Admin Manual
🔧 For Admin · Care Manager · Scheduler
Three staff members talking in the nurses' station
Manual 2 of 5 · Admin Manual · As of r771

Rosie — The Full Configuration

The complete reference for administrators, care management and schedulers. From initial setup through structures, shifts and wish budget to month-end close, audit ledger and observability — everything you need to run Rosie.

🔧 Admin 🧙 Wizard 🤖 AI Planning ⚖️ Legal Engine As of r771
🏠

Welcome, Administrator

What you control — and where to best begin

Switch back to mobile view

As an admin you control everything: employees, structures, shifts, plans, approvals, reports. Recommendation on first login: run through the Onboarding Wizard, then Structures → Shifts → Wish Budget, and finally create your first plan.

ℹ️
Newly set up? Start below with the 6-step assistant — it guides you through privacy, company, shifts, employee import and target hours.
Bright corridor in the morning, a care worker on her way
Setting up

Getting the organisation running

From an empty system to a working home: wizard, roles, structures, staff, shift types and contracted hours.

🧙

6-Step Assistant

Sign-up with company search, step 0–5, resumable
Before the assistant: signing up

When a new organization signs up, ROSIE suggests matching entries from the commercial register (Zefix) in the first step, from three characters onwards. If you pick a suggestion, ROSIE fills in the company name, address, postcode, town and canton; everything stays editable. If the search finds nothing or can’t be reached, you enter the details by hand — “Next” always remains possible. Weekly hours at 100% (20–50 h) and working days per week (5, 6 or 7) are required; ROSIE doesn’t suggest a number.

The setup assistant walks you through 6 steps (0–5): Privacy notice → Company → Shifts → Import employees → Target hours → Done. A progress indicator shows the current step. If you close the assistant mid-way (step 1–4), it asks for confirmation; once confirmed, it remembers ONLY the step position (not your entries) locally in the browser and offers to resume there or start over next time you open it.

0 · Privacy notice
What's imported / not imported (AHV, IBAN, religion, salary are excluded) — confirmation required.
1 · Company
Company name, canton, industry (free text).
2 · Shifts
A pure info screen — there are no industry templates anymore, you create shift types yourself under Admin → Shifts afterwards.
3 · Import employees
CSV/Excel import (11-field whitelist, sensitive fields ignored) or skip; invitation emails via toggle.
4 · Target hours
Weekly hours at 100% (20–50 h) and working days per week (5, 6 or 7) — both required, with no suggested value. A value once set can be changed later under Admin → Company, but not saved empty.
5 · Done
Summary, jump straight to schedule or employee list.
🏷️

Roles, Permissions, Approver Boxes

Free per tenant — no rigid hierarchy

Roles are freely definable per tenant (Structures → Roles). Per employee: multi-roles + "display role" for the display; additional flags: isScheduler, Springerpool, mayMessageAll.

Choose four separate approver boxes per role:

📅
Shift Planning
Who may create and publish plans.
⏰
Shift-Time Changes (STC)
Who approves shift-time changes. Someone who may approve but not plan finds open requests in the “Plan” tab under “My Requests” → “To approve”.
📋
Task Responsible
r162 — replaces the 3 old boxes (Author, QMS Upload, Delegation) with one.
🔁
Shift Swap (Mutations)
Who approves swap requests.
💡
Tip: The viewAs mode allows a test as an employee. Outdated hierarchy assumptions (Dev > Admin > Care Manager > …) are obsolete.
🏗️

Departments, Areas, Roster Groups

Four sub-pills in the Structures tab

The Structures tab has 4 sub-pills:

🏷️
Roles (top)
Roles + 4 approver boxes.
🏢
Departments / Stations
renderTeamManager.
🎨
Areas
Name + color per area.
📌
Roster Groups
Label + color for employee categorization.

Office-day time is set globally (start/break/end). Office days per role (count, frequency week/month).

Planning weekends and office days

Under Admin → Structures → Roles, you choose how scheduling handles weekends and office days. These settings apply to your organisation.

