§ 26 · People & institution

Staff portal

The staff portal is where an employee handles their own affairs: leave, documents, training, helpdesk and the staff directory. Its dashboard works for everyone; several of its inner pages are gated by permissions that are not currently granted to anybody.

What it is for

Your own employment record and requests.

Who can do it

Every employee

Needed first
  • A staff profile linked to your user account
  • The staff.portal.access permission — held by every staffed role
Where it ends

Requests that reach HR, and your own documents.

Getting in

Go to staff.cuo-ss.sektechsoftsolutions.co.ke and sign in with your email address or staff number, or use Staff Self-Service at the bottom of any admin sidebar. One login covers both.

The Staff Dashboard showing the employee's identity, staff number and the sidebar groups MAIN, EMPLOYEE SERVICES and SYSTEM.
Staff Dashboard. The sidebar groups your own affairs: Main (requests, library, special exams, announcements, calendar, meetings, security), Employee Services (workload, training, performance, helpdesk).
ItemWhat it is for
My RequestsEverything you have asked HR for, and where each has reached
LeaveApply for leave and see your balance
DocumentsYour contract, letters and payslips
EmploymentYour record as HR holds it — designation, department, contract
My Library / Library RequestsYour borrowing, and requests for new resources
Special ExamsSpecial and supplementary examination requests
Announcements, Calendar, MeetingsInstitutional notices and your diary
My Workload, My Training, My PerformanceTeaching load, training record, appraisal
HelpdeskRaise an ICT or facilities ticket
SecurityYour own sign-in activity — worth checking occasionally
DirectoryContact details for colleagues

Which pages actually open

Verified on the live system

The staff portal is governed by fourteen permissions. Only three of them are currently attached to any role: staff.portal.access (which lets you in), staff_portal.submit_leave and staff_portal.submit_requests. The rest — including staff_portal.view_leave, view_documents, view_directory and view_approvals — are attached to no role and no user at all.

The practical effect: the dashboard and helpdesk open for everyone, and Leave, Documents, Employment, Directory and Approvals return not authorised for everybody — including a Super Admin. This is not a fault in your account, and requesting the permission for yourself will not help, because it is not granted to anyone.

PagePermissionCurrently
Dashboardstaff.portal.accessOpen to all staffed roles
Helpdesk—Open
Apply for leavestaff_portal.submit_leaveGranted to 23 roles
Submit a requeststaff_portal.submit_requestsGranted to 23 roles
View leavestaff_portal.view_leaveGranted to nobody
View documentsstaff_portal.view_documentsGranted to nobody
Employment recordstaff_portal.view_profileGranted to nobody
Directorystaff_portal.view_directoryGranted to nobody
Approvalsstaff_portal.view_approvalsGranted to nobody
What to do meanwhile

Use HR directly: leave through HR & staff, documents and employment details from your HR officer. If your institution wants the portal fully open, this is a single configuration change — attach the staff_portal.view_* permissions to the roles that should hold them, in Roles & Permissions.

The helpdesk

The staff Helpdesk screen for raising and tracking support tickets.
Helpdesk. Open to every signed-in member of staff. This is the right route for “I cannot open a screen I should be able to” — it creates a record ICT can work from, rather than a conversation in a corridor.
Worked example

Raising a ticket that gets fixed quickly

Say what you did“Signed in to the admin portal as an Academic Registry Staff account”
Say whereThe menu path, not just the page name: Students & Registry›Retake Authorizations
Say what happenedThe exact message. If it named a permission, quote it: semester-registration.retake-authorize
Say what you expected“To see the retake queue for the September intake”
Say whenThe date and rough time — ICT can find it in the audit log
Do not attachScreenshots containing other people's personal data

If the portal refuses

SymptomCauseFix
Leave, Documents, Employment or Directory refuseThose permissions are granted to nobodyNot your account. Use HR directly, and see the table above
You cannot sign in at allNo staff profile linked to your user accountHR links the profile and grants staff.portal.access
The dashboard shows the wrong staff numberTwo staff profiles for one personHR — merge them before anything else is done
Your workload looks wrongIt is computed from published timetable periodsTimetable
You lost access after a contract renewalThe old contract expired before the new one startedHR — Contract Renewals