Working as staff

For a member of staff who is not an administrator: signing in, what your role lets you see, and the parts of the panel that are yours alone.

The panel as somebody on the Employee role sees it: a short menu, and a dashboard with only the panels the role allows. The panel as somebody on the Employee role sees it: a short menu, and a dashboard with only the panels the role allows.

Who this section is for

These pages are for the people who use the CRM every day but do not run it: somebody whose role is not Administrator. They describe the panel as you will see it — which is usually much shorter than the one in the rest of this manual — and why. For the full detail of a screen, each section links to the page that describes it for everybody (the CRM admin panel pages).

Signing in

The staff sign-in page at /login. The staff sign-in page at /login.

Your workspace has its own address, which whoever set up your account will have given you. Go to /login on that address, type your Email address and Password, and press Sign in. Tick Keep me signed in on a computer that is yours alone. You land on your dashboard. The sign-in page is described in full under Signing in.

The customer portal has a sign-in page of its own, at /portal/login. That one is for your customers' contacts; a staff account signs in at /login.

Other ways in

A forgotten password

Reset your password: the page behind Forgot password?. Reset your password: the page behind Forgot password?.
  1. On the sign-in page, press Forgot password?.
  2. Type your Email address and press Send reset link. The page says If that address belongs to an account, a reset link is on its way. whether or not it does, so it cannot be used to find out who has an account.
  3. Open the link in the email within an hour. Type a New password twice and press Save new password.
  4. You are sent back to the sign-in page: Your password has been reset. Please sign in.

No email arrives for an account that has been deactivated. If that is you, ask an administrator: nothing on the sign-in page can switch an account back on. Customers use the same page from the portal sign-in, and are sent back there afterwards (see Getting into the portal).

To choose a new password while you are signed in, use My account.

Your role

Everything you can see and do is decided by the role an administrator gave you, shown under your name at the top right. A role is a list of modules (Leave, Invoices, Tickets…), and for each one two things:

ScopeWhat you see
All recordsEvery record in the workspace.
Their teamsRecords owned by anyone on the same team as you, and your own.
Assigned to themOnly the records you are assigned to.
Their clientsRecords belonging to the customers you manage: those whose Account owner you are, or where you are Also on the account.
Their own recordsOnly the records you created or own.
No accessThe module is hidden from you entirely.

So two people can open the same screen and see different lists: with Their own records on leave, the leave screen lists your requests only; with All records, everybody's. Nothing about the screen tells you what is outside your scope, which is the point of it.

The Employee role, as shipped

Every workspace starts with three roles: Administrator, Manager and Employee. Employee is described as Sees their own team and nothing else. Out of the box it gives:

ModuleAbilitiesScopeIn practice
StaffViewTheir teamsA read-only list of the colleagues who share a team with you.
AttendanceView, CreateTheir own recordsClock yourself in and out, and see your own shifts.
LeaveView, CreateTheir own recordsAsk for leave, see your balance and your own requests.
AnnouncementsViewAll recordsRead the notices addressed to you.
Team timelineView, CreateAll recordsRead the timeline, post and reply.
Internal wikiViewAll recordsRead the wiki.
AI assistanceUse the AI features, Use the assistantAll recordsThe Ask AI assistant, when the workspace has AI set up.
CalendarView, CreateAll recordsYour calendar, and events of your own.
GoalsViewAll recordsThe goals that are yours, your team's or the company's.
MessagesCreateAll recordsStart a conversation with anybody on the staff.

And nothing else. As shipped, an Employee has no leads, customers, quotes, invoices, projects, tasks, timesheets, tickets, knowledge base, files, surveys, campaigns, reports or settings. That is a starting point, not a verdict: the usual next step is to give each person the modules their job needs — a support agent the tickets, a developer the tasks and projects — either by changing the Employee role, by making a new role, or by overriding one person's permissions on top of their role. That is done by an administrator under Organisation → Roles and on your staff record; see Roles and permissions. What you do with those modules once you have them is on Your own work.

The Manager role, as shipped, sees everybody's attendance and leave, approves leave, writes announcements and the wiki, adds staff, makes teams and reads the activity log; see Running a team.

How the panel shrinks to your role

The menu down the left shows only what your role reaches. An item you have no access to is left out, and so is a heading with nothing left under it. With the Employee role as shipped, the whole menu is:

HeadingItems
—Dashboard
Supports & TicketsWiki, Pages
Human ResourcesAttendance, Leave, Goals, Calendar, Timeline, Messages, Announcements
OrganisationStaff

Compare it with the full menu under The menu: the CRM, Sales & Invoicing, Projects & Deliveries and Marketing & Communications headings are gone altogether. A few items need no permission at all and are there for everybody: Dashboard, Pages (the staff-only pages your business has published, such as a handbook; see Pages and the website menu) and Messages. Staff comes with the View ability on staff. Activity — the log of every change in the workspace — needs more: seeing all of the staff, not only your own team, because the log is as sensitive as every record in it. The Manager role has that; the Employee role does not.