Full weekends

When this setting is active, scheduling prefers people for Sunday who already worked on Saturday. It may depart from this preference when someone is overloaded or coverage is insufficient. The setting therefore does not guarantee that the same people always work both days.

Office day or shift coverage

With Shifts first, scheduling moves the office day if shifts might otherwise remain uncovered. With Office first, the day stays reserved; this can leave gaps in shift coverage.

Count office days towards planned hours

With Yes, the office day’s duration counts towards the person’s planned working hours. With No, it remains outside the distribution of hours. This choice controls scheduling.

Office day replaces or supplements a shift

Inclusive reserves the day for office work. Additive allows an additional shift on the same day if working times and labour law permit it. The office day and shift must belong to the same planning area.

🏥

Industry

Free text, no templates

Under Company you enter the industry as free text (e.g. care, hospitality, home care, cleaning services). There are no industry templates or shift-type suggestions — the field is purely for internal reporting, you always create shifts yourself under Admin → Shifts.

👥

Manage Employees

Create, send access, record an exit

"+ Employee" → required fields first name/last name/email/role. The team list shows each person in a compact row. For people with access, “Message” (speech bubble) opens a conversation directly; for people without access but with an email on file, “Send access” (open padlock) appears instead. In the edit modal you maintain:

📇
Master Data
Name, email, phone, address, start date.
💼
Status & Workload
active / inactive / sick / accident · workload %.
🏷️
Multi-Roles + Display Role
Several roles, one is shown.
💵
Pay Type
Hourly or monthly pay, salary, AHV, IBAN.
🔑
Login
Login email + password. “Send access” sends a link with which the person sets their password themselves (valid for 7 days).
🚫
Restrictions
e.g. not-with-person / not-on-days.
🛠️
Help Tools
4 toggles per employee: enabled / agent / quickAccess / proactive.
🖼️
Profile Photo
Everyone uploads or removes their own photo under “My profile”; you can also set it here. The app shrinks it. Small in front of the name in every plan, not in the JPG export and not in print.
🚪
Exit
“Exit date (last working day)” and “Reason for leaving”. Up to and including that day the person remains normally schedulable, after that no longer. An exit deletes nothing.
⚠️
Phantom profiles (incomplete) are marked with a yellow warning and hidden in the grid. Access by click: “Send access”; if the person has already set a password, ROSIE refuses another invitation. Deactivate instead of delete — preserves data and audit.
👁️
What colleagues see: anyone who may not plan sees other people’s sickness or accident only as “absent” and receives neither their phone, email or job description nor their actual, target and balance hours.
🗓️

Configure Shifts

All relevant attributes per shift

Per shift you maintain: name, abbreviation, start/end, break mode (paid_break yes/no — r163), color, area, multi-select departments, role restriction.

The session default shift setting for meetings is additive. There are no industry templates — every shift is created by hand. Shifts take effect everywhere (plan, wish form, surcharges, AI, paintbrush).

⏱️

Working Time & Target Hours

Limits, overtime, canton

Max h/day, h/week, rest time, warning thresholds. Overtime: threshold, compensation (pay / timeoff / both), multiplier. Canton selection + target-hours calculator. Cantonal public holidays are loaded automatically.

Care professional in a bright corridor, holding a tablet
Planning

Wishes, absences, the plan

The wish allowance, absence types, the plan itself, cover bonuses for open shifts and shift swaps.

🎯

Shift / Time-Off Wishes

Area limits, third-party wishes, reminders

In the admin tab Shift/Time-Off Wishes you set limits per area × priority (1–3). Period: rolling or fixed date window. countFremdwuensche decides whether planner entries count against the employee's allowance. With several areas per employee, the strictest area limit wins.

💡
Wish reminder: automatically notifies employees before the deadline ends.
🤒

Manage Absences

4 types, workflow, cut-off date rule, withdrawal

4 types: sickness / sickness_longterm / accident / accident_longterm. Workflow pending → approved / rejected / cancelled. Approver roles are configurable (default: Administrator, Scheduler, Care Manager, Person in Charge of the Day). Mode GLOBAL or PRO_STATION.

