Roles & Permissions

Every member of an organization has a role, and that role determines what they can see and do. Roles are what let a line manager approve their team's leave requests without also having access to the organization's finance records, or let an HR administrator manage employee data without touching procurement.

Built-in roles

Every organization starts with a few default roles:

  • Admin: full access across every enabled module
  • Manager: oversight of a team, including approvals for requests from direct reports
  • Member: standard access, generally scoped to the employee self-service portal

Administrators can also create custom roles, so access can be shaped around how a specific organization actually operates rather than forced into a generic set of titles.

Permission scopes

Permissions are assigned at the module level: a role can be granted view, create, edit, or delete access independently for HR, Finance, Attendance, and every other enabled module. A role can, for example, have full access to Attendance but read-only access to Finance.

Roles are per-organization

A person's role is scoped to a single organization. Someone who's an Admin in one workspace can be a Member in another they also belong to. Each organization's roles are independent.

Where this shows up day to day

Permissions decide what appears in the sidebar, what actions are available on a given record, and whose approval a request routes to. A member without HR access, for instance, won't see the HR module in their dashboard at all, rather than seeing it locked or greyed out.