Employees
The Employees area is where you keep the record for everyone who works in your workspace. From here you add new hires, open a person's profile, review their documents, and record transfers and promotions.
Open Employees from the admin sidebar to reach the directory at
/admin/employees. You can search by name, employee code, or email, and filter
by department and status. Use Export CSV or Print to take the current,
filtered list with you.
Adding an employee
- On the All Employees page, click Add Employee (top right). This opens
the form at
/admin/employees/create. - Choose the Portal access mode (see below), then fill in the details across the sections.
- Click Create Employee.
The employee code (for example EMP-0001) is generated for you automatically,
following the format set in your company settings.
Portal access: invite, or admin-managed
The Portal Access card at the top of the form decides how the person's account is set up:
| Choice | What it means |
|---|---|
| Invite to portal (default, recommended) | An activation invitation is emailed. The employee signs in, completes their own personal details in My Account, and submits them for your approval (see Profile approvals). |
| No portal login | Admin-managed — no credentials are created and the person never signs in. HR enters everything, and the record's details count as approved from the start. You can invite them later at any time. |
A no-portal employee still counts as a billable seat on your plan — they
are billed like any other active employee — and an
admin with the impersonation permission can still open the portal as them
(audited) when something needs checking from the employee's side. On the Users
page (/admin/access/users) the membership shows a No portal badge with an
Invite to portal action — enter an email address and the standard
invitation flow upgrades the account whenever you're ready. See
Users, roles & permissions.
Required fields
You cannot save the employee until these are filled in:
| Field | Section |
|---|---|
| First Name | Personal Information |
| Last Name | Personal Information |
| Department | Employment Details |
| Designation | Employment Details |
| Employment Type | Employment Details |
| Joining Date | Employment Details |
| Present Address — Address Line 1, City, Country | Present Address (No portal login records only) |
For an admin-managed ("No portal login") employee, a complete present address — Address Line 1, City, and Country — is mandatory; the form and the server both reject the record without it. For an invited employee the address is optional at creation: the person provides it themselves through their profile submission, and HR approves it with the rest of their details.
Optional details you can add now
- Personal Information — Father's Name, CNIC, NTN, Date of Birth, Gender, Marital Status. A CNIC, if entered, must be unique within your workspace.
- Contact Information — Personal Email, Official Email, Primary Phone (with country code). Official Email is the company-owned work mailbox — all in-employment system emails go there. Personal Email is the person's own address — HR's channel after employment ends, and (under the default sign-in policy) the preferred address for the account invitation.
- Employment Details — Reporting Manager, Daily Reports preference (follow the designation default, or force Required / Exempt), Loans & Advances eligibility, Shift, and Leave Group. Leaving Shift or Leave Group blank falls back to the company/shift default.
- Emergency Contact / SOS — contact name, phone, and relationship.
- Bank Account — pick a bank from the list, then account title, account number, and IBAN. A bank must be selected for the account to be saved.
Hiring through the Recruitment module? Use Convert to Employee on the candidate. It opens this same form with the candidate's name, email, phone, department, designation, and joining date already filled in — you just add the official email, CNIC, address, and bank details.
The account invitation
When Portal access is Invite to portal, creating an employee does not set a password for them. Instead, an invitation email with a single-use activation link (valid for 7 days) is sent, and the person activates their own account:
- Which address is invited is decided by your workspace's sign-in policy under Settings → Workspace → Member accounts. Under the default Flexible policy the invitation goes to the Personal Email, falling back to the Official Email; under Official email only it always goes to the Official Email. If both email fields are left empty, an extra Invitation Email field appears on the form so you can enter an address to invite.
- The invited address becomes the sign-in email. The activation page is bound to exactly that address. A brand-new address chooses a password and is signed straight into the portal. An address that already has an Operentra account (for example from a sister company) enters its existing password instead — your workspace is simply added to that account, and the person can switch between companies from the top bar.
- Until the invitation is accepted, the person shows an Invited badge on the
Users page (
/admin/access/users), with a re-send action if the link expires.
