AWRA OpsHub Search

Most of Your Staff Have No Login

An employee record here does not require a user account, and that is deliberate — in most of the businesses this was built for, a majority of staff have never logged into anything. Every account-shaped feature in the product therefore covers a minority of your people.

HR & Payroll AWRA OpsHub Team 11 min read

A great deal of business software is built on an assumption so basic that nobody states it: that a person and an account are the same thing. It holds in an office of forty knowledge workers. It fails completely in a business with a hundred and twenty staff and eighteen computers.

The design decision

An employee in this product is a record in its own right. The link to a user account is optional. Somebody can be hired, rostered, paid, given custody of equipment and assigned work without ever having a login.

This is the right model for the operations this product serves, and the product is consistent about it in places that matter. The helpdesk carries two assignee fields — an employee and a user — because an agent may be one, the other, or both. When a ticket breaches, the escalation resolves the assignee's manager through the employee record rather than through an account, precisely so that it works for somebody who has no account of their own.

Those are not accidents. Somebody thought about the login-less majority and built for them.

What still assumes an account

Everything that has to reach a person rather than describe one.

Which features work for an employee with no login

Feature Works without an account Needs an account
Being paid, and having a payslip generated Yes No
Being rostered onto a shift Yes No
Holding custody of an asset Yes No
Being assigned a support ticket Yes No
Having your manager escalated to Yes No
Receiving a notification No Yes
Being covered by the data export tool No Yes
Appearing in the account reconciliation screen No Yes

Built and maintained Configurable by you, not maintained by us Not built

The bottom three are not oversights. Delivery needs an address, and account tooling is about accounts. They are the boundary of what the login-less design can reach.

The system can pay you, roster you, escalate on your behalf and hold you responsible for a generator. What it cannot do is tell you anything.

The other population, and what was built for it

The mirror image of an employee with no account is an account with no employee, and it is the more dangerous one — a login that nobody is responsible for, belonging to somebody who may have left.

There is a reconciliation screen for exactly this: every active login with no employee record behind it, sorted with never-used accounts first, each one revocable. It sits behind the permission to edit users rather than the permission to edit employees, deliberately, because it can surface an administrator who was never in the HR system at all.

And it is deliberately not automatic. The reasoning is worth quoting in substance: these accounts have no employment status to read, and an owner's account or an integration account is indistinguishable from a forgotten contractor by any rule you could write. So it is a list somebody reviews, not a rule that runs.

That is a genuinely good call. The automatic version of this feature deactivates the owner's login one quiet Tuesday.

What is still missing on that side

An expiry date on an account. A contractor login cannot be granted until a stated day and left to lapse on its own.

The reconciliation screen makes a forgotten account visible; an expiry date would make one impossible. It is the stronger version of the same control and it is the half that has not been built.

What we would build

Two, on opposite sides of the same boundary

One reaches the people without accounts. The other closes the accounts without people.

A delivery channel that is not an account

Notifications to an employee's phone number rather than to a user's inbox — a payslip is ready, a shift changed, an asset is due back. This is what would extend the login-less design from "the system knows about you" to "the system can reach you", and it is the difference that matters to the majority of a workforce.

An account expiry date

Granted until a stated day, then lapsed automatically. It turns the review screen from the control into a backstop, which is the right order. Small, and it is the named next step in our own gap file.

How it works: you describe the requirement, we return a written scope, timeline and cost, and once agreed it is built into your environment and maintained as part of the product.

Talk to us about workforce access

People and accounts, precisely

What AWRA OpsHub does today

  • Employee records independent of user accounts, so staff without logins are hired, paid, rostered and given custody normally.
  • A dual assignee on tickets — employee or user — with manager escalation resolved through the employee record so it works either way.
  • A reconciliation screen listing every active login with no employee behind it, revocable, sorted with never-used accounts first.
  • Self-revocation blocked on that screen, so nobody can lock themselves out of it.
  • Payslip generation and distribution for employees regardless of account status.

What it does not do

  • Any notification delivery to an employee who has no user account.
  • An account expiry date, so a contractor login cannot lapse on its own.
  • Coverage of login-less employees by the account-shaped data export tooling.
  • Any automatic action on an unlinked account — deliberately, and we would defend that.
  • A single view of a person spanning their employee record and their account.

Not ours, by choice

  • The login-less design is a strength and the reason this product fits operations rather than offices. This page is about where that design stops, not an argument that it is wrong.
  • The unlinked-account screen being a review rather than a rule is a deliberate decision we would defend: no rule can distinguish an owner's account from a forgotten contractor's.
  • Nothing here is Caribbean-specific in law. The region is here because small operations with large seasonal and casual workforces are the norm, which is precisely the shape where most staff never hold an account.

Our position

Create employee records for everybody and accounts only for people who need to use the system — that is the model working as intended, and it keeps your payroll, rosters and custody records complete. Then review the unlinked-accounts screen on a fixed day each month, because until an expiry date exists that review is the only thing standing between you and a live login nobody owns.

Four questions about people who do not log in

Can an employee exist without an account?

A good answer sounds like

Yes, fully.

What it actually means

A no means every member of staff needs a licence and a login, which changes the cost and the deployment entirely.

Which features require an account?

A good answer sounds like

A specific list.

What it actually means

Ours is essentially anything that delivers something. Ask for the list rather than inferring it.

How do you find accounts with nobody behind them?

A good answer sounds like

A screen, reviewed.

What it actually means

Ours has one and deliberately does not act automatically. An automatic version eventually deactivates an owner.

Can an account be granted until a date?

A good answer sounds like

Yes.

What it actually means

Ours cannot. It is the control that makes forgotten contractor accounts impossible rather than merely visible.

Count your accounts against your people

Two numbers. If the first is larger, the difference is a list worth reading, and it is the one security review nobody schedules.

Talk about workforce records

Frequently asked questions

How does a login-less employee get their payslip?

Distribution goes through the channels the product has, which are account-shaped, so in practice it is printed or handed over. This is exactly the boundary a phone-number delivery channel would cross, and it is the most commonly felt version of the gap.

Does an employee without an account count towards licensing?

Employee records and user accounts are different things in this product, which is the whole design. What that means commercially is worth confirming for your specific arrangement rather than assuming.

Why not deactivate unlinked accounts automatically?

Because an owner's account, an integration account and a forgotten contractor's account are indistinguishable to any rule — none of them has an employment status to read. An automatic sweep would eventually lock out the person who owns the business.

Help Center

Need a quick answer while you read?

Run inventory, procurement, assets, sales, and field work with approved AWRA guidance for setup, migration, integrations, security, pricing, and support.

Search all approved AWRA public help articles.

Open Help Center