People & access

Access that matches the job.

One role called "admin" is why companies end up giving their accountant the keys to everything. Spyne gates every action separately, so you can hand out exactly the access somebody's job needs and nothing beyond it.

30 days free · no card · your data exports whenever you want it

The roles and access screen listing custom roles with the permissions each one grants
Roles you define, built from individual permissions.
The problem

Most systems offer admin or not-admin. So the office manager who tracks laptops gets access to salaries, and the accountant who reconciles payroll gets the ability to issue it. Nobody wants that; the software just left no other option.

How it works

Profiles, roles and who can see what

Start from the defaults

Owner, Administrator, HR Manager, Finance, Team Lead, Office Manager and Employee come ready-made — real jobs, not an abstract ladder.

Tick what the job needs

Roles are built from individual permissions, grouped by module. The ones that expose salary or move money are flagged so nobody hands them out by accident.

Invite people into it

An invitation email, a password they set themselves, and access from the moment they accept.

Profiles

The details payroll and compliance need

Employee number, designation, joining date, bank details, PAN, Aadhaar, UAN and PF number — held once, used by the payslip, the exit checklist and the statutory deductions.

  • Sensitive identifiers are encrypted at rest
  • Bulk import from a spreadsheet, with a template to start from
  • Export the whole filtered list as CSV
The employee list showing names, designations, joining dates and roles
The team, with the details every other module reads.
Security

Two-factor, and who can turn it off

A six-digit code by email, valid for ten minutes and usable once. Three wrong codes locks the account, and only somebody with the security permission can unlock it — because a person whose mailbox has stopped working cannot fix their own second factor.

  • Per person, or required company-wide
  • Lockouts are announced to admins rather than discovered
  • Every change is told to the person it affects
Creating a new role, with permissions grouped by module and sensitive ones flagged
Building a role. Permissions that expose pay are marked as such.
Why it matters

What changes when you run it this way

Per action, not per module

Reading payroll and running payroll are different permissions, because they are different jobs. Same for seeing invoices and raising them.

The menu matches the door

The navigation is built from what you can actually do. A link that answers "forbidden" teaches people the product is broken; Spyne simply does not show it.

Everyone keeps the basics

Whatever role somebody holds, they can always check in, request leave, read their own payslips and track their own KPIs. Without that the product is unusable for them.

Two-factor when you want it

Email one-time codes, switched on per person or required for everyone. A locked-out colleague is unlocked by an admin, not by a support ticket.

More of it

Other screens in people & access

The invite employee form with name, email and role
Inviting somebody. They set their own password.
An employee's own profile screen
What each person can see and manage about themselves.
The detail

People & access at a glance

What people & access supports in Spyne today.
Default rolesOwner, Administrator, HR Manager, Finance, Team Lead, Office Manager, Employee
GranularityPer action — around 40 distinct permissions
Two-factorEmail one-time code, 10-minute validity, single use
LockoutThree wrong codes; unlocked by an admin
Import / exportCSV and Excel, with downloadable templates
Questions

Before you ask us

Can we create our own roles?

Yes. The seven defaults are a starting point, not a cage — you can edit any of them or build a role from scratch out of individual permissions.

Can somebody read payroll without being able to run it?

Yes, and that is the reason the permissions are per action. "See everyone's payslips" and "run payroll and issue payslips" are separate ticks.

What can an employee with no role at all do?

Check in and out, request leave, read their own payslips, work their own tasks and track their own KPIs. Everything else is closed until a role opens it.

Is two-factor authentication available?

Yes — a six-digit code by email, valid for ten minutes and usable once. It can be enabled per person or required for the whole company.

Connected

What people & access touches

These are not separate products. What you record in one is what the next one reads.

See it with your own numbers in it

Start a trial and generate a full sample company in one click — three months of attendance, payroll, invoices and projects, all joined up. Then delete it and start for real.