Team & roles

Access for DA KINGS Financial Services. You are previewing StaffPay as: Company Owner.

Team members

A user may belong to more than one company

NameEmailRoleStatusTwo-factorActions
Thapelo Kgabagethapelo@dakings.example.co.zaCompany Owner
Active
Enabled
Nomsa Dlamininomsa@dakings.example.co.zaPayroll Administrator
Active
Optional
Chantelle Naidoochantelle@dakings.example.co.zaPayroll Reviewer/Approver
Active
Optional
Lerato Mahlangulerato@tellulahwater.example.co.zaHR Administrator
Active
Optional
Sibusiso Mthembusibusiso@dakings.example.co.zaPayroll Bureau Administrator
Active
Optional
Andre Fourieauditor@external.example.co.zaRead-only Auditor
Pending
Optional
Wandile Ngcobowandile@dakings.example.co.zaEmployee Self-Service
Active
Optional

Role permissions

Least privilege with maker-checker separation

RoleAccessRestriction
Platform Super AdministratorPlatform, subscriptions, system healthNo unaudited payroll access
Company OwnerEverything in the company, including approvalFull
Payroll AdministratorCapture inputs, calculate, prepare declarationsCannot approve own run
Payroll Reviewer/ApproverReview, approve, sign off statutory exportsCannot capture inputs
HR AdministratorEmployees, leave, documentsNo banking or PAYE edits
Employee Self-ServiceOwn payslips, leave and documentsOwn record only
Read-only AuditorRead-only across payroll and audit logNo changes, masked identifiers
Payroll Bureau AdministratorAssigned client companiesScoped to assigned clients

Capability matrix

The authority actually enforced in every module — capture is separated from approval

RoleAdd / edit companiesAdd / edit employeesCapture payroll inputsApprove & release payrollCapture leaveApprove / decline leaveManage document vaultDownload reportsManage statutory filingPlatform administration
Platform Super Administrator
Payroll Bureau Administrator
Company Owner
Payroll Administrator
Payroll Reviewer/Approver
HR Administrator
Employee Self-Service
Read-only Auditor

Roles are stored separately from user profiles to prevent privilege escalation. Role changes, elevations and sensitive data reveals are written to the immutable audit log.