Skip to main content
Skip table of contents

Authorization concept

The authorization concept in Nesto enables you to allow certain functions for each employee. Either predefined roles can be used for this or rights can be assigned individually.

Where can I find the system access??

System access must be activated for each employee and can be found in the navigation menu under Employees > Master Data - then select an employee and navigate to the System access tab. Employees must have an e-mail address stored for access, as this is required to activate an account. If an e-mail address is stored, system access is granted in the first step.

image-20250611-084734.png

How can I assign rights to an employee?

The prerequisite for assigning authorizations is that the employee has access to Nesto. A distinction is then made between the authorizations of the employee app and the authorizations of Nesto Backoffice.

User roles can be assigned in Nesto Backoffice.

image-20250611-085041.png
image-20250611-085126.png
image-20250611-085220.png

Can rights also be assigned individually?

Yes, it is generally possible to grant each user more or fewer rights. If a role has too few rights, additional rights can be added. Conversely, if a role has too many rights, you can simply select a role with fewer rights or no rights for the employee and then assign them individual rights. However, user roles themselves cannot be customized.

image-20250611-085340.png

 

image-20250611-085446.png

 

Can an employee have different rights at different locations?

Yes, the rights are assigned per location. For example, an employee can have the manager role at one location, the assistant role at another location and only one right (e.g. control of recorded working hours) at a third location.

Which role has which rights?

 

Brief description of the roles:

Icon-Admin.png

Admin

Usual role in the company: Nesto manager or management

Rights include: Granting back office rights, distributing new administrator roles, processing requirements planning

Icon-Managerin.png  

Manager

Usual role in the company: Person responsible for an organizational unit, e.g. operations management

Rights include: Full access to employee master data, all operationally necessary rights, creation of new employees, rights for the employee app (but no rights for the back office), daily closing, approval of duty rosters

 

Icon-HR-Managerin.png

HR manager

Usual role in the company: HR manager

Rights include: Full access to employee master data and the back office, assignment of further back office rights, payroll details, access to individual evaluations

 

Icon-Controllerin.png

Controller

Usual role in the company: Controller, area manager

Rights include: Viewing duty rosters and key figures, reopening completed days

 

Icon-Assistentin.png

Assistant

Usual role in the company: Employees who perform initial management tasks

Rights include: Checking and correcting recorded working times, creating duty rosters (but not granting approval) 

 

Detailed information on the rights of a user role:

 

Shopfloor management

Icon-Admin.png

Admin

Icon-Controllerin.png

Controller

Icon-HR-Managerin.png

HR manager

Icon-Managerin.png

Manager

Icon-Assistentin.png  

Assistant

Shopfloor management dashboard

Icon-Check.png

Icon-Check.png

Icon-Cross.png

Icon-Check.png

Icon-Check.png

Report sick on dashboard

Icon-Check.png

Icon-Check.png

Icon-Cross.png

Icon-Check.png

Icon-Check.png

Labor scheduling

Icon-Admin.png

Admin

Icon-Controllerin.png

Controller

Icon-HR-Managerin.png

HR manager

Icon-Managerin.png

Manager

Icon-Assistentin.png  

Assistant

Day planner

Icon-Check.png

Icon-Check.png

Icon-Cross.png

Icon-Check.png

Icon-Check.png

Week planner

Icon-Check.png

Icon-Check.png

Icon-Cross.png

Icon-Check.png

Icon-Check.png

Month planner

Icon-Check.png

Icon-Check.png

Icon-Cross.png

Icon-Check.png

Icon-Check.png

Employee-centered planner

Icon-Check.png

Icon-Check.png

Icon-Cross.png

Icon-Check.png

Icon-Check.png

Release labor schedule

Icon-Check.png

Icon-Cross.png

Icon-Cross.png

Icon-Check.png

Icon-Cross.png

Release labor schedule with violations

Icon-Check.png

Icon-Cross.png

Icon-Cross.png

Icon-Cross.png

Icon-Cross.png

View planned labor cost ratio

Icon-Check.png

Icon-Check.png

Icon-Cross.png

Icon-Check.png

Icon-Cross.png

View planning-relevant data from employees in other organizational units[1]

Icon-Check.png

Icon-Check.png

Icon-Cross.png

Icon-Check.png

Icon-Cross.png


[1] View planning-relevant data for other locations: This right enables you to view the availabilities, planned and recorded working times of employees who are loaned to other organizational units.

