Administration
Administration in TriostackOne is centralized: because every app shares one identity model, a role or permission change you make once applies everywhere that person has access — you're not reconciling separate admin panels per product.
This guide covers the three things most admins configure early: roles, permission scopes, and offboarding.
1. Understand roles vs. permissions
A role (Admin, Manager, Member) sets a starting permission baseline. Permissions themselves are scoped per app — a person can be a Manager in HRMS (able to approve leave) while only having Member-level access in Finance (able to submit expenses, but not approve them).
Admins can see and edit every app's permission scope for a given person from that person's profile in Settings → Team, without switching between apps.
2. Set up approval chains
Several workflows across the suite depend on an approval chain — leave requests in HRMS, expense reports in Finance, deal discounts in CRM. Configure these under each app's Settings → Approvals, where you can set a manager-based chain (approvals follow the org chart) or a fixed approver per team.
3. Audit access regularly
Settings → Team → Access log shows every permission change, sign-in, and app enablement across the workspace, with who made the change and when. Use it during periodic access reviews rather than trying to reconstruct history from memory.
4. Offboard a team member
Removing someone from Settings → Team immediately revokes their access to every app at once — there's no need to individually deactivate them in CRM, then HRMS, then Payroll. Their historical records (deals they owned, reviews they completed) stay intact and are simply reassigned or marked as owned by a former employee, depending on the app.