screenshots, idle, retention and category rules. See [Settings](/en/modules/settings#recording-settings).                                                                                                                                                                   |
| **Users**                                                         | Members with their role and joining date, pending invitations and **Invite Members**.                                                                                                                                                                                                                       |
| **Roles**                                                         | The roles in order, with level, members and description, and **Create Role**.                                                                                                                                                                                                                               |
| **Devices**                                                       | Enrolled desktop apps with their employee, version, enrolment date, last seen, status and the **Revoke** action.                                                                                                                                                                                            |
| **Usage**                                                         | Usage per meter, day by day, with monthly budgets and **Download CSV**.                                                                                                                                                                                                                                     |
| **Roles & permissions** (More)                                    | Permission sets, assignments, field policies, **Explain access**, the registry and changes waiting for a second administrator.                                                                                                                                                                              |
| **Sign-in**, **Group mappings** (More)                            | Sign-in providers, connected directories and which directory group gives which role or unit.                                                                                                                                                                                                                |
| **External access**, **Access reviews**, **Audit records** (More) | Contractors, access review campaigns and the log of privilege and configuration changes.                                                                                                                                                                                                                    |

<Screenshot src="/screens/en/org-admin.webp" alt="Organisation admin page with counters for units, active members, active delegations and open access reviews, a people-per-unit chart and a Waiting panel" caption="Admin → Organisation admin: units, members, delegations and open reviews at a glance." />

The structure itself is edited in the **People** section: **Units** shows the tree of units and **Org chart** the reporting lines on any date.

<Screenshot src="/screens/en/org-structure.webp" alt="Organisation structure page with a date picker and a units tree of a company, its departments and teams" caption="People → Units: the organisation as a tree of units, on today’s date or any other date." />

## Key tasks [#key-tasks]

### Build the organisation structure [#build-the-organisation-structure]

A unit has a kind: company, region, branch, division, department or team. Teams are units too, placed under their department.

<Steps>
  <Step>
    ### Open the units [#open-the-units]

    Choose **People → Units**, or select **Create unit** on **Organisation admin**.
  </Step>

  <Step>
    ### Create the unit [#create-the-unit]

    Select **Create unit**. Enter the name, choose the kind and the parent unit.
  </Step>

  <Step>
    ### Set the effective date [#set-the-effective-date]

    Enter the **Effective date** and a reason, then select **Create unit**. The unit takes effect from the start of that day in the organisation’s time zone.
  </Step>

  <Step>
    ### Check the result [#check-the-result]

    Pick a date and select **Show** to see the structure on that day. Moving a person to another unit is recorded as a transfer, so their history stays correct.
  </Step>
</Steps>

### Invite members [#invite-members]

<Steps>
  <Step>
    ### Open Users [#open-users]

    Choose **Admin → Users**.
  </Step>

  <Step>
    ### Invite [#invite]

    Select **Invite Members**, enter the email address and choose a role. **Member** is preselected.
  </Step>

  <Step>
    ### Send the invitation [#send-the-invitation]

    Select **Send Invite**. The invitation stays pending until the person accepts it with the same email address. There is no open sign-up.
  </Step>
</Steps>

<Screenshot src="/screens/en/settings-members.webp" alt="Users page with the Members list showing member, role and joined date, and the Invite Members button" caption="Admin → Users: members, their roles and the button to invite more." />

### Create a manager role and give it a scope [#create-a-manager-role-and-give-it-a-scope]

Owner, Admin and Member are built in. A manager is not a fourth built-in role: you create it, then limit it to the people it may manage.

<Steps>
  <Step>
    ### Create the role [#create-the-role]

    Choose **Admin → Roles** and select **Create Role**. Give it a name and a description. Custom roles take their place in the role order between the built-in ones.
  </Step>

  <Step>
    ### Give it permissions [#give-it-permissions]

    On **Roles & permissions**, create or choose a permission set (for example one that approves leave or reviews tasks) and assign it to the role.
  </Step>

  <Step>
    ### Set the scope [#set-the-scope]

    On the workforce page (**Settings → Workforce & recording**), give the manager a scope: which unit or team they may review, and for which dates. Reviewing another person needs both the permission and a valid scope.
  </Step>

  <Step>
    ### Assign the role [#assign-the-role]

    On **Admin → Users**, give the role to the person.
  </Step>
</Steps>

<Screenshot src="/screens/en/settings-roles.webp" alt="Roles page listing the default Owner, Admin and Member roles and custom roles with their level, members and description" caption="Admin → Roles: role order, members and the Create Role button." />

### Decide who can use which module [#decide-who-can-use-which-module]

Each module (time, projects, people, customers, finance and so on) publishes the areas and actions it offers. A person can use a module page only when an action of that page is granted to them.

