> ## Documentation Index
> Fetch the complete documentation index at: https://help.dingtalk.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Set up an attendance administrator

> Learn about DingTalk's attendance management role system, including the permission differences and setup steps for the Super Admin, Attendance app admin, and attendance group primary/sub-owners, so you can flexibly configure attendance management permissions.

## 1. Feature overview

This article explains the attendance management role system, including the permission differences and setup steps for each role, so you can flexibly configure attendance management roles.

## 2. Use cases

A large enterprise has multiple departments (such as Marketing, R\&D, and Sales), each with its own attendance requirements and management needs. The company wants to delegate attendance management permissions to each department so that daily tasks can be handled more efficiently.

How to use:

* **Create Sub Admin roles**: Create dedicated attendance administrator roles for department heads.

* **Assign app scope**: Assign each head's own department as their app scope.

* **Refine permissions**: Configure different permissions for each department head as needed, such as whether they can modify attendance rules or approve leave requests.

* **Data isolation**: Ensure that each department's attendance data is visible only to the corresponding attendance administrator, preventing information leakage.

## 3. Attendance management role system

### Role descriptions

| **Category** | **Name**                           | **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | **Assignment suggestions**                                                                                     |
| ------------ | ---------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------- |
| 1            | **Super Admin**                    | **Role**: The Super Admin set in [**Admin Console**](https://oa.dingtalk.io) > **Security & Permissions > Manage permissions**.<br /> **Permissions: Holds all management permissions in the attendance backend**, including attendance group management, leave management, overtime management, and administrator settings. **The management scope covers the entire company**.                                                                                                                                                                                                                                                                                                                                                                                                                                             | Recommended for senior executives across the company, such as the group HR lead.                               |
| 2            | **Attendance app admin**           | **Role**: A Sub Admin set in [**Admin Console**](https://oa.dingtalk.io) > **Security & Permissions > Manage permissions** (must be granted the Attendance app permission).<br /> **Permissions**: Like the Super Admin, holds **all attendance management permissions**, including attendance group management, leave management, overtime management, and administrator settings. However, **the management scope can be specified as needed**.                                                                                                                                                                                                                                                                                                                                                                            | Recommended for subsidiary or sub-department managers, such as branch HR leads or department HR leads.         |
| 3            | **Attendance group primary owner** | **Role**: On **DingTalk desktop > Workbench > Attendance > Attendance group management > Edit**, click **Settings** next to attendance group owner to set the attendance group primary owner.<br /> **Permissions**: The primary owner of an attendance group is the Owner of that group and, by default, is its creator (must be a Sub Admin with attendance permissions). This role has full access to attendance group settings, including attendance participants, attendance type, attendance hours, employee scheduling, clock-in methods, overtime rules, photo verification rules, field clock-in, and makeup clock-in rules.<br />For the groups they manage, this role has **permissions to set attendance rules, view attendance data, and schedule employees**.                                                  | Recommended for a specific attendance group, for example, the HR who manages attendance for Group A employees. |
|              | **Attendance group sub-owner**     | **Role**: On **DingTalk desktop > Workbench > Attendance > Attendance group management > Edit**, click **Settings** next to attendance group owner to set the attendance group sub-owner.<br /> **Permissions**: By default, sub-owners can view the attendance data of employees in the groups they manage. Sub-owner permissions are divided into: setting attendance participants, setting attendance type, setting attendance hours, employee scheduling, setting clock-in methods, setting overtime rules, photo and facial recognition, setting field clock-in, and setting makeup clock-in rules. Assign the corresponding permissions to sub-owners based on your organization's needs.<br />Attendance group sub-owner permissions are assigned by the Organization Admin or by the attendance group primary owner. | Recommended for a specific attendance group, for example, the HR who manages attendance for Group A employees. |

### Permission notes

**The system enforces strict permission isolation based on the management scope, mainly in the following two ways:**

<Note>
  **1. Admins can only view and edit data within their management scope.**

  For example: Xiao Jia is an attendance group administrator whose management scope is Department A, but a certain attendance group contains members from both Department A and Department B. In this case, Xiao Jia can only view Department A's data in that attendance group and cannot view Department B's data. Similarly, Xiao Jia can only schedule members of Department A and cannot perform actions on Department B.

  **2. Depending on the management scope, an admin's permissions may be limited.**

  For example: Xiao Yi is an attendance app admin with attendance group view permission. However, when no members of a certain attendance group fall within their management scope, Xiao Yi cannot view that attendance group.
</Note>

## 4. Procedure

### Organization Admin and attendance app admin

Go to [**Admin Console**](https://oa.dingtalk.io) > **Security & Permissions > Manage permissions > Sub Admin** and configure permissions based on your organization's needs.

<Note>
  **Instructions:**

  In general, to add an admin dedicated to managing the Attendance app, add them as a Sub Admin and configure their app permissions and department scope.
</Note>

<Frame caption="Example page for setting clock-in permissions for a Sub Admin">
  ![Sub Admin clock-in permission settings](https://alidocs.oss-cn-zhangjiakou.aliyuncs.com/res/Lk3lbmbYgwGRGOm9/img/fd1c7c2b-f63b-440b-a428-e02354b1d828.png)
</Frame>

### Set an attendance group sub-owner

To set an attendance group primary owner or sub-owner, open **DingTalk desktop > Workbench > Attendance > Attendance group management > Edit**, click **Settings** next to attendance group owner, and add or remove users in the primary owner or sub-owner field.

<Frame caption="Example page for setting an attendance group sub-owner">
  ![Attendance group sub-owner settings](https://alidocs.oss-cn-zhangjiakou.aliyuncs.com/res/Lk3lbmbYgwGRGOm9/img/f4640368-ca15-4ac4-9f34-d3b0ced9b286.png)
</Frame>

## 5. FAQ

<AccordionGroup>
  <Accordion id="q1" title="How do I view the information of my newly assigned attendance group?">
    Members of attendance group A can open **DingTalk mobile > Workbench > Attendance** and tap **View rules** at the top to view the name and owner of the newly assigned attendance group.
  </Accordion>

  <Accordion id="q2" title="How do I refine the Attendance app permissions?">
    You can refine permissions for the Attendance app. After setup, a Sub Admin can perform only the attendance actions granted by the assigned permissions. For settings they do not have permission for, they will be prompted to contact the admin to enable them. The Super Admin can go to [**Admin Console**](https://oa.dingtalk.io) > **Security & Permissions > Manage permissions > Sub Admin > Add Sub Admin/Admin**, or **Edit** the corresponding admin group > click **Edit** next to DingTalk official app permissions > select **Attendance > Turn on refinement > Configure**, and assign the corresponding permissions.
  </Accordion>
</AccordionGroup>
