Permissions

Flowtly Editorial Team4 min

In the Permissions tab, you can assign different permissions to each employee. These permissions determine the actions an employee can perform within the system. As an admin, you can also remove roles from employees, as soon as they are no longer relevant. Note, that the Manager role always supersedes the Viewer role. This hierarchy ensures that individuals with managerial responsibilities have broader access and control over system functionalities compared to those with viewing permissions only.

Below is a comprehensive list of the available roles and their descriptions:

  • ROLE_ACCOUNTANCY_VIEWER: Allows viewing accountancy-related information.
  • ROLE_ADMIN: Grants full administrative access to all system functionalities.
  • ROLE_AGREEMENTS_MANAGER: Enables managing agreements, including creation and editing. Also required to read an agreement's pay terms wherever an agreement is shown, including alongside a person on the People list.
  • ROLE_AGREEMENTS_UPLOADER: Permits uploading agreements.
  • ROLE_BANKS_MANAGER: Allows managing bank details and related information.
  • ROLE_BENEFITS_MANAGER: Enables management of employee benefits.
  • ROLE_CANDIDATES_MANAGER: Allows managing candidate information.
  • ROLE_CLIENTS_MANAGER: Grants access to manage client details.
  • ROLE_COSTS_ANALYSER: Permits analysis of costs and expenditures.
  • ROLE_COSTS_MANAGER: Allows managing costs within the system.
  • ROLE_COUNTRIES_MANAGER: Enables management of country-related information.
  • ROLE_CURRENCIES_MANAGER: Allows managing currencies and exchange rates.
  • ROLE_DEBT_COLLECTIONS_MANAGER: Permits managing debt collections.
  • ROLE_DOCUMENTS_MANAGER: Allows full management of documents.
  • ROLE_DOCUMENTS_VIEWER: Permits viewing documents.
  • ROLE_EMPLOYEES_MANAGER: Grants permissions to manage employee information.
  • ROLE_EMPLOYEES_VIEWER: Allows viewing employee information, including each person's working-time terms. It does not include agreement pay terms.
  • ROLE_HOLIDAYS_MANAGER: Enables management of holiday requests and approvals.
  • ROLE_HOLIDAYS_VERIFICATOR: Permits verification of holiday requests.
  • ROLE_HR_MANAGER: Grants access to human resources management functionalities.
  • ROLE_INVOICES_MANAGER: Allows managing invoices and income-related information.
  • ROLE_INVOICES_VIEWER: Permits viewing invoices and income-related information.
  • ROLE_LOCATIONS_MANAGER: Grants permissions to manage location details.
  • ROLE_ORGANIZATION_USERS_MANAGER: Allows managing organizational users.
  • ROLE_PAYMENT_DUE_VIEWER: Permits viewing payment due details.
  • ROLE_POSITIONS_MANAGER: Enables management of job positions.
  • ROLE_PROJECTS_MANAGER: Grants permissions to manage projects.
  • ROLE_PROPERTIES_MANAGER: Allows managing property-related information.
  • ROLE_RESOURCING_APPROVER: Permits confirming draft bookings into counted coverage, un-confirming them, and declaring what a role needs — in addition to everything a Resourcing Manager can do.
  • ROLE_RESOURCING_MANAGER: Allows planning in Resourcing — creating draft bookings from the bench, adjusting and deleting them, and importing allocations.
  • ROLE_RESPONSIBILITIES_MANAGER: Permits managing responsibilities within the system.
  • ROLE_ROLES_MANAGER: Enables management of user roles and permissions.
  • ROLE_TAXES_MANAGER: Allows managing tax-related information.
  • ROLE_TAXES_VIEWER: Permits viewing tax-related information.
  • ROLE_TRANSACTIONS_MANAGER: Grants permissions to manage financial transactions.
  • ROLE_TRANSACTION_ATTACHMENT_UPLOADER: Allows uploading attachments to transactions.
  • ROLE_WORKING_HOURS_MANAGER: Permits viewing working hours for all projects.
  • ROLE_WORKING_HOURS_VIEWER: Permits viewing working hours for projects assigned to this user.

