All documentation

Chapter 11

Reports, company settings and administration

This chapter covers the administrative side of MusterHR: the five reports and their CSV exports, the branding you control under Company settings, and the User accounts screen where logins, roles and passwords are managed. It also explains Sign-in activity and what the system records in its audit log. It is written for whoever runs the workspace — usually a Super Admin or HR / Ops — although managers, finance and reporting users can open parts of it too. If you are looking for what each role is allowed to do in general, see Roles and permissions.

This chapter covers the administrative side of MusterHR: the five reports and their CSV exports, the branding you control under Company settings, and the User accounts screen where logins, roles and passwords are managed. It also explains Sign-in activity and what the system records in its audit log. It is written for whoever runs the workspace — usually a Super Admin or HR / Ops — although managers, finance and reporting users can open parts of it too. If you are looking for what each role is allowed to do in general, see Roles and permissions.


Who can open what

Screen Where it is Who can open it
Reports Payroll & reports → Reports Super Admin, HR / Ops, Manager, Finance, Reporting
Payroll summary report inside Reports Super Admin and Finance only
Download CSV on any report inside a report Super Admin, HR / Ops, Finance, Reporting — not Manager
Company settings People → Company settings Super Admin only
User accounts People → User accounts Super Admin and HR / Ops
Changing roles on an account inside a user account Super Admin only
Sign-in activity (your own) My space → Sign-in activity Everyone

If a screen named here is missing from your sidebar, you do not have the role for it. The server enforces every rule; hiding the link is only a courtesy. The ⌘K (Ctrl+K) command palette searches only pages you are allowed to open.


Reports

Go to Payroll & reports → Reports. The top of the page shows your current headcount and the three largest employment types, then a card for each report. Every report reads the whole company, not just your team — a manager who opens Reports sees company-wide figures.

The counts at the top of the index cover everyone on the books today — onboarding, active and on notice. People who have exited are not counted there.

Headcount

Reports → Headcount answers "who is on the books right now". It has no date controls; it is always as at today.

Four charts break the same population down:

Chart Groups by
By department Department, with everyone unassigned grouped as Unassigned
By status Onboarding, Active, On notice, Exited
By employment type Employee, Intern, Contractor, Consultant
By work model Remote, Hybrid, Office

Worth knowing. The four charts do not add up to the same total. By status also counts people who have exited; the department, type and work-model charts leave them out. The page says so above the charts, and the CSV repeats it in its section headings. If By status totals 9 while By department totals 8, one person has exited — nothing is broken.

Attendance summary

Reports → Attendance summary counts every attendance session in the company dated inside a range.

  1. Set From and To, then click Apply. The report defaults to the current calendar month.
  2. Read the three tiles: Sessions in this period, Marked late, and Average worked per session (shown as, for example, 9h 38m). If nobody has recorded hours, the third tile reads No hours recorded yet.
  3. Read Sessions by status below — Present, Absent, Half day, On leave, Holiday, Weekly off, Work from home, Missing clock-out.

A range longer than 366 days is refused, and so is an end date earlier than the start date. The dates stay on screen with the error above them so you can correct them and apply again. For what the statuses mean and how sessions are created, see Attendance.

Leave summary

Reports → Leave summary covers one financial year, April to March.

  1. Type the starting year in Financial year starting2026 means 1 Apr 2026 to 31 Mar 2027.
  2. Click Apply.

The table lists each leave type with Approved, Pending and Requests. Unpaid types are marked (unpaid) after the name. A leave request is counted in the year its start date falls in. Leave types nobody requested that year are left out entirely, so a short table is normal in a young workspace; if nothing at all was requested you see No leave in this FY.

The Requests column counts every request of that type in the year whatever became of it, while Approved and Pending count days in those two states only — so the columns are not meant to reconcile. See Leave and holidays for the statuses themselves.

Attrition

Reports → Attrition compares joiners and exits over a range.

  1. Set From and To, then click Apply. It defaults to the current financial year.
  2. Read the four tiles: Joiners in this period, Exits in this period, Attrition rate, and Headcount today.
  3. Exits by reason breaks the leavers down; anyone whose exit reason was left blank is grouped as Unspecified.