Recorded working times

Icon-Admin.png

Admin

Icon-Controllerin.png

Controller

Icon-HR-Managerin.png

HR manager

Icon-Managerin.png

Manager

Icon-Assistentin.png  

Assistant

View recorded working times (incl. editing comments)

Icon-Check.png

Icon-Check.png

Icon-Check.png

Icon-Check.png

Icon-Check.png

Change recorded working times

Icon-Check.png

Icon-Check.png

Icon-Check.png

Icon-Check.png

Icon-Check.png

Execute labor cost simulation

Icon-Check.png

Icon-Check.png

Icon-Check.png

Icon-Check.png

Icon-Check.png

Execute labor cost simulation incl. management costs

Icon-Check.png

Icon-Check.png

Icon-Check.png

Icon-Check.png

Icon-Cross.png

Labor cost report

Icon-Check.png

Icon-Cross.png

Icon-Check.png

Icon-Check.png

Icon-Cross.png

Perform daily closing

Icon-Check.png

Icon-Cross.png

Icon-Cross.png

Icon-Check.png

Icon-Cross.png

Withdraw daily closing

Icon-Check.png

Icon-Check.png

Icon-Cross.png

Icon-Cross.png

Icon-Cross.png

Evaluation

Icon-Admin.png

Admin

Icon-Controllerin.png

Controller

Icon-HR-Managerin.png

HR manager

Icon-Managerin.png

Manager

Icon-Assistentin.png  

Assistant

Day analysis

Icon-Check.png

Icon-Check.png

Icon-Cross.png

Icon-Check.png

Icon-Check.png

Benchmarking

Icon-Check.png

Icon-Check.png

Icon-Check.png

Icon-Check.png

Icon-Check.png

Performance evaluation

Icon-Check.png

Icon-Check.png

Icon-Cross.png

Icon-Check.png

Icon-Cross.png

Vacation planning

Icon-Admin.png

Admin

Icon-Controllerin.png

Controller

Icon-HR-Managerin.png

HR manager

Icon-Managerin.png

Manager

Icon-Assistentin.png  

Assistant

Vacation overview

Icon-Check.png

Icon-Check.png

Icon-Check.png

Icon-Check.png

Icon-Check.png

Vacation reduction

Icon-Check.png

Icon-Check.png

Icon-Check.png

Icon-Check.png

Icon-Cross.png

 

Employee master data

Icon-Admin.png

Admin

Icon-Controllerin.png

Controller

Icon-HR-Managerin.png

HR manager

Icon-Managerin.png

Manager

Icon-Assistentin.png  

Assistant

Full access

Icon-Check.png

Icon-Cross.png

Icon-Check.png

Icon-Check.png

Icon-Cross.png

General

Icon-Check.png

Icon-Check.png

Icon-Check.png

Icon-Check.png

Icon-Check.png

Personal

Icon-Check.png

Icon-Check.png

Icon-Check.png

Icon-Check.png

Icon-Cross.png

Contract data

Icon-Check.png

Icon-Check.png

Icon-Check.png

Icon-Check.png

Icon-Cross.png

See management costs

Icon-Check.png

Icon-Cross.png

Icon-Cross.png

Icon-Cross.png

Icon-Cross.png

Availabilities

Icon-Check.png

Icon-Check.png

Icon-Check.png

Icon-Check.png

Icon-Cross.png

Qualifications

Icon-Check.png

Icon-Check.png

Icon-Check.png

Icon-Check.png

Icon-Cross.png

Working hours

Icon-Check.png

Icon-Check.png

Icon-Check.png

Icon-Check.png

Icon-Check.png

Working time account

Icon-Check.png

Icon-Check.png

Icon-Check.png

Icon-Check.png

Icon-Cross.png

Absences

Icon-Check.png

Icon-Check.png

Icon-Check.png

Icon-Check.png

Icon-Cross.png

Notes

Icon-Check.png

Icon-Cross.png

Icon-Check.png

Icon-Check.png

Icon-Cross.png

Special payments

Icon-Check.png

Icon-Cross.png

Icon-Check.png

Icon-Check.png

Icon-Cross.png

Delete employee

Icon-Check.png

Icon-Cross.png

Icon-Check.png

Icon-Check.png

Icon-Cross.png

Employee document management

Icon-Admin.png

Admin

Icon-Controllerin.png

Controller

Icon-HR-Managerin.png

HR manager

Icon-Managerin.png

Manager

Icon-Assistentin.png  

Assistant

Full access

Icon-Check.png

Icon-Cross.png

Icon-Check.png

Icon-Check.png

Icon-Cross.png

Incoming documents

Icon-Check.png

Icon-Cross.png

Icon-Check.png

Icon-Check.png

Icon-Check.png

Read

Icon-Check.png

Icon-Cross.png

Icon-Check.png

Icon-Check.png

Icon-Cross.png

Upload 

Icon-Check.png

Icon-Cross.png

Icon-Check.png

Icon-Check.png

Icon-Cross.png

Delete

Icon-Check.png

Icon-Cross.png

Icon-Check.png

Icon-Check.png

Icon-Cross.png

Employee system access

Icon-Admin.png

Admin

Icon-Controllerin.png

Controller

Icon-HR-Managerin.png

HR manager

Icon-Managerin.png

Manager

Icon-Assistentin.png  

Assistant

System access[2]

