Skip to content
All guides

Getting Started · Updated September 5, 2026

Company Setup & User Management

Configure your company profile, build out departments, positions and teams, invite people and assign roles, and understand how billing and module licensing decide what your team can see.

This guide covers the administrative surface of Arche: the Company Settings area, your org structure (departments, positions, teams and the org chart), how users and roles work, and how billing ties to the modules your company can use. If you are setting up a brand-new company, read the Quick Start Guide first, it walks through the same ground in the order you would actually do it. This article is the reference for what each screen does and who can use it.

Company Settings

Open Company Settings → Settings (/settings/company). Viewing the page needs view_company or manage_company; editing anything on it needs manage_company. The page is organized into five tabs.

Company Profile

Your company's identity: name, industry, website, company email, phone, HR/reply-to email (used as the Reply-To on system emails), physical address, city, country, KRA PIN, a legacy field still labelled NHIF Number, and NSSF employer number. The legacy label is not the current SHIF contribution setup; statutory payroll settings are configured separately.

You can also upload a company logo (PNG, JPG, SVG or WebP, up to 2 MB, 200×200px or larger recommended). It appears on branded PDFs such as payslips.

Payroll Settings

Two things live here:

  • Currency: the currency pay runs and salaries are denominated in (KES, USD, EUR or GBP). Pay frequency is set per employee on their salary structure, not here. PAYE, SHIF, NSSF and Housing Levy rates live in Payroll → Salary Setup.
  • Require a separate approver for pay runs: off by default. When on, the person who created a pay run cannot also approve it (maker-checker for payroll). Leave it off if you run payroll with a single operator, turning it on with no second approver blocks payroll entirely. See the Payroll Workflow Guide for how this interacts with the approve_payroll permission.

Approvals

  • Senior Escalation Approver: when someone senior enough that their own approval chain would otherwise be empty (they are the manager) submits a leave request or salary advance, this person reviews it instead of the request auto-approving.
  • Leave entitlements, carry-over, probation gates and approval chains are configured per leave type, not company-wide. This tab links you through to Leave Settings for that.

Email Templates

Customize the wording of the automated emails Arche sends (invitations, password resets, notifications) for your company.

M-PESA Integration

Where you connect your Safaricom Daraja credentials so completed pay runs can disburse salaries by M-Pesa. See the "Paying Salaries by M-Pesa" guide for the full setup walkthrough.

Departments, Positions, and Teams

These live under People in the sidebar and are part of Core HR, which is always on.

  • Departments (/departments) can nest under a parent to build a tree (a Tree View toggle lets you check the hierarchy), and each can have a department head. Deleting one deactivates it by default; a permanent delete is only allowed once it has no employees and no child departments.
  • Positions (/positions) are job titles, optionally linked to a department, with a grade and a salary band (min/max) visible only to full admins.
  • Teams (/teams) cut across departments, with a team lead and a membership list you manage directly.

Their APIs require manage_employees to create or edit and view_employees to read. The web editing controls additionally require company-wide HR-operator access: manage_users, or both manage_employees and manage_payroll. The Quick Start Guide has the full field-by-field walkthrough for setting these up in order.

Org Chart

Org Chart (/org-chart, needs view_employees) draws the reporting-line tree from the manager assigned on each employee record. It is searchable, and you can expand or collapse the whole tree at once. A Department Manager sees only themselves and their own reporting subtree; everyone else with access sees the full company tree. There is nothing to configure here directly, it reflects whatever managers are set on employee profiles.

Users

Company Settings → Users (/users, needs manage_users) is a read-only directory: everyone with a login at your company, their role, active/inactive status, and when their account was created, with totals at the top.

This page does not create accounts. Giving someone a login happens on their employee record, not here:

  • Open the employee's profile and use Create account: supply or override their email, leave the password blank so they get an email link to set their own, and assign a role.
  • If the person already has an account elsewhere (for example, an admin who is also an employee), use Link account instead of creating a duplicate.
  • To bring many people on at once, batch-create accounts from a list of employees with the same role; anyone who already has an account is skipped.

See the Quick Start Guide, Step 6, for the walkthrough.

Roles & Permissions

Company Settings → Roles & Permissions (/permissions, needs manage_role) is a read-only view: your company's roles (the seven standard ones, plus any custom roles already on your account) and a Role × Permission Matrix showing exactly which permissions each role grants, sourced from the same permission catalog the server enforces.

There is currently no interface to create a custom role or change what a standard role grants. If your seven default roles (Admin, HR Manager, Finance Manager, Department Manager, Recruiter, Compliance Officer, Employee) do not fit, talk to Arche support. Role names are company-specific labels either way: permission checks is against the underlying permission (like manage_payroll or view_employees), never against a role's display name, so renaming or repurposing a role does not silently change what it can do.

Billing

Company Settings → Billing (/settings/billing, needs manage_billing) is where a company manages its own subscription and module selection, separate from the platform-operator tools Arche staff use internally.

The page shows your current plan, amount due (including VAT), subscription status, and when the current period ends, plus which modules your subscription currently includes ("Your Modules").

Build Your Plan lets you select a modular or enterprise product, employee count, module choices, and billing frequency. Minimum seats, module counts, limits, rates, and discounts are read from the billing catalog; use the figures shown in the current quote instead of a fixed price in this guide.

The page supports M-Pesa subscription payment and displays payment history. A displayed quote or pending payment is not confirmation that payment completed. Check the payment and subscription status after the payment flow.

Module licensing

A module is a feature area, Payroll, Time & Attendance, Leave, Recruiting, Onboarding, Performance, Compensation, Benefits, Expenses, Salary Advance, Compliance, Reports & Analytics, Data Export, AI Assistant, and Webhooks, plus Core HR, which every company always has. Whether a module is licensed for your company controls whether its nav items, pages and API routes are reachable at all: an unlicensed module simply does not appear in the sidebar, regardless of what permissions a user holds.

For a normal company admin, module licensing is managed through the Billing page above: the modules you select and pay for in Build Your Plan are the modules that get switched on. There is no separate self-service "licensing" screen for tenant admins; if you need modules added or changed outside of what Billing supports (for example during a sales negotiation), that is handled by the Arche team directly.

Frequently asked questions

Can I create a custom role from the interface? Not currently. Roles & Permissions is read-only, showing you the seven standard roles and any existing custom roles with their exact permission grants. Contact Arche support if you need something different.

Why can't I find an "Invite User" button? There isn't one, on purpose. For employee self-service access, create the employee first (People → Employees), then use Create account on their profile to give them a login. The Users page only lists who already has access.

What is the difference between the Users page and the employee list? Employees (/employees) are HR records: everyone who works at your company, whether or not they can log in. Users (/users) are logins: a subset of employees (plus, rarely, someone without an employee record) who can sign in. Creating an account links the two.

Do I need to be a platform admin to manage billing? No. Billing (/settings/billing) is scoped to your own company and only needs the manage_billing permission, which the Admin role has by default. Platform-wide tools like Tenant Companies and Module Licensing under /platform/* are separate, and only visible to Arche's own platform operators.

Where do I change what modules my company can use? Company Settings → Billing. Pick the modules you want under Build Your Plan and pay via M-Pesa; check the payment status and Your Modules after payment completes.

I deactivated a department by mistake. Is it gone? No, the default delete is a soft delete. Edit the department and set it active again. A permanent delete only works once it has no employees or child departments, and cannot be undone.

Can I see what a role can do before I assign it to someone? Yes. Company Settings → Roles & Permissions shows the full matrix, filter or search it for the permission you care about and check which roles have it.