Configure the database, access rights and locks

Objective. Set up a reliable and secure Tempolia database by configuring companies, users, reference data, permissions, profiles and period locks in the correct order.

Estimated duration1 h

What you will learn

  • Configure issuing companies, bank accounts and core reference data.
  • Grant each employee only the permissions required for their role.
  • Use profiles and locks to standardise access and protect closed periods.

Recommended workflow

  1. Define companies, general options, bank accounts and document settings first.
  2. Create stable sales, task and expense codes before operational data is entered.
  3. Create employees, assign profiles and review sensitive permissions individually.
  4. Test the configuration with a standard user account before opening the database to the team.

Before continuing

  • No shared or generic employee account is used for day-to-day work.
  • Permissions are tested with the actual user profile, not only as Administrator.
  • Locks protect approved periods without preventing legitimate current work.

Before you begin

In your subscription, choose a representative employee who must enter time on one open matter with an authorised task and see only matters belonging to the assigned group, but must not see cost prices or alter a locked period. Check the complete configuration chain before enabling the access.

Prerequisites in your subscription

  • Have the necessary administration rights in your subscription and a representative business account. Without change authorisation, follow the workshop in read-only mode.
  • Locate your issuing company, selected employee, assigned group, effective profile, one task, its sales code and its one-character VAT code.
  • Choose one matter the employee must see and another outside the permitted scope, so both permission and prohibition can be tested.
  • Use a second account representing the tested profile. A check performed only as administrator does not show what the business account can actually do.

Suggested schedule — 1 h

  1. 5 min: state the business need and prohibited actions.
  2. 10 min: check options, company and bank.
  3. 10 min: review the employee record and assignments.
  4. 10 min: test profile, scope and sensitive columns.
  5. 10 min: check tasks, expenses, sales codes and VAT.
  6. 10 min: test approval and locking with the business account.
  7. 5 min: step back and record the chosen access settings.
Complete “The selected employee can … on … but cannot …”. Without this sentence, no one can judge whether a permission is correct or excessive.

1. Configure common rules before individual users

Open Configuration > General options, then Companies and Bank accounts. General options establish profiles, passwords, entry controls, approval behaviour and defaults. The issuing company holds legal identity and invoice settings; bank accounts support payment instructions and exports. These values are foundations, not a collection of optional switches.

For your issuing company, identify which rules the team truly uses. For every sensitive option, note its purpose and expected effect. Enabling everything produces contradictory behaviour and makes support harder. Keep only settings whose purpose and effect are clear.

Tempolia screenshot: general options and profiles
General options group profiles, passwords and structural rules.
Tempolia screenshot: issuing companies
The list shows company code, legal name, SIRET, email, address, model and sales rules; bank details and logo are checked in the full record.

2. Build the employee, profile and scope chain

Open Employees, the selected employee’s login rights and the profile matrix. The employee record supplies identity, company, group and operational links. The profile grants page capabilities. Login scope determines which employees, clients or matters are visible. Column permissions can hide sensitive values such as cost price.

Rights therefore answer three separate questions: which page, which records and which fields. Test all three with the representative account. Search for a matter the employee should access, open time entry, and verify that cost-price columns and administration pages are absent. Do not infer business-user behaviour from the administrator view.

Check profile, record scope and cost-price visibility separately. An “Associate” profile, “All” scope and visible costs fail the restricted target; correct each setting and repeat the test with the business account.

Tempolia screenshot: employee list
The employee list controls identity, group and active status.
Tempolia screenshot: employee login rights
Login rights define the records and organisational scope a user can see.
Tempolia screenshot: profile permission matrix
The profile matrix grants capabilities page by page.

3. Approve and lock without erasing history

Approval separates entry from managerial control. Locking prevents changes before a chosen date or in a validated period. These mechanisms protect history only when the organisation knows who approves, when the cut-off occurs and how a legitimate exception is handled.

Test the selected employee in one open and one locked period. Current work should follow the normal workflow, while the locked line remains visible but cannot be silently altered. If it disappears, check scope and filters; if it remains editable, check effective profile, company, cut-off date and approval state. Locking is a process control, not a substitute for correct rights.

Tempolia screenshot: approval and locking options
Approval and locking options protect validated periods.
Tempolia screenshot: time control options
Time controls define completeness and validation rules.

4. Stabilise tasks, sales, tax and expense reference data

Sales codes, VAT codes, expense codes, billable tasks, non-billable tasks and invoice templates translate operational entries into commercial and accounting outputs. Build dependencies in order: commercial and tax rules first, tasks and expenses next, templates and client settings last. Reuse stable codes rather than creating near-duplicates.