Icon-Check.png

Icon-Cross.png

Icon-Check.png

Icon-Check.png

Icon-Cross.png

My Nesto (employee app) 

Icon-Check.png

Icon-Cross.png

Icon-Check.png

Icon-Check.png

Icon-Cross.png

Assign authorizations for Nesto Backoffice[3]

Icon-Check.png

Icon-Cross.png

Icon-Cross.png

Icon-Cross.png

Icon-Cross.png


[2] System access: Basic access to the system (log in, change password, etc.)

[3] Nesto back office: Only authorizations and roles that are assigned to you can be assigned.

Employee archive

Icon-Admin.png

Admin

Icon-Controllerin.png

Controller

Icon-HR-Managerin.png

HR manager

Icon-Managerin.png

Manager

Icon-Assistentin.png  

Assistant

Read employee archive

Icon-Check.png

Icon-Cross.png

Icon-Check.png

Icon-Cross.png

Icon-Cross.png

Reactivate employee

Icon-Check.png

Icon-Cross.png

Icon-Check.png

Icon-Cross.png

Icon-Cross.png

Payroll export

Icon-Admin.png

Admin

Icon-Controllerin.png

Controller

Icon-HR-Managerin.png

HR manager

Icon-Managerin.png

Manager

Icon-Assistentin.png  

Assistant

Location transmission

Icon-Check.png

Icon-Check.png

Icon-Check.png

Icon-Check.png

Icon-Cross.png

Employee overview

Icon-Check.png

Icon-Check.png

Icon-Check.png

Icon-Check.png

Icon-Cross.png

Employees

Icon-Check.png

Icon-Cross.png

Icon-Check.png

Icon-Cross.png

Icon-Cross.png

Central document upload

Icon-Check.png

Icon-Cross.png

Icon-Check.png

Icon-Cross.png

Icon-Cross.png

Export

Icon-Admin.png

Admin

Icon-Controllerin.png

Controller

Icon-HR-Managerin.png

HR manager

Icon-Managerin.png

Manager

Icon-Assistentin.png  

Assistant

Full access

Icon-Check.png

Icon-Cross.png

Icon-Check.png

Icon-Check.png

Icon-Cross.png

Working times

Icon-Check.png

Icon-Cross.png

Icon-Check.png

Icon-Check.png

Icon-Check.png

Absences

Icon-Check.png

Icon-Cross.png

Icon-Check.png

Icon-Check.png

Icon-Check.png

Employee lists[4]

Icon-Check.png

Icon-Cross.png

Icon-Check.png

Icon-Check.png

Icon-Check.png

Payroll exports

Icon-Check.png

Icon-Cross.png

Icon-Check.png

Icon-Check.png

Icon-Cross.png

Vacation accruals

Icon-Check.png

Icon-Cross.png

Icon-Check.png

Icon-Check.png

Icon-Cross.png

Monthly vacation accruals

Icon-Check.png

Icon-Cross.png

Icon-Check.png

Icon-Cross.png

Icon-Cross.png

Working time change history 

Icon-Check.png

Icon-Cross.png

Icon-Check.png

Icon-Check.png

Icon-Cross.png

Support assignments[5]

Icon-Check.png

Icon-Cross.png

Icon-Check.png

Icon-Check.png

Icon-Cross.png

Total annual surcharges[6] 

Icon-Check.png

Icon-Cross.png

Icon-Check.png

Icon-Check.png

Icon-Cross.png

Working time accruals

Icon-Check.png

Icon-Cross.png

Icon-Check.png

Icon-Check.png

Icon-Cross.png


[4] Employee list: Only master data that can be viewed can be exported.

[5] Support assignments: Overview of borrowed employees and the hours worked

[6] Total annual surcharges: A comparison of the actual surcharges earned and the flat-rate surcharges paid out.