Joiners are people whose joining date falls in the range; exits are people whose exit date does. The range may span roughly ten years.

Worth knowing. The attrition rate is exits divided by an approximate average headcount — today's headcount plus half the exits in the period. It is a quick indicator, not an audited figure, and because the headcount part is always today's, a range far in the past will be measured against a company of a different size.

Payroll summary

Reports → Payroll summary shows current monthly CTC by department for active employees. The card only appears if you have salary access — in practice Finance and Super Admin. HR / Ops can open every other report but not this one.

Tiles show Active employees, Total monthly CTC and Average monthly CTC, and the table breaks the total down by department. A department whose people have no salary structure yet reads No salary on record rather than ₹0.00, because a real zero and a missing figure would otherwise look identical.

A workspace of six active employees might show ₹1,07,200.00 total and ₹17,867.00 average, with Engineering at ₹92,200.00 across three people and Finance at ₹15,000.00 for Sanjay Iyer.

Worth knowing. This report has no period picker, and that is deliberate. It always sums the salary structures in force today and cannot reproduce a past month. Anyone with no salary on record counts as nil, which pulls the average down. For what was actually paid in a given month, use a payroll run and its payslips instead — see Payroll and payslips.

Exporting a report to CSV

Every report page carries a Download CSV button at the top right, if your role may export. Managers can read reports on screen but have no export button, and the page description changes to match ("People analytics across the company, on screen").

  1. Set the report's dates or financial year first and click Apply.
  2. Click Download CSV. The file uses whatever period is on screen and is named report-headcount.csv, report-attendance.csv and so on.

The CSV carries the same wording as the screen, including the caveats: the headcount export labels the section that includes exited people, and the payroll export opens with a Basis row saying "Current CTC of every active employee — not a payroll run" plus the month the export was taken in. Every export is written to the audit log with your name against it.


Company settings

People → Company settings is a Super Admin screen, and today it holds your branding. The heading names your company, for example "Branding for FinalDoc Technologies Pvt. Ltd.".

Your logo appears in the sidebar for everyone in your company and on the documents you issue, such as payslips and offer letters.

  1. Use the Logo file picker to choose a PNG, JPG, WebP or SVG under 2 MB.
  2. Click Upload. The preview beside it updates; before the first upload it reads No logo.
  3. To take it down, click Remove and confirm. The logo disappears from the sidebar for everyone and from documents issued from then on. You can upload a new one at any time.

Uploading a replacement discards the previous file, which cannot be recovered from within MusterHR.

Brand colour

The brand colour is used for buttons, links and highlights across the app for everyone in your company. A readable text colour is derived from it automatically.

  1. Pick a colour with the swatch, type a hex value such as #0D9488 into Colour, or click one of the seven Presets.
  2. Check the Preview strip. It shows a primary button and a link in your colour, with the contrast ratio and whether text on it comes out white or dark.
  3. Click Save colour. The whole app re-renders in the new colour.

If the value is not a valid hex colour, saving is blocked with "Enter a colour like #0D9488." If the derived text contrast falls below the 4.5:1 accessibility standard you get a warning naming the actual ratio — you can still save, but a darker or lighter shade will read better for everyone.

Reset to default puts the product colour back.

The sign-in page always keeps the MusterHR look. It is shown before anyone has signed in, so there is no way to tell yet which company's branding to use. The musterhr.com marketing site is not affected either.

What is not on this screen

A few things people expect to find here are set elsewhere, or are not editable in the app at all.

Setting Where it stands
Employee code format Fixed per workspace. Employees get EMP-{FY}-{SEQ} and interns INT-{FY}-{SEQ} by default, so the first employee joining in FY 2026–27 becomes EMP-2026-0001. {FY} is the financial year of the joining date; {SEQ} is a four-digit running number within that prefix. No screen changes the pattern.
Company legal details — legal name, CIN, GSTIN, PAN, registered address Captured when the workspace is created. There is no screen in the app to edit them afterwards; write to hello@musterhr.com.
Holiday calendar Company → Holidays — see Leave and holidays.
Leave types and balances Set up with your workspace; there is no self-service screen for creating or editing leave types. See Leave and holidays.
Departments, designations and locations Chosen on the employee record — see Employee records and profiles.
Your own password and two-factor My space → My profile, and the Change password button on Sign-in activity. See Getting started.

