Skip to main content
Employee portal

Portal administration

What portal managers and tenant administrators control: the management dashboard, content, layout, branding, the people directory, directory sync and catalog items.

Portal managers and tenant administrators run the portal from Workspace settings in the IT workspace. Portal managers author and publish content; tenant administrators additionally switch features on, set branding and govern the people directory. See Roles and permissions for the permission keys.

Portal management dashboard

Workspace settings → Portal management is the unified portal manager. It shows:

  • Drafts and reviews;
  • Scheduled content;
  • content Expiring within 7 days;
  • Review due;
  • Release failures;
  • recent changes.

Per item you have Employee preview (desktop or mobile, light or dark), Duplicate as draft, Publish / retry release and Audit history. The preview cannot vote, acknowledge or publish.

Two protections apply to every edit:

  • Conflict protection. If someone else saved the item in the meantime, TENSOR refuses to overwrite it. Click Reload current version and apply your change again.
  • Published content is locked. Published content must return to draft before editing.

Publications, banners and polls go live and expire at the times you set. A failed release appears under Release failures; fix the cause (for example a missing works-council acknowledgement for a poll) and use Publish / retry release.

Publications

Under Workspace settings → Publications you write, submit for review, publish and retire publications; require acknowledgement; choose the audience (All employees or Specific groups); set a cover image with alt text; and manage categories. Managing categories needs portal.publications.admin.

The Ack column shows how many people have acknowledged a mandatory publication. For mandatory publications, the author cannot publish.

Each content type is authored, targeted and published separately:

  • Events: title, details, start, optional end and location, optional external link. Unpublish returns a published event to draft; Retire archives it.
  • Polls: title, questions (Scale, Slider, Choice), Anonymous and the Results threshold (k-anonymity). Open starts the poll, Close freezes the results. The Votes column shows participation.
  • Push banners: message, severity, Dismissible or Mandatory, Regulated intent for an acknowledgement receipt, optional icon and tone with a preview. The Acks column counts receipts. Icon and tone can be changed only while the banner is a draft.
  • Quick links: link sets with label, URL, icon key, audience, order and whether the link opens in a new tab or the same tab. TENSOR stores only the URL, never credentials. Managing quick links needs portal.links.admin.

Intranet layout

With in-app layout authoring switched on (flag portal_authoring), Workspace settings → Intranet layout lets you add, edit, reorder, retire and restore home page sections, each with an optional audience.

The layout uses fixed section types with typed settings. Free HTML, CSS or scripts are deliberately not possible. Every change is audited; a reorder counts as one change. Employees see the new layout on their next visit.

At most three featured stories can be active at the same time.

Company branding

Workspace settings → Portal branding (page Company branding) sets:

  • the display name;
  • the primary logo and compact mark (with required alt text);
  • the accent colour;
  • the default theme.

You check previews, publish as a revision and can restore an earlier revision as a new draft. Branding is limited to these tokens: there is no way to inject CSS, HTML or scripts. Colours that do not meet the platform's minimum contrast are rejected by the server, and logos are virus-scanned and checked for size and format. For the full workflow, see Publish company branding.

Planned — not yet available. Per-audience portals and brand profiles.

People directory

Workspace settings → People directory (needs directory.admin and the flag tenant_directory) holds:

  • the Works-council acknowledgement;
  • the Published fields: Job title, Team, Location, Work phone, Email, Photo, Availability, Expertise;
  • Who can see whom: everyone in the tenant, same department only, or same location only.

Enable the people directory stays blocked until the works-council acknowledgement is recorded. Fields you did not publish never leave the server, even if they were imported from the company directory.

Directory sync

With tenant_directory_sync switched on, Directory sync connects Active Directory or Entra ID through WorkOS, maps attributes and lets you monitor sync runs. Sync keys users on the identity provider's external ID; synced fields are read-only in TENSOR, and locally maintained fields can be pinned so the next sync does not overwrite them. A directory sync failure notifies the portal managers.

See Directory Sync — ingest is not publish for why importing people never makes them visible.

Catalog items

Catalog items compose service catalogue entries with ordered form fields, simple show or hide rules and a fulfilment binding. Publishing a catalog item requires a fulfilment binding; archived items keep working for existing requests. See Service requests and the catalog for request models, approval steps and fulfilment tasks.

Projects

The project portfolio is curated in the workspace and shown to employees under People → Projects. See Employee project portfolio.