Staff for an Employee: the colleagues who share a team with them, with nothing to add or edit. Staff for an Employee: the colleagues who share a team with them, with nothing to add or edit.

Two more things take items away for everybody, administrators included: a module your workspace has switched off under Settings → Modules, and an item an administrator has hidden under Settings → Menu. Nothing done to the menu can show you an item your role does not reach.

Buttons that are missing

Inside a screen, each button asks for its own ability, so a screen you may open can still be missing buttons that are in the screenshots elsewhere in this manual. With the Employee role, for example:

If a button you need is missing, it is your role, not a fault: ask an administrator for the ability.

An address you may not open

Typing an address by hand, or following an old link, does not get round a role. You see one of two pages instead of the screen:

You seeWhen
403 — Access denied. You do not have permission to view this page.Your role does not have the ability the screen needs: /admin/invoices for an Employee, say.
404 — Page not found.The record exists but is outside your scope (a colleague's leave request when yours is Their own records), or the whole module is switched off for the workspace. Outside your scope is answered exactly as if the record did not exist, so an address cannot be used to find out what is there.

Your dashboard

Dashboard is where you land. It greets you by name with today's date, then shows panels — and only the panels whose module your role can see. With the Employee role as shipped that is:

The money, leads, tickets, delivery and other panels appear once your role reaches their modules. The dashboard is still yours to arrange: Customise picks and orders the panels you are allowed, and the period menu (This month) changes the dates they cover. You can keep several dashboards of your own; see Reports and dashboards. Nothing you arrange can show you a panel your role does not allow.

My account

My account for an Employee: language and time zone, password, and recent sign-ins. No signature card, because the role cannot sign for the business. My account for an Employee: language and time zone, password, and recent sign-ins. No signature card, because the role cannot sign for the business.

Open the menu under your name at the top right and choose My account. Everybody has it, whatever their role; nothing on it changes what you may do. The card on the left shows your name, email address and role. Only an administrator can change your name, email or role, on your staff record.

Each is described in full under My account.

The top bar

The top bar is the same for everybody; what is behind each button follows your role. The control-by-control list is under The top bar.

Search as an Employee: the only kind of record the role can open is the wiki, so that is all it finds. Search as an Employee: the only kind of record the role can open is the wiki, so that is all it finds.

The box at the top (/ jumps to it) searches every kind of record your role can view, and within each only the records in your scope — the same records the list would show you. A kind of record you cannot see is not searched at all, rather than searched and then hidden. With the Employee role as shipped, that leaves the Wiki: searching for a customer finds nothing, however many there are. See Search, filters and bulk actions.

Messages, reminders and the bell

My list and Starred

Ask AI

When your workspace has AI assistance set up, and your role has Use the assistant (the Employee role does), an Ask AI button sits at the bottom right of every screen; Ctrl+K (⌘+K on a Mac) opens it too. The assistant works as you: it reads only what you could open yourself, offers only the actions your role allows, and prepares nothing until you press Confirm. Your conversations with it are yours; nobody else can open them.

Use the AI features is the AI help beside a record — scoring a lead, triaging and drafting a reply to a ticket, summarising a customer or a project. It appears only on those records, so it does nothing for you until your role reaches leads, tickets, customers or projects. See AI assistance.

Addresses on this page

For reference and for anyone scripting against the panel. Everything here needs somebody signed in to the workspace whose role allows it; anybody else is refused.

MethodAddressWhat it does
GETloginThe sign-in page.
POSTloginSigns you in.
GETlogin/{provider}Continue with Google or Continue with Facebook (google, facebook): sends you to the provider. With ?for=portal, from the portal sign-in, for a customer's contact.
GETlogin/{provider}/callbackWhere the provider sends you back, and you are signed in. Used by the page itself.
POSTlogoutSigns you out (Sign out in the menu under your name).
GETforgot-passwordThe Reset your password page, from Forgot password?.
POSTforgot-passwordEmails a reset link, if the address belongs to an active staff or customer account.
GETreset-password/{token}The page the reset link opens: choose a new password.
POSTreset-passwordSaves the new password.
GEThandoff/{token}A one-time link that signs an account in at the workspace's own address, after signing up or on the way into or out of a super admin's Sign in as. Opens without signing in; works once, for two minutes.
GETadminYour dashboard.
GETadmin/accountMy account.
PUTadmin/accountSaves your language and time zone.
PUTadmin/account/passwordChanges your password.
GETadmin/searchThe search results page, for q.
GETadmin/search/previewThe results that drop down under the search box as you type. Used by the page itself.
GETadmin/staffStaff: the colleagues within your scope.
GETadmin/pagesPages: the staff-only pages your business has published.
GETadmin/notifications/feedThe bell's list. Used by the page itself.
GETadmin/remindersYour reminders.
GETadmin/my-listMy list.
GETadmin/starsThe Starred menu. Used by the page itself.
POSTadmin/ai/assistantAsks the assistant a question.