Once approved, the absence appears in the plan and locks the days for AI planning. Weekends and public holidays can be excluded configurably. On the lock screen, push notifications about absences mention neither the name, nor the type of absence, nor a rejection reason.

Cut-off date rule: the date counts, not the person’s status

You can approve or record an absence afterwards for any person — including archived, deactivated or departed people — for all days from the entry date up to and including the exit date. ROSIE never approves days after the exit (or before the entry) and never writes them into the plan. If an absence runs past the exit, ROSIE offers “Approve up to leaving date” and never shortens it on its own; for a sickness or accident report the confirmation also refers to Art. 336c CO (if the employer gave notice, the notice period may be extended — in that case, update the leaving date first). The approval list and the planner cockpit mark archived, deactivated and departed people, without health status or reason for leaving. If the exit has already been processed, the confirmation reminds you that ROSIE now only calculates the leaving month — if that month’s pay has already been run, a follow-up report to payroll is required.

Withdrawal and notification

People withdraw open requests of any type themselves. They can only withdraw an approved sickness or accident report if they reported it themselves; all other approved absences, holidays and blocked dates are withdrawn only by the administration, with a seal check and a log entry. If someone withdraws an approved absence, the person who approved it and the scheduling for their area receive the notification “Absence withdrawn”: as a push without name or type of absence, in the app for 14 days with the name, period and number of replaced shifts. The shifts replaced on approval don’t come back, and nothing is closed automatically — re-plan the days. The push follows the switch “Notify approvers of new requests”.

Medical certificate

Employees attach the medical certificate as a photo or PDF (at most 3 MB) or add it later under “My reports”; the approvers are notified. You open and download it in the approval. Only the administration replaces a certificate that is already on file.

ℹ️
Bradford Factor: UI present, but dormant — no active monitoring. Self-reports are reason-free (data minimization); third-party reports require a reason. Audit via absence_audit_log (hash chain SHA-256, prev_hash → entry_hash).
📅

Create Plan

4 methods — Publish/Print separated (r154)
✋
Manual
Directly setting individual shifts.
🖌️
Paintbrush
Shift types as a brush + holidays/absence/blocks/delete.
📊
Status-Quo Matrix
Interactive monthly grid with coverage % and coverage report.
🤖
AI Plan
Solver with wishes, absences, holidays, cantonal public holidays, Legal Engine.

Publish and Print are separate flows (r154): Publish sends a push to all employees and shows them the area; Print acts on the print dialog. The publication history is available; the status-quo month strip shows a published badge.

Employees can only swap shifts and take over open shifts in published months; before that, they see their shifts dashed with “not yet published — changes possible”. In every plan, a small profile photo or the initials appear in front of the name; the JPG export and printing stay without photos. In the planning week view on a phone, the whole week is always visible; tapping shows the shift name and times.

🏆

Cover Bonuses and Stand-in Assignments

Open shifts and stand-in pool — settled separately

A cover bonus belongs to a single openly posted shift; employees volunteer in the “Plan” tab under “Open shifts”, and you approve. Past postings and postings without a date no longer appear there. On a takeover, ROSIE checks the person’s holidays, absences and blocked periods as well as the rules of the Labour Act. A stand-in assignment runs through the stand-in pool = list of people with surcharges (own cards: adminSpringerCard, adminSpringerListingCard).

ℹ️
In the payroll export (CSV/PDF), cover bonuses and stand-in surcharges are aggregated separately.
🔁

Mutation Approval

NEW r155 — Shift Swap tab

The "Shift Swap" tab has 3 sub-tabs:

📤
My Requests
Your own open and completed requests.
✅
Approval Required
Approval queue with timeline + notes.
📜
History
Complete audit view.

Mutation polling every 60 s (window.mutationsRefreshTimer). Several approvers per mutation possible; approval timeline + notes. Approving also works directly from the push notification (deep link).

