Understanding roles and permissions
How role-based access works in Dapplon
Every user in Dapplon is assigned a role. The role determines which modules they can access, which records they can view or edit, and which actions they can take. Roles are scoped per panel — the same person can have different roles in the admin panel and the job portal.
Built-in roles
Super Admin — unrestricted access to all modules including billing, settings, and role management. Assign this only to the primary IT or HR owner.
HR Admin — full access to employee management, payroll, leave, attendance, recruitment, and reports. Cannot change billing or system-wide settings.
HR Manager — can view and edit employees in their assigned department only. Can approve leave for their team. Cannot access payroll details of other departments or run payroll.
Recruiter — access to the Recruitment module only. Can post jobs, manage candidates, schedule interviews, and send offer letters. Cannot view salary data.
Finance — read-only access to payroll reports, cost reports, and invoice downloads. Cannot edit employee profiles or run payroll.
Employee (Employee Portal role) — can view their own profile, payslips, and leave balance. Can apply for leave and submit expense claims. Cannot see any other employee's data.
Checking what a role can do
- Go to Settings > Roles & Permissions
- Click on any role name to see the full permissions matrix
- The matrix shows each module with the access level: None, View, Edit, Full Control
Creating a custom role
- Go to Settings > Roles & Permissions
- Click Create Custom Role
- Name the role (e.g., "Payroll Specialist")
- In the permissions matrix, set access for each module
- Click Save Role
- Assign the role to users under Settings > Users
In this section
- Inviting your HR team and setting permissions
- Logging in to Dapplon
- Setting up two-factor authentication