Who can see agreement pay terms

The People list and each employee's record show the person's active agreement. Two kinds of information sit there, and they follow different permissions:

  • Working-time terms — the contract type and its period, the job size, the hours per week, and whether working time is fixed. These are visible to anyone who can view employee records, because planning and scheduling depend on them.
  • Pay terms — the amount, whether that amount is net or gross, and the billing basis. These require ROLE_AGREEMENTS_MANAGER, the same permission the Agreements module itself demands. Someone who can view employee records but does not hold that permission sees the person and their working-time terms, without the pay terms.

Assigning Roles to Employees

To assign a role to an employee:

  1. Navigate to the Employee item in the main menu.
  2. Click on the “Edit" button to the employee you wish to assign a role to.
  3. Click on the Permissions tab.
  4. Choose the appropriate roles from the list based on the employee’s responsibilities.
  5. Save the changes to apply the new permissions.

By assigning the appropriate roles, you ensure that employees have the necessary access to perform their duties efficiently while maintaining the security and integrity of the system.

Example use cases

  • Onboarding a new HR Manager who needs to manage employee details, benefits, and holiday requests.
  • An employee transitions from a viewing role to a managerial role, requiring updated permissions to reflect their new responsibilities.
  • Restricting a temporary contractor's access to only view specific project documents, without edit capabilities.
  • Ensuring that a payroll specialist has comprehensive access to financial data while general employees only have viewing permissions for their own details.

Connection map

Refers toPart of
Documented hereDocumented elsewhere
audit-log records person. second-factor held by person. person works under agreement. work-schedule assigned to person. benefit-assignment held by person. employee-profile describes person. employee-document filed against person. responsibility assigned to person. performance-target set for person. meeting held with person. holiday-request submitted by person. leave-entitlement held by person. granted-allowance held by person. project staffed by person. project-rate rates person. booking books person.recordsheld byworks underassigned toheld bydescribesfiled againstassigned toset forheld withsubmitted byheld byheld bystaffed byratesbooksAAudit trail — The record of who did what and when. It is how a user action is investigated after the fact, and what compliance is demonstrated from.Audit trailPPerson — An employee. The central record the rest of the workforce data hangs off — profile, documents, leave, benefits, rates.PersonSSecond factor — The extra proof of identity asked for at sign-in on top of the password — a six-digit code from an authenticator app, changing every 30 seconds.Second factorAAgreement — The document formalizing the terms between the organisation and one employee or contractor. It is the foundation of the employees module: whether someone has an active agreement decides whether they appear in the other modules at all.AgreementWWork schedule — The working days, hours and breaks assigned to an employee, from the week the assignment starts. It is what the Work Time calendar draws.Work scheduleEEmployee benefit — One benefit granted to one person for a date range. A person can hold several at once.Employee benefitEEmployee profile — The detailed record for one person: contact details, job role, department, employment history.Employee profileEEmployee document — A file attached to a person — a contract, a review, anything filed against them.Employee documentRResponsibility — An area of ownership assigned to a person.ResponsibilityPPerformance target — An objective set for a person and measured against.Performance targetMMeeting — A recorded one-to-one or review between people.MeetingHHoliday request — An employee's request for time off, submitted for approval. Approving it is what turns it into leave the rest of the system counts.Holiday requestEEntitlement — How much leave a person has for the leave year. A request draws it down; the balance is what remains.EntitlementGGranted allowance — A number of days set for a person against one holiday type, effective from a date. It is granted rather than accrued, so a request against that type draws it down instead of the leave entitlement.Granted allowancePProject — The core organizational unit for a business initiative, client engagement or internal work. Everything tracked — time, cost, invoicing, profitability — hangs off one.ProjectMMember rate — A team member's billing or cost rate on a project. Rates are per member, so the same person can cost differently on two projects.Member rateBBooking — One person committed to one role for a stretch of weeks, at a percentage of their time. A booking is a plan, not a record of work done.Booking