User accounts

Go to People → User accounts. The page opens with a count ("9 accounts") and a table of every account in your company.

An employee record and a login are two different things

An employee record holds a person's details, salary, leave and documents. A user account is the login they sign in with. They are linked but separate:

  • You can hold an employee record for someone who cannot sign in at all — new joiners often start this way.
  • An administrator can have a login with no employee record, shown on their account page as No employee record linked.
  • Suspending or deactivating an account never touches the employee record, and vice versa.

Creating a login for an employee

You create a login from the person's record, not from the User accounts list — that way the new account is linked to the existing record instead of creating a second employee.

  1. Go to People → Employees and open the person, for example Priya Sharma.
  2. Find the User account card. If they have no login it says "This employee cannot sign in yet."
  3. Check Login email. It is pre-filled with their work email where one is on record.
  4. Choose one route:
    • Send invite — emails an activation link so they set their own password. The link is also shown on screen so you can hand it over directly. It is valid for three days.
    • Create login under Or set a temporary password — creates the account immediately and forces a password change at first sign-in. Leave the box blank to have one generated, or type your own.
  5. Copy the link or password from the green panel and click I've saved this. It is shown once only; dismissing the panel reloads the record and the value is gone for good.

New logins are created with the Employee role. Grant anything further from the account page, below.

If the person already has an account, the card instead shows Signs in as: with their email and a Manage account → link. An email already used by another account is refused.

Reading the accounts list

Column What it shows
User Name and email address
Status Active, Invited, Suspended or Deactivated, plus a Must change password badge where one is pending
Roles Every role granted on that account
Last sign-in Date and time in IST, or Never signed in
Manage Opens the account

Use Search (name or email), the Status and Role filters, then Apply; Clear removes them. The list shows 25 accounts a page with ← Previous and Next → below it.

Account statuses

Status What it means How it is reached
Active Can sign in normally Invitation accepted, a temporary password set, or an admin clicks Activate account
Invited Invitation sent, not yet accepted; cannot sign in until it is Created through Send invite
Suspended A temporary block. Signed out everywhere and cannot sign in An admin clicks Suspend
Deactivated For someone who has left. Signed out everywhere and cannot sign in An admin clicks Deactivate, or offboarding revokes access

A suspended or deactivated person cannot sign in at all until an administrator activates the account again. Their employee record, documents and history stay exactly as they were.

Resetting a password

Open the account and use the Password reset card.

  • Generate reset link creates a one-hour link the person uses to set their own password. It is emailed if email is configured for your workspace, and shown on screen either way so you can pass it on. Use Copy; it is shown once.
  • Set password under Set a temporary password sets a password immediately and makes the person change it at their next sign-in. Leave the box blank and one is generated for you. A password you type needs 10 characters or more, with upper and lower case, a number and a symbol.

Setting a temporary password ends every session the person has open and also clears a lockout, so it is the quickest fix for someone locked out after repeated failed attempts. It leaves the account Active.

Neither the reset link nor the temporary password can be retrieved later. If you lose it before handing it over, generate another.

Blocking access

The Account card carries three controls, each of which asks you to confirm and each of which signs the person out of every device immediately.

Control Effect
Suspend Temporary block. Available only while the account is Active.
Deactivate For someone who has left. Locks them out of the portal; the employee record stays.
Sign out everywhere Ends every open session and nothing else. If the account is active they can sign straight back in.

When an account is not Active the card instead offers Activate account — which lets them sign in again with the password they already have — and, for an invited account, Resend invite, which issues a fresh three-day link.