Local settings(1/2)

Icon-Admin.png

Admin

Icon-Controllerin.png

Controller

Icon-HR-Managerin.png

HR manager

Icon-Managerin.png

Manager

Icon-Assistentin.png  

Assistant

General

 

 

 

 

 

Read store information

Icon-Check.png

Icon-Check.png

Icon-Check.png

Icon-Check.png

Icon-Cross.png

Manage store information

Icon-Check.png

Icon-Check.png

Icon-Check.png

Icon-Check.png

Icon-Cross.png

Read positions

Icon-Check.png

Icon-Check.png

Icon-Check.png

Icon-Check.png

Icon-Check.png

Manage positions

Icon-Check.png

Icon-Check.png

Icon-Cross.png

Icon-Check.png

Icon-Cross.png

Read opening hours

Icon-Check.png

Icon-Check.png

Icon-Check.png

Icon-Check.png

Icon-Cross.png

Manage opening hours

Icon-Check.png

Icon-Check.png

Icon-Check.png

Icon-Check.png

Icon-Cross.png

Demand planning

 

 

 

 

 

Read dynamic staffing requirements

Icon-Check.png

Icon-Check.png

Icon-Cross.png

Icon-Check.png

Icon-Cross.png

Manage dynamic staffing requirements

Icon-Check.png

Icon-Cross.png

Icon-Cross.png

Icon-Cross.png

Icon-Cross.png

Read minimum staffing requirements

Icon-Check.png

Icon-Check.png

Icon-Cross.png

Icon-Check.png

Icon-Cross.png

Manage minimum staffing requirements

Icon-Check.png

Icon-Cross.png

Icon-Cross.png

Icon-Cross.png

Icon-Cross.png

Read additional staffing requirements 

Icon-Check.png

Icon-Check.png

Icon-Cross.png

Icon-Check.png

Icon-Cross.png

Manage additional staffing requirements

Icon-Check.png

Icon-Cross.png

Icon-Cross.png

Icon-Cross.png

Icon-Cross.png

Read other planning settings[7]

Icon-Check.png

Icon-Cross.png

Icon-Cross.png

Icon-Cross.png

Icon-Cross.png

Manage other planning settings[8]

Icon-Check.png

Icon-Cross.png

Icon-Cross.png

Icon-Cross.png

Icon-Cross.png

Automatic planning

 

 

 

 

 

Read shift proposals

Icon-Check.png

Icon-Check.png

Icon-Cross.png

Icon-Check.png

Icon-Cross.png

Manage shift proposals

Icon-Check.png

Icon-Check.png

Icon-Cross.png

Icon-Check.png

Icon-Cross.png

[7][8] Other planning settings: overwrite sales forecast, temporary staff can be scheduled above maximum hours

Local settings(2/2)

Icon-Admin.png

Admin

Icon-Controllerin.png

Controller

Icon-HR-Managerin.png

HR manager

Icon-Managerin.png

Manager

Icon-Assistentin.png  

Assistant

Time recording

 

 

 

 

 

Read configuration

Icon-Check.png

Icon-Cross.png

Icon-Cross.png

Icon-Cross.png

Icon-Cross.png

Read registered devices

Icon-Check.png

Icon-Check.png

Icon-Check.png

Icon-Check.png

Icon-Cross.png

Manage registered devices

Icon-Check.png

Icon-Cross.png

Icon-Check.png

Icon-Cross.png

Icon-Cross.png

Notifications

 

 

 

 

 

Read notifications

Icon-Check.png

Icon-Cross.png

Icon-Check.png

Icon-Check.png

Icon-Cross.png

Manage notificaitons

Icon-Check.png

Icon-Cross.png

Icon-Check.png

Icon-Cross.png

Icon-Cross.png

Employee app

 

 

 

 

 

Read features

Icon-Check.png

Icon-Cross.png

Icon-Cross.png

Icon-Cross.png

Icon-Cross.png

Manage features

Icon-Check.png

Icon-Cross.png

Icon-Cross.png

Icon-Cross.png

Icon-Cross.png

Read deadline for desired times

Icon-Check.png

Icon-Cross.png

Icon-Cross.png

Icon-Check.png

Icon-Check.png

Manage deadline for desired times

Icon-Check.png

Icon-Cross.png

Icon-Cross.png

Icon-Check.png

Icon-Cross.png

Payroll export

 

 

 

 

 

Read payroll simulation

Icon-Check.png

Icon-Cross.png

Icon-Check.png

Icon-Cross.png

Icon-Cross.png

Manage payroll simulation

Icon-Check.png

Icon-Cross.png

Icon-Check.png

Icon-Cross.png

Icon-Cross.png

Global settings

Icon-Admin.png

Admin

Icon-Controllerin.png

Controller

Icon-HR-Managerin.png

HR manager

Icon-Managerin.png

Manager

Icon-Assistentin.png  

Assistant

Manage contract templates, special payments, document categories

Icon-Check.png

Icon-Cross.png

Icon-Check.png

Icon-Cross.png

Icon-Cross.png

Customize employee app background image

Icon-Check.png

Icon-Cross.png

Icon-Cross.png

Icon-Cross.png

Icon-Cross.png

JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.