- UserController: use Spatie syncRoles([$role]) instead of direct Eloquent relations relation sync() which bypassed Spatie model events and cache observers
- RoleController: explicitly call forgetCachedPermissions() on store and update to force cache refresh
- Clear application cache
- EmployeeController::create(): pass company roles + defaultRole (employee) to Inertia
- EmployeeController::store(): assign role from role_id request field (fallback to 'employee')
- EmployeeController::edit(): pass company roles + currentRoleId to Inertia
- EmployeeController::update(): syncRoles() with selected role_id
- create.tsx: Role <Select> dropdown pre-selected to default employee role
- edit.tsx: Role <Select> dropdown pre-selected to employee's current role
- LeaveApplicationController: add employee branch to bypass can() check
- AttendanceRecordController: add employee calendar view (own records only)
+ open clockIn/clockOut to employee type (no permission required)
- PayslipController: add employee branch to show own payslips only
- routes/web.php: remove permission:clock-in-out middleware from clock routes
- employee-dashboard.tsx: always show clock in/out buttons for employees
- Rebuild frontend assets
- Add getEmployeeNavItems() to app-sidebar.tsx for users with type='employee'
showing Dashboard, My Leaves, Overtime Requests, My Attendance, My Payslips
- Route employee users to their own nav instead of admin getCompanyNavItems()
- Move GET index routes for leave-applications, attendance-records, overtime,
and payslips outside permission:manage-* middleware so employees can access
their own records without admin permissions (controllers already scope by user)