As an administrator, specify whose entries a manager user can view and manage in the browser. Permissions are granted to a manager role. The users whose entries can be managed are selected separately based on their manager or mobile roles, or access can be permitted for all users.

Using general working time requires the working time feature to be enabled in your service. Saving permissions does not enable the feature. When the working time feature is enabled, this configuration also grants the selected permissions for the selected users' travel expenses.

Select the users who will manage entries and open the permission settings

  1. In the browser's main menu, open User management → User roles.
  2. Open the manager role for the users who will manage entries by clicking the pencil icon on its row. If you need a new role, see configuring manager user permissions.
  3. In the Users section of the Manager user role tab, check that the role includes the users who need these permissions.
  4. Make sure Role grants permissions for folders and other content is selected. This opens the permission settings.
  5. On the same tab, go to the Manager's content rights section, open Other management and find the Working time monitoring row.

The role's Users section determines who receives the permissions. The role selection on the Working time monitoring row determines whose entries those permissions apply to. Selecting a target role does not add its users to the role receiving the permissions.

Select whose entries can be managed

In the role selection field on the right of the Working time monitoring row, select the manager and mobile roles whose members' entries need to be managed. You can select multiple roles. The scope follows membership of the target roles: adding a user to a target role or removing them from it also changes the set of users included in the scope.

Alternatively, select Permit all on the same row. This includes all users and disables the role selection field. This option does not itself select the Create, Read, Edit or Delete permissions. When you clear the option permitting all users, check the target roles again.

For example, select the supervisors in the Users section of the supervisors' manager role. On the Working time monitoring row, select the installers' mobile role as the target role. This grants the supervisors the selected permissions to manage the installers' entries.

Select the actions you need

  • Read grants permission to view the selected users' entries.
  • Create grants permission to create entries. However, note the limitation on restricting creation described below.
  • Edit grants permission to correct entries within the limits allowed by their status. Approving general working time entries, revoking their approval and marking them as processed are based on this permission.
  • Delete grants permission to delete entries that have neither been approved nor marked as processed.

The interface automatically selects Read when you select a target role or select Edit or Delete. Check the final checkbox selections after changing the scope and actions. If you use Select role template in this section, also check the working time permissions afterwards: the template may change them.

Restricting creation: Clearing Create alone does not guarantee that adding new entries is prevented. Creating an individual entry in the browser and creating general working time entries in bulk check whether the target user is permitted, but do not check the Create selection as part of this check. For example, it may therefore be possible to create entries for a user within the scope without Create being selected. Do not rely solely on clearing this option to prevent creation.

Consider work permissions and entry statuses

Approving task and service request entries, revoking their approval and marking them as processed require permission to edit the relevant task or service request. Edit on the Working time monitoring row alone is not sufficient for these actions. Ordinary corrections and deletion are checked separately against the entry's permissions.

An unapproved entry with the status Completed can be approved. An entry in progress cannot be approved. For a completed and approved entry, approval can be revoked or the entry can be marked as processed.

You cannot directly correct the contents of an approved entry or delete it. Revoke approval and save first; make the correction on the next save. A Processed entry is locked: its contents or status cannot be changed, its approval cannot be revoked and it cannot be deleted. Granting broader permissions does not remove these locks.

For instructions on performing these actions, see approving time entries, correcting and deleting a time entry and the working time report and marking entries as processed.

Check all of the user's permissions

The scope of one role does not guarantee that the user's overall permissions are limited to that scope. Check all roles and other permissions granted to the user managing entries. The target user sets in working time permission configurations may be combined when permissions are built, allowing an action permission from another configuration to extend to users targeted by an earlier configuration. Do not assume that combinations of actions and target roles assigned through different roles remain separate.

The user managing entries may also have permissions for their own entries and their tasks or service requests on other grounds. Clearing the Working time monitoring row therefore does not mean that all permissions for entries are removed. Testing with an administrator account also does not demonstrate whether the manager's permissions work.

Save and verify the result

  1. Click Save at the bottom of the role form.
  2. Reopen the same role using the pencil icon. Check the users who will manage entries, the action selections on the Working time monitoring row, the target roles and the Permit all selection. The role's success message alone does not confirm that the working time permission configuration was saved, because these are saved separately.
  3. Using the account of a user who will manage entries, open Working time monitoring from the main menu. Check that an entry belonging to the intended target user is visible, and test the required action on an entry with a suitable status.
  4. Also check a user outside the scope. If visibility or action permissions are broader than expected, review all roles of the user managing entries and the members of the target roles.

Changing permissions does not itself change entry times, approval or processing status, or delete entries. If you clear Role grants permissions for folders and other content and save, the role's previous working time permission configuration is also deleted. This option affects the role's other content permissions as well; do not use it to remove just one working time action.

This configuration is made in the browser. On Android and iOS, editing and deleting entries are limited to the user's own entries; the manager role's target scope does not grant permission to edit other users' entries on mobile. Entry status locks also apply on mobile. Recording working time and configuring working time rules are separate tasks: see recording working time and working time rules and entry types.