ADMIN sees everything, SYSTEM_ADMIN sees the technical surfaces without the people
data.
Organization
Locations
Standorte with their canton. The canton drives public holidays, the default sick-pay scale, and
cantonal payroll parameters.
Teams and org graph
Who reports to whom. Manager scoping for absences, salary visibility and applications is derived
from this — it is not a display hierarchy.
Legal entities
Rechtsträger, where the installation employs through more than one. Flag-gated.
Positions catalog
Function definitions reused across recruitment, contracts and certificates.
Users
Creating, editing and deactivating accounts, and assigning roles.SYSTEM_ADMIN administers accounts but cannot escalate: it may not create, modify or
delete a user holding HR_STAFF, MANAGER, ADMIN or SUPERADMIN, may not assign
those roles to anyone, and may not change its own role. See
Roles and permissions.
Which domains may sign in
ALLOWED_EMAIL_DOMAINS lists the e-mail domains that may auto-create an applicant
account on first Microsoft sign-in. Leaving it unset falls back to the Entra tenant
boundary alone, which is logged as a warning.
Integrations
A read-only mailbox diagnostic (
mailbox:diagnose) reports credential drift, an
unconfigured mailbox, or a Graph outage, with values masked. Administrators can
self-triage without server-log access.
Branding
Logo, colours and typography for the careers page, the portal and generated documents. A design extractor can derive a starting palette from an existing site, which you then adjust. Branding isSUPERADMIN and SYSTEM_ADMIN — it is visual identity, containing no
personal data, which is why the technical operator role holds it.
Menu configuration
Which modules appear in the navigation, and in what order. This is how an installation that does not use, say, budgeting keeps it out of the way — alongside the feature flags, which switch the module off entirely rather than merely hiding it.System configuration
Mailbox connection, cron secrets, site verification tokens and similar operational settings sit undersystem:configure (SUPERADMIN, SYSTEM_ADMIN).
Google Search Console verification is available as an administrator-configurable token
rather than only as an environment variable, so the person who owns the domain can
complete verification without a deploy.