Skip to main content

Employee roles

How to set up and assign employee roles: extra permissions that give someone access to the data of specific other employees or teams, without changing anyone's main permission level.

An employee role gives an employee extra access on top of the permission level they already have. It doesn't replace or limit anything the employee already has. There are two separate steps. First you set up the role, which means creating a template that describes what the role allows. Then you assign that finished role to a specific employee.

What is an employee role?

An employee role lets someone view or edit the data of another specific employee or team, without changing their permission level. For example, it's useful when an HR specialist needs access to one department's data only, without becoming an administrator with full rights.

Setting up (creating the role itself)

Go to Configure → Permissions → Employee roles:

  • Create a new role and give it a name (e.g. "Department HR access").

  • For each data set (e.g. working hours, documents, personal details), choose whether the role can view it or edit it.

The role isn't linked to anyone yet. It's a reusable template that you can later assign to several different employees.

Picture guide


Assigning (linking the role to a specific employee)

The employee's profile page shows two panels:

  • Employee roles: which roles this employee has, and whose data each role applies to.

  • Access to data: who else can currently view or edit this employee's data through a role.

Picture guide

When you assign an employee role, you choose:

  • which employee role to use,

  • whose data it applies to (one employee or a team),

  • a validity period, if you want one (Valid from – Valid until).

Picture guide

When you add someone under Access to data, you choose who can see your data with the permissions of the selected role:

  • Employee role,

  • Who has access to your data,

  • a validity period, if you want one (Valid from – Valid until).

Picture guide

Both dates in the validity period are included. The role is active on the start date and on the end date itself, and stops being active from the next day. This works well for a cover period, for example while a manager is on holiday. If you leave the date fields empty, the role is always valid.


Permission limits

You can only give a role within the permissions you already have yourself. Nobody can pass on more rights to someone else than they have.

Example

Need

Solution

An HR specialist needs access to one department

An employee role that gives access only to the data of employees in that department

A manager covers for a colleague during their holiday

An employee role with a validity period (from–until)

Good to know

  • Adding or removing a role takes effect straight away. The user doesn't need to log out and back in.

  • When you deactivate an employee, you can choose whether to also remove all the roles that employee has given to others. Roles that give other people access to the deactivated employee's data stay as they are.

Did this answer your question?