The invitation email is a regular template (trigger employee_invitation,
category Employee Lifecycle), so you can customize its wording under your email
templates.
An invited employee's record starts with its personal details incomplete by design — the person fills them in and submits them for your review from their own account. See Profile approvals below for how those submissions reach you.
An employee created with no email at all gets no invitation. You can still create their login manually from the Users page (with an admin-set password). Adding an email to the profile later does not send an invitation automatically — manual user creation is the path in that case.
Plans, seats and billing
Paid plans bill per employee per month: your bill is your active headcount, floored at your plan's seat minimum. Adding people raises the next invoice instead of hitting a cap — there is no employee ceiling on standard plans.
Creating an employee is still blocked (with a prompt to visit Billing) when your trial has ended or your subscription is canceled — and, only if your provider set an explicit headcount cap on a bespoke deal, when you reach that cap. In that last case the message names the plan and the cap, for example "The Growth plan includes up to 50 employees. Upgrade your plan to add more."
Your Billing page (/admin/billing) shows how many seats you are currently
billed for — including when the plan's seat minimum is doing the work — and
what adding one more employee costs. Deleted employees do not count; only
active records do.
Employee statuses & activation
Every employee record carries a status, shown as a colored badge throughout the directory and profile:
| Status | Badge | Meaning |
|---|---|---|
| New | New (Pending Activation) (amber) | Every record is created in this state — see below. |
| Active | Active (green) | Fully part of operations: payroll, attendance, leave. |
| On Leave | On Leave | Temporarily away on approved leave. |
| Suspended | Suspended | Temporarily barred from duty. |
| Terminated | Terminated | Employment ended by the company. |
| Resigned | Resigned | Employment ended by the employee. |
| Retired | Retired | Employment ended at retirement. |
| Separated | Separated (slate) | Written only by the offboarding module when a final settlement completes — you can never pick it by hand (it shows in the status dropdown only as the current value). See Onboarding & offboarding. |
What "New (Pending Activation)" means
A pending employee is excluded from payroll runs (no salary, no slip), attendance, leave accrual, and headcount reports — but still counts as a billable seat on your plan. You are paying for someone the system is not yet processing, which is exactly why you should not leave people pending.
How an employee becomes active
Activation follows a fixed three-step sequence. Each step can be done while the employee is still pending:
- Assign a salary structure — Payroll → Employee Salaries
(
/admin/payroll/salaries). Pending employees can be assigned a salary; only departed ones (Separated, Terminated, Resigned, Retired) are refused. - Create the employment contract — requires the assigned salary, and the contract form pre-fills from it. See Contracts & HR letters.
- The contract is accepted — either the employee e-accepts it in their
portal (My Contract,
/portal/contract), or HR uses Upload signed copy on the contract. The moment either happens, the employee flips to Active automatically and their pro-rata leave balance for the current fiscal year is allocated.
You can also activate by hand: pick Active from the Status control on the profile. This routes through the exact same activation logic, so it allocates pro-rata leave too.
If your workspace has no current active fiscal year, a manually or automatically activated employee still becomes Active — but their leave balances stay empty until a fiscal year is opened and allocation is re-run.
Where you'll see the pending state
- The employee profile shows an amber "This employee is not active yet" panel with the three-step checklist: done steps are ticked, the current blocking step is highlighted, and each open step carries a button that deep-links to the right screen.
- The Employees directory shows an amber banner — "N employees are pending activation" — with a Show them button whenever any exist and your filter isn't already on them, plus a New (Pending Activation) option in the status filter.
- The edit page shows the status badge next to the title and an amber strip with a See what's needed link back to the profile.
The payroll pre-flight also reports pending-activation employees as a single warning naming them ("will not be paid — still pending activation") instead of raising missing-shift, missing-salary, or missing-attendance blockers for people the run would never pay.