ℹ️
Swap rules: swaps only happen in published months and only from today onwards; only the administration enters a past swap, as a correction. If your organization has switched swapping off, open requests can be neither accepted nor approved — but they are not cancelled automatically. Before a swap, ROSIE checks the rules of the Labour Act (among others, consecutive days and the weekly maximum) and shows violations beforehand.
Team in the break room over coffee
Closing

Payroll and analysis

Month-end closing and payroll export, allowances, tasks, quality documents and ideas from the team.

📊

Month-End Close & Payroll Preparation

Publish, seal at the required tier, then export

In Admin → Import/Export, “Monthly close & seal” lets the administration seal a published month after month end. A sealed month is write protected until the administration removes the seal with a reason. Sealing requires the Compliance tier; payroll and time exports remain available without a seal. Before export, ROSIE shows whether a frozen snapshot exists. Older seals without a snapshot are clearly marked.

Export: standard CSV and PDF. There is currently no XLSX export.

ℹ️
Wage type code: in «Export to payroll accounting (CSV)», ROSIE does not fill the «Lohnartcode» column; it carries the note «unassigned». You map the wage type codes of your payroll software with a profile in the «Data exchange» tab.

Who is in the export depends on the date: the payroll export and the time record include everyone employed in the selected month — including the leaving month, with sick and accident days. People already archived after leaving are included as well, and the export lists them in a note; in the time record selection they carry the suffix “(archived)”. If they can’t be loaded, ROSIE asks before exporting. The time record calculates target hours from the entry date to the leaving date.

⚠️
Monthly salary in the entry and leaving month: ROSIE calculates the target hours pro rata but does not reduce the monthly salary. If the entry or exit falls within the month (not on the 1st or the last day of the month), the export marks the person: in the PDF with “(Joined/left during the month)”, in the payroll CSV and the payroll accounting CSV with a footer line asking to check the pro-rata share. Payroll sets the share (calendar days, working days or target hours).
💡
Employees do not have a "Roster History" card in this app version. You create timesheets under Import/Export and hand them over.
💰

Surcharges

Time surcharges, stand-in assignments and cover bonuses

Admin → Surcharges: time surcharges (card UI with 24h bar), calculation modes pay % / time % / rate %. Surcharges for stand-in assignments and cover bonuses (CHF/assignment).

⚠️
Legacy team surcharges and daily flat rates have been removed — replaced by the stand-in overlay.
📋

Tasks, Templates, AI

Three panels: Delegation, Templates, AI
🤝
Delegation Panel (r162)
task_delegation with can_delegate and scope station / department / all.
📑
Task Templates (r160)
task_templates with target_role_id, target_shift_type, target_date_type (any / weekday / weekend / holiday), payload.qms_doc_ids. CRUD via /api/tasks/templates.
🤖
AI Configuration
4-level autonomy slider (r147 P3): Off / Suggest / Draft / Locked.

Min confidence 0.5–1.0 (default 0.7), min occurrence 2–50 (default 5 / 30-day window). Prompts are anonymized — no staff.id in the LLM path (DPA firewall).

ℹ️
Correction from the old manual: It is not 6, but 4 levels.
Attachments to tasks

Photos and PDFs from the device can be attached to a task — when scheduling creates it (up to 3 files) and afterwards in the task history by everyone allowed to write there; on a phone directly with the camera or from the file picker. At most 3 MB per file (the app shrinks large photos), at most 10 attachments per task and 20 uploads per person in 10 minutes; storage is encrypted. Anyone who can see the task history can see an attachment; the person who uploaded it, the person who assigned the task and the administration can remove it. Attachments are deleted with the task, otherwise with the history after two years.

⚠️
Professional secrecy: the button carries the reminder not to attach health or personal data of residents or people in care.
📚

QMS Documents

r162 / r163 / r165 — Doc picker, polling, visibility

PDF/DOCX up to 25 MB, object storage (tenants/{tenantId}/qms/{id}), metadata in the database (qms_documents). Upload permission via qmsUploaderRoles (admin or configured roles).

