Permissions
In the Permissions tab, you can assign different permissions to each employee. These permissions determine the actions an employee can perform within the system. As an admin, you can also remove roles from employees, as soon as they are no longer relevant. Note, that the Manager role always supersedes the Viewer role. This hierarchy ensures that individuals with managerial responsibilities have broader access and control over system functionalities compared to those with viewing permissions only.
Below is a comprehensive list of the available roles and their descriptions:
- ROLE_ACCOUNTANCY_VIEWER: Allows viewing accountancy-related information.
- ROLE_ADMIN: Grants full administrative access to all system functionalities.
- ROLE_AGREEMENTS_MANAGER: Enables managing agreements, including creation and editing. Also required to read an agreement's pay terms wherever an agreement is shown, including alongside a person on the People list.
- ROLE_AGREEMENTS_UPLOADER: Permits uploading agreements.
- ROLE_BANKS_MANAGER: Allows managing bank details and related information.
- ROLE_BENEFITS_MANAGER: Enables management of employee benefits.
- ROLE_CANDIDATES_MANAGER: Allows managing candidate information.
- ROLE_CLIENTS_MANAGER: Grants access to manage client details.
- ROLE_COSTS_ANALYSER: Permits analysis of costs and expenditures.
- ROLE_COSTS_MANAGER: Allows managing costs within the system.
- ROLE_COUNTRIES_MANAGER: Enables management of country-related information.
- ROLE_CURRENCIES_MANAGER: Allows managing currencies and exchange rates.
- ROLE_DEBT_COLLECTIONS_MANAGER: Permits managing debt collections.
- ROLE_DOCUMENTS_MANAGER: Allows full management of documents.
- ROLE_DOCUMENTS_VIEWER: Permits viewing documents.
- ROLE_EMPLOYEES_MANAGER: Grants permissions to manage employee information.
- ROLE_EMPLOYEES_VIEWER: Allows viewing employee information, including each person's working-time terms. It does not include agreement pay terms.
- ROLE_HOLIDAYS_MANAGER: Enables management of holiday requests and approvals.
- ROLE_HOLIDAYS_VERIFICATOR: Permits verification of holiday requests.
- ROLE_HR_MANAGER: Grants access to human resources management functionalities.
- ROLE_INVOICES_MANAGER: Allows managing invoices and income-related information.
- ROLE_INVOICES_VIEWER: Permits viewing invoices and income-related information.
- ROLE_LOCATIONS_MANAGER: Grants permissions to manage location details.
- ROLE_ORGANIZATION_USERS_MANAGER: Allows managing organizational users.
- ROLE_PAYMENT_DUE_VIEWER: Permits viewing payment due details.
- ROLE_POSITIONS_MANAGER: Enables management of job positions.
- ROLE_PROJECTS_MANAGER: Grants permissions to manage projects.
- ROLE_PROPERTIES_MANAGER: Allows managing property-related information.
- ROLE_RESOURCING_APPROVER: Permits confirming draft bookings into counted coverage, un-confirming them, and declaring what a role needs — in addition to everything a Resourcing Manager can do.
- ROLE_RESOURCING_MANAGER: Allows planning in Resourcing — creating draft bookings from the bench, adjusting and deleting them, and importing allocations.
- ROLE_RESPONSIBILITIES_MANAGER: Permits managing responsibilities within the system.
- ROLE_ROLES_MANAGER: Enables management of user roles and permissions.
- ROLE_TAXES_MANAGER: Allows managing tax-related information.
- ROLE_TAXES_VIEWER: Permits viewing tax-related information.
- ROLE_TRANSACTIONS_MANAGER: Grants permissions to manage financial transactions.
- ROLE_TRANSACTION_ATTACHMENT_UPLOADER: Allows uploading attachments to transactions.
- ROLE_WORKING_HOURS_MANAGER: Permits viewing working hours for all projects.
- ROLE_WORKING_HOURS_VIEWER: Permits viewing working hours for projects assigned to this user.
Who can see agreement pay terms
The People list and each employee's record show the person's active agreement. Two kinds of information sit there, and they follow different permissions:
- Working-time terms — the contract type and its period, the job size, the hours per week, and whether working time is fixed. These are visible to anyone who can view employee records, because planning and scheduling depend on them.
- Pay terms — the amount, whether that amount is net or gross, and the billing basis. These require ROLE_AGREEMENTS_MANAGER, the same permission the Agreements module itself demands. Someone who can view employee records but does not hold that permission sees the person and their working-time terms, without the pay terms.
Assigning Roles to Employees
To assign a role to an employee:
- Navigate to the Employee item in the main menu.
- Click on the “Edit" button to the employee you wish to assign a role to.
- Click on the Permissions tab.
- Choose the appropriate roles from the list based on the employee’s responsibilities.
- Save the changes to apply the new permissions.
By assigning the appropriate roles, you ensure that employees have the necessary access to perform their duties efficiently while maintaining the security and integrity of the system.
Example use cases
- Onboarding a new HR Manager who needs to manage employee details, benefits, and holiday requests.
- An employee transitions from a viewing role to a managerial role, requiring updated permissions to reflect their new responsibilities.
- Restricting a temporary contractor's access to only view specific project documents, without edit capabilities.
- Ensuring that a payroll specialist has comprehensive access to financial data while general employees only have viewing permissions for their own details.