The employee profile
Click any name in the directory to open their profile at
/admin/employees/{id}. The profile gathers everything about the person into
cards:
- Personal Information, Contact Information, and Emergency Contact / SOS
- Employment Details — code, department, designation, employment type, branch, joining date, and reporting manager, plus a Status row (the badge, with an explanatory help icon while the employee is pending activation) and Probation End and Confirmation Date rows
- Shift — the current shift, with Assign Shift / Change Shift and View History
- Leave Configuration — the resolved leave group and each policy's remaining balance, showing whether the group comes from an employee override, the shift, or the company default
- Address, Biometric, and Bank Account
From the profile header you can:
- Change status — the button reads Status:
<current status>. The dropdown offers Active, On Leave, Suspended, Terminated, Resigned, and Retired as targets; New (Pending Activation) and Separated appear only when they are the current value — they are displayed but can never be chosen. Picking Active for a pending employee performs full activation (including leave allocation), not just a label change — see Employee statuses & activation. - Edit the record (opens
/admin/employees/{id}/edit). - Delete the employee (asks for confirmation; this cannot be undone).
You can also upload a photo on the edit screen, which then appears throughout the directory and profile.
Profile approvals (employee-submitted details)
Employees own their personal details. Each person edits their profile — personal fields, addresses, and primary bank account — in their own My Account area, and nothing reaches your employee records until they submit it to your company and you approve it. What you approve becomes your company's verified copy, and from then on only HR edits it — the employee proposes further changes through the same submission flow.
Every employee record carries a profile status:
| Status | Meaning |
|---|---|
draft | Invited to the portal; you are waiting for their first approved submission |
submitted | A submission is sitting in your review queue |
approved | The record holds company-approved data (HR-entered records, and all records that existed before this feature, start here) |
The review queue
Open Profile Approvals (/admin/employees/profile-approvals, permission
employees.update) to see every pending submission. The admin Dashboard
also raises an alert — "N profile submission(s) awaiting review" — that links
straight here.
Each row expands to a field-level diff: only what would actually change on your record is shown, current value against proposed value, including addresses (per type) and the bank account. For each submission you can:
- Approve — the snapshot is copied into your employee record. If the phone number, emergency contact, or an address changed, its verification resets to unverified so your normal verification flows re-run. A submitted bank name that matches your workspace's bank list is linked to the catalog entry automatically, so bank payment files keep working.
- Return — send it back with an optional note. Your record keeps its current data; the employee is told what to fix and can submit again.
A submission holds a snapshot of the person's profile at the moment they sent it — approving applies exactly what you reviewed, even if the person kept editing afterwards.
Two seeded email templates (category Employee Lifecycle) keep both sides
informed: profile_submission_pending notifies users holding
employees.update with a link to the queue, and
profile_submission_reviewed tells the employee the outcome — approved, or
returned along with your note.
Documents & expiry
Open Documents (/admin/employees/documents) and choose an employee to see
all of their document types laid out as cards. A summary strip across the top
counts Document Types, Uploaded, Verified, Pending, Rejected, and Missing
Mandatory (highlighted in red when anything required is still missing).
Each document type shows tags where relevant:
- Required — a mandatory document for every employee.
- Multi — the type allows more than one entry (older uploads move under View history).
For each uploaded document you can:
- Preview files (images and PDFs open in a viewer; anything else downloads).
- Verify a pending document, or Reject it with a reason (the employee is emailed and must re-upload).
- Revoke a verification you granted earlier, with a reason.
- Delete an uploaded or rejected document.
Expiry: document types can be configured to track an expiry date, and an expiry date is stored with the document when provided. Documents nearing expiry surface as an alert on the admin Dashboard ("N documents expiring within 30 days"), which links straight back to the Documents page.
Document Review queue
Document Review (/admin/employees/document-review) is a focused inbox of
everything employees have submitted through the portal that is still pending.
Reviewers see the employee, document type, file thumbnails, and upload date, and
can Verify or Reject (with a reason) in one place instead of opening each
profile. This page needs the document-verify permission.
Transfers
Transfers (/admin/employees/transfers) records movements between
departments, designations, or branches.
- Click Initiate Transfer.
- Choose the Employee and a Transfer Date (both required).
- Set any of New Department, New Designation, or New Branch — leave any of them on No change to keep the current value.
- Optionally add a Reason, then click Transfer.