Two guards you will meet:

  • You cannot suspend, deactivate or force-sign-out your own account. The card says so.
  • You cannot block the last active Super Admin: "This is the last active Super Admin. Give someone else the Super Admin role before blocking this account."

If you are HR / Ops, the buttons on another Super Admin's account are visible but the action is refused — "Only a Super Admin can manage another Super Admin." Ask a Super Admin to do it.

Granting and removing roles

The Roles & access card lists all six roles with a one-line summary of what each opens up. Only a Super Admin can change them; HR / Ops sees the same list read-only with "Only a Super Admin can change the roles on an account."

  1. Tick a role to grant it, untick to revoke it. Each change saves on the spot — there is no separate save button.
  2. The change takes effect the next time that person loads a page, so ask them to refresh.
Role What it grants, as stated on screen
Super Admin Everything, including roles and company settings
HR / Ops People, onboarding, leave, attendance, documents, policies and reviews
Manager Approves leave and attendance for their team and writes reviews
Finance Salary, payslips, payroll runs and the payroll report
Employee Self-service only — their own profile, leave, payslips and documents
Reporting Views and exports reports. No people or payroll data beyond that

A person can hold several roles, and permissions add up. The last Super Admin role in the company cannot be removed: "This is the last Super Admin. Grant the role to someone else before removing it here." Roles and permissions has the full matrix.


Sign-in activity

My space → Sign-in activity shows recent sign-ins, sign-outs and failed attempts on your own account, newest first, with a Change password button beside it. Anyone who can manage user accounts also sees the same table at the foot of each account page under Sign-in activity.

Each row shows the event, the device as read from the browser (Chrome · Windows, or Unknown device when nothing was recorded), the IP address, and the time in IST.

Event What happened
Signed in A successful sign-in
Signed out The person signed out themselves
Signed out — by an administrator An admin used Sign out everywhere
Signed out — password changed A password change or reset ended the session
Signed out — offboarding Sessions ended as part of an exit
Signed out — account deactivated The account was suspended or deactivated
Signed out — all devices Every session was ended
Failed sign-in — wrong password The password did not match
Sign-in blocked — account locked Too many failed attempts; the account was locked
Failed sign-in — 2FA not completed The password was right but the two-factor code never followed
Failed sign-in — wrong 2FA code The code was wrong
Failed sign-in A failure with no more specific reason recorded

On an account with two-factor turned on, the routine intermediate step of a normal sign-in is not listed — you see one Signed in row, not two. A Failed sign-in — 2FA not completed row is the exception that is kept deliberately: someone knew the password and stopped at the code. Treat it as a signal, change your password and tell HR.

Worth knowing. Your own list shows up to the 50 most recent events and says "Showing the 50 most recent events." when it is full. An administrator viewing someone else's account sees up to the 25 most recent. Neither list pages further back, so there is no way to reach older history from the interface. Notifications is capped the same way, at the 40 most recent.


What the audit log records

Separately from sign-in history, MusterHR keeps an append-only audit log of consequential actions across the whole workspace. Each entry records who did it, what was affected, a plain-language summary, the time, and the IP address and browser it came from. Actions are classified as create, update, delete, sensitive read, sign-in, sign-out, permission change or export.

Things that are written to it include:

  • Revealing a masked field — bank account, IFSC, PAN or Aadhaar on an employee record. Unmasking is recorded against your name every time.
  • Viewing or downloading a payslip, a salary structure or a salary history.
  • Downloading a document from an employee's file.
  • Exporting a report CSV or an attendance export.
  • Granting or revoking a role, and changing an account's status.
  • Changing your brand colour or logo, including resetting to the default.
  • Ordinary record changes across people, leave, attendance, payroll, policies, assets and offboarding.

Worth knowing. There is no screen in MusterHR that displays the audit log. It is written for compliance and support, and reading it back is a support or database task rather than something you can browse. If you need an extract, write to hello@musterhr.com.

Sensitive fields are encrypted at rest and masked on screen; the audit entry references what was read rather than storing the value again. See Employee records and profiles for how masking behaves day to day.


Where to go next

Something unclear on this page? Tell us.