3 visibility modes: task_only (default), public, roles_restricted with visible_roles JSON. Soft-delete cascades to task_qms_links.

Doc picker in the task editor (#taskNewQmsPicker): chips with comma-separated data-ids; PATCH /api/tasks/:id/qms-links with {add:[], remove:[]}. Only documents the person may read themselves can be picked; a linked document can be removed by the person who assigned the task, by scheduling and by the administration.

💡
Global polling (r165 G1): aggressive 25 s in the Tasks tab, passive 60 s otherwise, paused on document.hidden (battery save).
💡

Ideas Inbox

Live push, Merkle hash, auto-sync

All ideas visible with author. Status buttons (submitted / in_review / implemented / rejected), admin notes, is_appropriate filter.

Live push to all Admin / Scheduler / Developer on a new idea (r152, pushGated idea_received). Merkle hash + parent_hash in improvement_suggestions. Auto-sync every 60 s.

💬

Messaging & Quiet Hours

Policy, peerChat, category-precise push

Messaging policy: 1to1 (open) / groups (within teams) / hierarchy. Add-on peerChat: off / company / bereich. Per-staff mayMessageAll bypasses the policy.

Quiet Hours: companySettings.quietHours {enabled, start, end} — default 22:00–07:00. Within the time window, all push categories are delivered silently. Under “My profile” → “Notifications”, employees can add their own quiet hours, which only extend the window and never shorten it. A push notification for a new message only shows the sender, never the text.

Alarm categories individually controllable: bounty · planPublished · adminAlert · messages · absenceResult. Exception: if a posted shift stays unfilled or a posting expires without anyone taking it over, scheduling and the administration always receive this message — even if they have switched the category off.

🔔

Push Configuration (RFC 8291)

VAPID, idempotent UPSERT, iOS note

Web Push via VAPID, idempotent subscribe UPSERT after login (subscribeToPushNotifications(true)). iOS: push only possible in the installed PWA. Active/inactive per category (see Messaging Policy).

Empty reception desk in the evening
Securing

Protecting and operating

Data protection and access, audit trail, monitoring, import and export, languages and accessibility.

🔐

Security & Data Protection

Policies, PII scrub, crypto shredding, HSTS
🔑
Password Policy
At least 12 characters (8 with two-factor sign-in), no special-character requirement; the same for all organisations, with no setting in the admin area. The session ends after 30 minutes without input (fixed, not configurable).
🗑️
Data Retention
No setting in the admin area: the statutory minimum periods take precedence. Retention and deletion are governed by the data processing agreement.
🩹
PII Scrub
r166 A6 — financial and personal attributes are masked before analytics.
📈
k-Anonymity ≥ 4
For aggregate charts.
💣
Crypto Shredding
Key destruction + IndexedDB + SW wipe (executeCryptoShredding).
💵
Finance Unlock
Sub-panel for payroll preparation.
ℹ️
HSTS preload (r168): max-age=63072000; includeSubDomains; preload in _headers AND worker.js corsHeaders. For manual submission to hstspreload.org see docs/HSTS_PRELOAD_SUBMIT.md.
📡

Version Headers & Web Vitals

NEW — X-Worker-Version, X-Request-Id, LCP/CLS/INP/FCP/TTFB
🏷️
X-Worker-Version + X-Request-Id
r166 A10/B1, migration 041. On every release bump the worker constant is carried along.
📊
Web Vitals
r167 B5 via PerformanceObserver: LCP/CLS/INP/FCP/TTFB → /api/analytics (keepalive fetch, DNT respected).
🧾

Audit & Evidence

r154 — Quick audit, KPI, Merkle hash chain

Admin → System: Quick audit, KPI analysis, retention config, audit ledger with Merkle hash chain over AUDIT_LEDGERS + storage fallback (r154 Quick-Audit fix). Every entry contains a predecessor hash; tampering is detectable immediately. revFADP-compliant.

