Protect system roles, super-admin continuity, impersonation, password resets, company settings, SMS configuration and audit views behind explicit administration permissions.
Admin safeguards
Protect system roles, super-admin continuity, impersonation, password resets, company settings, SMS configuration and audit views behind explicit administration permissions.
Rules prevent accidentally removing the final active super-admin.
Built-in roles cannot be deleted like disposable custom roles.
SMS, audit and settings areas require dedicated permissions; company backups are an Enterprise plan feature managed under company settings.
Critical access cannot be removed accidentally.
Built-in roles stay available as a stable access foundation.
Five failed attempts lock an account until the next successful sign-in.
Admin resets set a must-change flag, so the user picks their own password on the next sign-in.
User impersonation is controlled and logged — and platform-operator assistance inside a company is a separate, equally audited path.
Sensitive areas are protected by narrow permissions instead of broad access.
Protect system roles, super-admin continuity, impersonation, password resets, company settings, SMS configuration and audit views behind explicit administration permissions.
Every view stays structured and reviewable — nothing hides behind a tab.
The system protects at least one active super-admin account.
Default roles are protected while custom roles remain editable.
Impersonation is permission-gated and leaves a security trail.
Company settings, SMS management and audit views are separately gated, with Enterprise-plan backups living under company settings.
No. System roles are protected.
No. Roles assigned to users should be unassigned first.
Yes. High-impact actions such as impersonation should leave audit history.
Map your current workflow to the right HRM setup, permissions and rollout plan.