The page keeps a dated history of every transfer, showing the from → to change for each employee.
Promotions
Promotions (/admin/employees/promotions) records a change in designation,
optionally with a new salary.
- Click Record Promotion.
- Choose the Employee, the New Designation, and a Promotion Date (all required).
- Optionally enter a New Salary and a Reason, then click Promote.
Each row shows the old → new designation, the date, and the new salary where one was set.
Bulk import
Bulk Import (/admin/employees/import) lets you create many employees, or
assign salaries to many employees, from a CSV file. It has two tabs:
- Import Employees — creates employees in bulk. Bulk import does not
create accounts or send invitations — for anyone who needs to sign in, create
a user from the Users page (
/admin/access/users). - Assign Salaries — sets gross salary for existing employees by code, closing the previous assignment automatically.
Steps:
- Click Download Sample CSV and fill in your data using it as the template.
Columns marked with
*are required. - Click to select your
.csvfile (UTF-8, comma-separated). The page parses it and previews the first rows. - Click Import and confirm. A results panel then shows how many rows were Created / Assigned, Skipped, and Errors, with a per-row message.
For the employee import, the required columns are firstName, lastName,
departmentCode, designationCode, and joiningDate; other columns such as
CNIC, emails, phone, and emergency contact are optional. Bulk-imported
employees start as New (Pending Activation) like everyone else — see
Employee statuses & activation.
The template also carries six optional address columns: addressLine1,
addressLine2, city, stateProvince, country, and postalCode. A filled
set creates the employee's present address — the minimum is addressLine1 plus
city, and a blank country falls back to your workspace country. A
partially filled address fails that row with "Incomplete address:
addressLine1 and city are required when any address column is filled" rather
than importing bad data. A fully blank address still creates the employee, and
the results panel flags the row: "Employee created — no present address on
file; complete it from the employee profile". Wrap any value containing commas
(typical for address line 1) in double quotes — the parser handles quoted
fields, and the sample CSV shows the pattern (e.g. "House 12, Street 5").
Employees imported without an address are never locked out of the portal by the address-verification deadline — that 30-day clock only starts counting when a verification is actually requested.
On standard plans imported rows are not capped — every created employee becomes a billable seat on your next invoice. An operator-set headcount cap on a bespoke deal still applies (rows beyond it are not created), and import is blocked entirely while your trial is expired or your subscription is canceled.
Address & identity verifications
Verifications (/admin/employees/verifications) is where you clear pending
identity checks. It has three tabs — Address, Mobile, and SOS
Contact — each showing a count of what is still pending.
Which checks are enforced
The checks themselves are switched on and off in Settings → Verification
(/admin/settings/verification, permission company.settings). There are
three toggles:
- Address Verification — on by default. The employee verifies their home address with a secret code sent by postal letter. Portal access is blocked after 30 days unverified; each code allows 3 attempts and expires after 45 days.
- Document Verification — on by default. Employees must upload their mandatory documents (identity card, photo, certificates), which HR reviews and verifies.
- Phone Verification — off by default (opt-in). SMS OTP for the employee's mobile number and their SOS/emergency contact.
Phone verification is opt-in by design because it needs an SMS provider to be
usable at all. Even when you switch it on, it never blocks anyone until your
workspace has an active SMS provider configured
(/admin/integrations/sms) — without one the OTP cannot be sent, so the gate
stays inactive rather than locking employees out of the portal behind a check
they cannot satisfy.
The pending-verifications checklist employees see in their portal only lists checks that are actually enabled for your workspace, and its progress count matches what is shown — a disabled check never appears as outstanding work.
The Address tab
On the Address tab, each pending address lists the employee, the address, the date it was requested, and how many attempts have been made. For each row you can:
- Download letter — a PDF containing the verification code to send to the employee's address.
- Regenerate code — issue a fresh code and a new letter (for example if the first never arrived).
- Mark verified or Mark unverified — an admin override that sets the status directly.
Employees enter the code from their letter in their self-service portal to verify their own address. If an address stays unverified for too long, the employee can be flagged until it is cleared — so keep this queue moving.