Administrator overview

Where everything an administrator looks after lives in the suite, what to set up first on a new installation, and how to change things without disturbing work that is already in progress.

This section is for System Administrators and ICT administrators, and for HR officers who manage staff records. If you are new to the suite as a user, start with Quick start in 5 steps and ICT & System Administrators.

Names on this installation. The hospital's own words replace some of the suite's default labels (see Terminology). This manual uses the hospital's words and gives the default in brackets the first time, for example Departments & Units (User Groups), Request Templates (Request types), Voucher Types (Payment types), Approval routes (Approval workflows) and My Desk (Approvals).

Where everything lives

Administration pages sit in two groups of the menu on the left. You see an item only if you hold its permission (in brackets below). System Administrators hold every permission.

Menu itemWhat you manage thereHow-to
People › Users (view_users)Staff accounts: add, edit, deactivate, reset passwords, reset onboarding, per-person permissions, export.Add, import and manage users
People › Departments & Units (view_user_groups)The organisation tree: departments, units, their codes and heads.Departments, units & heads
Administration › Role & Permissions (view_roles)Role templates: named sets of permissions you copy onto people.Roles & permissions
Administration › Request Templates (view_request_types)Each kind of request: its form, its printed document, its approval chain, who files it and who receives it.Build a request type
Administration › Approval routes (manage_approval_workflows)Reusable approval chains for payment vouchers and memos.Approval workflows
Administration › Memo templates (view_memo_templates)Letterhead, header fields, numbering and approval route of each kind of memo or circular.Memo templates
Administration › Voucher Types (manage_payment_types)Each kind of payment voucher: its form, printed voucher and approval routing.Payment types
Work › Registry (manage_registries)Which units are registry offices that file finished requests.Registry offices
Administration › Mail Control (view_mail_control)Mail domains, shared mailboxes, who can open them, and the external mail policy.Mail domains & mailboxes
Administration › Settings (view_settings)System variables, modules on/off, colours, terminology, notification and health checks.System settings
Administration › Audit Logs (view_audit_logs)The record of who did what, and when.Reviewing the audit log

For a full list of permissions and which standard roles hold them, see Every permission explained and Roles at a glance.

First-day setup checklist

On a fresh installation the hospital's reference data (the unit tree, role templates, request templates, approval routes, voucher types, memo templates and default settings) is loaded by the ICT team with the seed script npm run db:seed:uath. After that, work through this list in the app.

  1. Check the system is healthy. Open Settings › Health and confirm All required checks passing. Fix anything red before inviting staff. See Health.
  2. Check the organisation's details. In Settings › Variables, confirm org.name, org.short_name, org.address and org.email_domain, and the approval rules (approvals.require_comment, approvals.require_signature, approvals.allow_return). See Useful variables.
  3. Check the wording. Settings › Terminology holds the hospital's words. Change them only if the hospital asks.
  4. Switch off modules the hospital does not use. Settings › Modules. A module that is off disappears for everyone.
  5. Review the unit tree and heads. In Departments & Units, check that each department and unit has the right head. Heads decide the first level of most approval chains. See Departments, units & heads.
  6. Load the staff. Bulk-import the nominal roll, or add people one at a time. Put each person in their unit. See Add, import and manage users.
  7. Give office holders their permissions. The CMD, CMAC, DA, DFA, finance, audit and registry staff need more than the Employee template. See Office holders.
  8. Check the registries. On Registry, select Registry offices and confirm which units file finished requests. See Registry offices.
  9. Walk one request through. As a test person, submit a request of a common type and approve it at every level. Check who received each step, the printed document and the registry copy.
  10. Set up mail if the hospital uses the suite's mailboxes: domains, shared accounts and the external mail policy. See Mail domains & mailboxes.

Making changes safely

Most administration screens change what happens next, not what already happened. Knowing which is which keeps you out of trouble.

When you change…Work already in progressNew work
A request template's form, document or chainKeeps the copy it was submitted with. A step that has not opened yet is assigned again when it opens.Uses the new version at once.
An approval routeFinishes on the version it started with. Saving creates a new version.Uses the new version.
A memo templateMemos keep the template copy they were written from.Uses the new template.
The head of a unitPending approvals the old head held as head of that unit move to the new head automatically.Routes to the new head.
A role templateNothing changes for people who already have it.Only people you copy it onto from now on get the change.
A person's permissionsTake effect at once. The person's menu catches up the next time their page reloads.
TerminologyOnly the words on screen and in new documents change. Stored statuses and reports do not.

Good habits

Some switches save the moment you flip them, with no Save button: the external mail policy in Mail Control is one. Read the description beside a switch before you touch it.

Jobs done from the command line

A few jobs have no screen and are run by the ICT team on the server, from the application folder:

npm run users:import
Bulk-create staff from the nominal roll spreadsheet. See Bulk import.
npm run db:seed:uath
Load or top up the hospital's reference data and re-apply office templates.
npm run permissions:backfill
Bring every stored role and person up to date after an upgrade adds permissions. See After an upgrade.
npm run users:mark-onboarding
Send existing staff who have no photo or signature through first-time onboarding.
npm run users:dedupe-staff-ids
Report staff numbers or IPPIS numbers shared by more than one person, which make staff-ID sign-in ambiguous.

Each command accepts --dry-run (except the read-only dedupe report). Always run the dry run first.

Related