📦

Import, Assistant, Export

DPA filter, 6-step assistant, r163 extension

The server always matches duplicates by email server-side and skips them — there is no "overwrite all" mode anymore. DPA filter blocks AHV, IBAN, religion, salary, health data. For a complete fresh setup, the 6-step setup assistant is also available (see section above).

Payroll preparation requires activation; export formats: CSV / PDF incl. r163 extension (paid/unpaid breaks, stand-in assignments and cover bonuses separate).

Download the roster

At the top of the roster, you will find the PDF, JPG and ICS buttons. PDF lets you print the roster, while JPG saves it as an image. ICS downloads your own shifts as a calendar file. Under Admin → Import/Export, the roster export entry takes you there.

🧰

Tools & Licenses

Admin → Tools (not the general Tools tab)

Optional licensed modules: Quality management (QMS) · Voice-to-Schedule · Payroll preparation & finance · Smart Matchmaker · Workload radar · Regional network. Text recognition (OCR) no longer exists.

🎙️
Voice-to-Schedule
Voice control with 7 commands. ROSIE receives no audio recordings; speech-to-text conversion is handled by the speech recognition service of the browser or operating system. Only the recognized text is sent to an AI for recognition. Before the first use, the person gives consent; before the microphone starts, ROSIE checks that the feature is enabled for them.
💵
Payroll preparation & finance
Full payroll export with hours, surcharges and pay data (see Month-End Close & Payroll Preparation).
🌍

Multilingualism

4 app languages, 14 chat languages

4 app languages: DE / FR / IT / EN — 42 keys × 4 languages = 168 translations (monatsabschluss / mahistory / qms / shift_rules / preferences / vacation / common). Definitions also present for RM / SQ / BS. Chat translation: 14 languages client-side.

✉️

Login & Invitations

PBKDF2, sessions, self-service

Login: PBKDF2-SHA-256 (4 × 100,000 chained iterations, salt). Session token; after 30 minutes without input the session ends and the sign-in window states the reason. Invitation email from support@rosie-app.ch, link valid for 7 days. For people already on file without access, “Send access” sends a link with which they set their password themselves (also 7 days); if the person already has a password, ROSIE refuses and changes nothing. Forgotten password: link on the sign-in page, valid for 60 minutes. Self-service password change in your own profile.

♿

Accessibility

r166 A8/A9 — ESC, focus trap, ARIA progress bar

Global ESC handler + focus trap in modals. ARIA progress bar for the onboarding wizard. Mode pills for brightness.

🧭

Common Admin Tasks

Joining, leaving, fiduciary export
New employee joins
Create → assign role → workload/pay → optional restrictions → “Send access” (link to set the password, valid for 7 days).
Employee leaves
In the profile, enter “Exit date (last working day)” and “Reason for leaving”. Up to and including that day the person remains schedulable, after that no longer; the payroll export still includes them in the leaving month. Don’t delete — the profile is retained for audit and payroll.
Fiduciary export
Admin → Import/Export → choose month and year → download CSV / PDF.
❓

FAQ for Administrators

The most common admin questions, briefly answered
Can I close or reopen a month?▶
Yes. After publication and month-end, an admin with the Compliance tier can seal the month. It is then write-protected. Reopening requires a reason. Payroll and time exports are also available without a seal.
4 or 6 AI levels?▶
There are exactly 4: Off / Suggest / Draft / Locked.
QMS upload fails — who may upload?▶
Admin or members of qmsUploaderRoles.
How do I configure swap approvers?▶
Structures → Roles → approver box "Shift Swap" (r155).
Submit HSTS preload to hstspreload.org?▶
Manual step — details in docs/HSTS_PRELOAD_SUBMIT.md.
How do I find the worker version?▶
In the response header X-Worker-Version.

Rosie Admin Manual · Version 9.9 · r771 · September 2026
Questions? support@rosie-app.ch · rosie-app.ch
← Back to overview