Permission groups

Flowtly Editorial Team2 min

Permission groups, accessible under Settings → People → Permission groups, are reusable bundles of permissions that you assign to employees. When you edit a permission group, the changes are applied to every assigned employee instantly, removing the need to update individual employee permissions one by one.

Permissions that are not part of any group can still be granted as per-employee overrides. However, adding permissions to a group helps maintain clearer access control and simplifies auditing.

Example use cases

  • Streamline onboarding by assigning a standard set of permissions to new employees based on their role (e.g., "Accountant", "Project Manager").
  • Ensure consistent access control across teams by creating groups for departments like "Marketing Team" or "HR Department", granting them the necessary permissions for their functions.
  • Quickly modify or revoke access for multiple employees simultaneously by editing a permission group, which instantly updates permissions for all assigned members.
  • Manage temporary access for contractors or consultants by creating a specific group that can be easily updated or removed once their work is complete.

Connection map

Refers toPart ofFulfils
Documented hereDocumented elsewhere
audit-log records person. setting defines attribute. org-document access governed by setting. subscription gates setting. setting requires second-factor. second-factor held by person. recovery-code stands in for second-factor. trusted-device waives second-factor.recordsdefinesaccess governed bygatesrequiresheld bystands in forwaivesAAudit trail — The record of who did what and when. It is how a user action is investigated after the fact, and what compliance is demonstrated from.Audit trailPPerson — An employee. The central record the rest of the workforce data hangs off — profile, documents, leave, benefits, rates.PersonSSetting — Platform-wide configuration — behaviours, permissions, security.SettingAAttribute — A custom data field defined once and collected across the platform, so an organisation can record what Flowtly does not ship a field for.AttributeDDocument — An organisational file, stored with control over who can reach it.DocumentSSubscription — The plan the organisation is on, and what it is billed for.SubscriptionSSecond factor — The extra proof of identity asked for at sign-in on top of the password — a six-digit code from an authenticator app, changing every 30 seconds.Second factorRRecovery code — One of ten single-use codes issued when an authenticator is confirmed. Each stands in for a code from the app once, for the day the phone is gone.Recovery codeTTrusted device — A browser a person has chosen to trust, which is not asked for a second factor again for 30 days. Per browser, not per person.Trusted device