Three switches govern the module company-wide, under Settings › Benefits › Settings. They are enforced by the server, not just by the interface: turning self-service off genuinely refuses an enrollment submitted by an employee.
The three settings #
| Setting | Effect when switched off |
|---|---|
| Enable the Benefits module | The whole module becomes unreachable, for employees and administrators alike. |
| Employee self-service | Employees can no longer enroll or unenroll themselves. Enrollments are recorded by an administrator. |
| Allow life-event declaration | The banner disappears for employees and declarations are refused. |
Automatic enrollment #
Under Automatic enrollment, the page also lists which active benefits enroll employees without any action on their part, with the enrolled count. The setting itself is made benefit by benefit, in the catalogue.
Who sees what #
Access is governed in the Roles & permissions matrix and nowhere else: one capability grants module access, another grants administration. Being an admin does not bypass the matrix — if a capability is revoked from a role, it is revoked for everyone.