For the selected billable task, verify that it is active, maps to the intended sales code and receives a one-character VAT code through the applicable rule. A non-billable task should remain available for internal work without reaching invoice preparation. Never delete a code used historically: make it unavailable for new entries so old time, invoices and exports remain intelligible.

Tempolia screenshot: sales-code reference data
Sales codes connect wording, account, VAT and invoice behaviour.
Tempolia screenshot: billable tasks
Billable tasks connect performed work to commercial treatment.
Tempolia screenshot: invoice templates
Invoice templates control presentation after commercial rules are validated.

5. Separate client rules, electronic routing, cost and price

Client billing data can override or complete common rules: payment terms, invoice contact, model, language, VAT context and electronic-invoicing identifiers. Missing PA/eReporting information may not affect time entry but can block transmission later. Custom characteristics need a clear reporting purpose, a limited list of values and someone responsible for maintaining them.

Compensation history supports internal cost valuation; selling prices by employee, matter or quantity support commercial valuation. They are not interchangeable and require different permissions. Effective dates matter: changing today’s value must not silently reinterpret historical work. The selected employee may enter time or quantity without seeing pay history or cost.

If the employee/matter or task/matter exception tables show no row, conclude only that no matter-specific override is observed. The applicable general rule, its effective date and its value must still be identified elsewhere; an empty table gives neither the applicable rate nor the resulting margin.

Tempolia screenshot: client billing data
The client billing tab holds specific commercial conditions.
Tempolia screenshot: compensation history
Compensation history supports dated cost valuation.

6. Check the configuration in downstream reports

Run a restricted report with the selected employee and a control report with the authorised manager. Use the same company, client, matter and period. The operational rows should agree while confidential cost columns remain hidden. Also verify that the selected task reaches the expected reporting axis and that its sales code and one-character VAT code produce consistent commercial data.

If the totals differ, compare filters and data scope before widening rights. If the totals agree but a sensitive column appears, correct the column or profile rule. Record the effective configuration together with the permitted and prohibited actions observed under the business account.

Tempolia report configuration form awaiting generated results
Keep these filters, then compare both generated outputs to check the rows and columns available to each account.

Try the access with the business account

  1. 1. List three permitted and three forbidden operations for the selected employee, including the chosen matter scope, cost visibility and locked periods.
    Every permission matches a real task performed by the selected employee.
    If not, stop and ask the person responsible for that role to decide before configuring.
  2. 2. Follow selected employee → group → profile → page → record scope → column and record each value.
    The observed access comes from visible profile, group, scope and column settings.
    If not, inspect inherited profile, duplicate account, company and group.
  3. 3. With the business account, find the chosen matter, open time entry, look for cost and inspect a locked period without saving.
    Normal work is possible, sensitive cost is hidden and history is protected.
    If not, identify whether page, row, column, lock date or approval causes the issue.
  4. 4. Confirm selected task → sales code → one-character VAT code, then compare restricted and manager reports.
    Operational totals agree while confidential fields respect the role.
    If not, review task mapping, effective dates and filters before expanding rights.
Keep the business need, chosen settings and observed account behaviour together in the access record.

Errors that create future incidents

  • Testing only with an administrator account.
  • Granting a broad profile to compensate for one missing page.
  • Deleting a code used in historical time, invoices or exports.
  • Changing rates without effective dates and an impact review.
  • Locking periods before defining approval and exception responsibilities.

Step back

Good access settings let the employee work on the intended matters without exposing costs or reopening a locked period.

When the role changes, review profile, group, record scope and sensitive columns, then sign in with that account and check the result. Keep the chosen settings with the access request so they are easy to revisit.

Test one more user profile

Use a second business account and prepare a four-column sheet: allowed, forbidden, observed and correct.

  1. 1. Before opening Tempolia, write down the company, profile, groups, visible matters, hidden costs and the period that must be locked.
  2. 2. Read the profile and groups first, then sign in with the test account and check one authorised action and one forbidden action. Record the exact screen and message.
  3. 3. Test one meaningful anomaly: the chosen matter is missing, a cost is visible, a locked period can still be edited or a report shows unrelated matters. Check the setting that governs that symptom, then repeat the same test.
  4. 4. Close every tab, sign in again with the test account and check that the permitted action works while the forbidden action remains blocked.
The permitted action works, the forbidden action remains blocked, and no additional rights are granted.