FriendHRM User Manual
Secure SuperAdmin platform access
Use the SuperAdmin workspace only for platform responsibilities, protect MFA and audit controls, and delegate tenant work through scoped roles rather than sharing privileged credentials.
Intended audience
- SuperAdmin
Where to find it
SuperAdmin → Security, MFA setup, or Audit logs.
Before you start
- SuperAdmin actions are platform-scoped and may require MFA, evidence, a maker/checker path, or another policy condition before a change is effective.
Steps
- 1
Enter the protected platform workspace
Sign in with the designated SuperAdmin account and complete any required verification before opening platform controls.
- 2
Use scoped delegation
Assign tenant or team responsibilities through the appropriate product role and workflow instead of sharing the SuperAdmin account or bypassing policy checks.
- 3
Review the audit trail
Use the audit and security views to confirm changes, evidence, and ownership when the product provides that record.
Expected result
Platform work remains attributable to the designated SuperAdmin account, subject to MFA, audit, and maker/checker controls.
Open the relevant FriendHRM workspace
These destinations are verified against the current product navigation or route record. They remain subject to sign-in, feature, tenant, role, and data-scope checks.
Common problems
A SuperAdmin security action is blocked.
Check the current MFA state, policy condition, and audit evidence. Use the approved recovery or governance process rather than disabling controls to complete the action.