<Steps>
  <Step>
    ### Open Roles & permissions [#open-roles--permissions]

    Choose **Admin → More → Roles & permissions**. The **Registry** lists every area and action the modules publish.
  </Step>

  <Step>
    ### Build a permission set [#build-a-permission-set]

    Select **New permission set** and choose the actions it bundles. Only listed actions can be chosen.
  </Step>

  <Step>
    ### Assign it [#assign-it]

    Under **Assignments**, give the set to a person, a role, a directory group or a service account, optionally for a limited period. Sets with administrative rights wait in **Waiting for approval** for a second administrator.
  </Step>

  <Step>
    ### Check the result [#check-the-result-1]

    **Explain access** shows, for one person, every permission they hold and where it comes from.
  </Step>
</Steps>

<Screenshot src="/screens/en/org-permissions.webp" alt="Roles and permissions page with the sections Waiting for approval, Permission sets, Assignments, Field policies, Explain access and Registry" caption="Roles & permissions: permission sets, who holds them, field policies and changes waiting for a second administrator." />

<Mermaid
  title="How a person gets access to a module page"
  chart="`flowchart LR
A[Module is enabled] --> B[Role or permission set grants an action]
B --> C{Scope covers the people or records?}
C -->|Yes| D[Page appears in the sidebar and opens]
C -->|No| E[Page says it is not available]`"
/>

### Run an access review [#run-an-access-review]

<Steps>
  <Step>
    ### Create the campaign [#create-the-campaign]

    On **Access reviews**, select **New campaign**, choose what to review (a unit, a role, everyone with administrative rights, contractors or service accounts), set the due date and select **Create draft**.
  </Step>

  <Step>
    ### Open it [#open-it]

    Select **Open campaign**. The access in scope is recorded and handed to reviewers, who find it under **My work → My access reviews**.
  </Step>

  <Step>
    ### Download the results [#download-the-results]

    When the campaign closes, download the results as CSV or Excel. See [Organisation and access](/en/product-guide/organisation-and-access#access-reviews).
  </Step>
</Steps>

## Permissions [#permissions]

* **Owners and administrators** cover the whole organisation. An owner can administer administrators; nobody can use Admin to give themselves a role they do not already hold.
* **Changes involving administrative rights**, and loosening a field policy, wait for a second administrator. The person who asked cannot approve their own request. Removing a set or retiring one takes effect at once.
* **Managers** act only within their scope. A role alone does not decide which people a manager sees; the scope does.
* **Sidebar**: each section and page appears only if you may open it. Hiding is a convenience, not the protection: every page checks your access again and says so if you are refused.
* **Support sessions** can read Admin pages but cannot create, change, approve or delete anything. A support session does not inherit an administrator’s access.

## What the AI can do here [#what-the-ai-can-do-here]

Admin pages have no AI that changes access. You can still ask the assistant (**Ask AI**) questions about records you are allowed to see, and administrators decide who may use AI at all, with seats, monthly limits per person and an emergency stop, under **Settings › AI › Access & usage**. AI token use appears on **Admin → Usage**. See [AI access and tokens](/en/ai/access-and-tokens) and [What assistance can see](/en/ai/privacy).

## FAQ [#faq]

<Accordions type="single">
  <Accordion title="Is “manager” a built-in role?">
    No. Owner, Admin and Member are built in. An administrator creates a manager role under **Admin → Roles** and gives the person a scope, for example one department.
  </Accordion>

  <Accordion title="Why can’t a manager see someone in another team?">
    Seeing or reviewing another person needs both the permission and a scope that covers that person on that date. Extend the manager’s scope if they should see more.
  </Accordion>

  <Accordion title="Can I give myself a higher role?">
    No. You cannot grant yourself a role you do not already hold, and changes involving administrative rights need a second administrator.
  </Accordion>

  <Accordion title="Why is a module missing from someone’s sidebar?">
    Either the module is not enabled for the organisation, or none of its actions is granted to that person. Use **Explain access** on **Roles & permissions** to see what they hold and where it comes from.
  </Accordion>

  <Accordion title="What happens to a person’s history when they move to another team?">
    The move is recorded as a transfer with an effective date. Reports and the org chart show the structure as it was on each date.
  </Accordion>

  <Accordion title="Can a connected directory make someone an administrator?">
    Not on its own. Directory changes run as joiner, mover or leaver cases, and a change that would make someone an administrator or owner waits for an approver.
  </Accordion>
</Accordions>

## Related [#related]

* [Organisation and access](/en/product-guide/organisation-and-access)
* [Settings](/en/modules/settings)
* [Security and administration](/en/trust/security)
* [Desktop app and devices](/en/product-guide/desktop-app)
* [People](/en/product-guide/people)
* [AI access and tokens](/en/ai/access-and-tokens)
