Access and permissions

Which permission each Employee Self Service screen needs, who may see and change what, and the rules that keep people from approving their own work.

On this page (20)

Permissions by screen

ScreenMenuPermission needed
HomeEmployee Self Service > Homeess.home (and the permission of each card's own page)
AttendanceEmployee Self Service > Attendanceess.attendance (view), ess.check_in (check in and breaks), ess.check_out, ess.attendance_correction
My TasksEmployee Self Service (left menu) > Tasksess.tasks
My LeaveEmployee Self Service > Leaveess.leave
My RequestsEmployee Self Service > Requestsess.requests
PayrollEmployee Self Service > Payrolless.payslip
My DocumentsEmployee Self Service (left menu) > Documentsess.documents
EmploymentEmployee Self Service (left menu) > Employmentess.employment
BenefitsEmployee Self Service (left menu) > Benefitsess.benefits
My ExpensesEmployee Self Service (left menu) > Expensesess.expenses
TimesheetsEmployee Self Service (left menu) > Timesheetsess.timesheet
LearningEmployee Self Service (left menu) > Learningess.home
My AssetsEmployee Self Service (left menu) > Assetsess.home
Letters & CertificatesEmployee Self Service (left menu) > Letters & Certificatesess.letter_request
My ProfileEmployee Self Service (left menu) > My Profileess.home (view), ess.profile_change (change)
My TeamEmployee Self Service > Manager > My Teammss.team
Team AttendanceEmployee Self Service > Manager > Team Attendancemss.team_attendance
Approvals queueEmployee Self Service > Manager > Leave Approvals / Attendance Corrections / Overtime Approvals / Timesheet Approvals; Configuration > All Approvalsmss.approve_leave / mss.approve_attendance / mss.approve_overtime / mss.approve_timesheet / mss.approve_request, hr.expense.approve, hr.private.manage
Probation ReviewsEmployee Self Service > Manager > Probation Reviewsmss.probation_review
Team Documents / Team CalendarEmployee Self Service > Manager > Team Documents and Team Calendarmss.team_documents / mss.team
Self-service setup (masters)Employee Self Service > Configuration > Self-service setupess.configure
Payroll runsEmployee Self Service > Configuration > Self-service setup > Payroll runsess.configure
ESS feature switches and field settingsAdministration > Workspace > Apps > Employees (HRM) > Features and Fieldscompany.manage

All ESS screens

RuleWhat the system does
The employee is the signed-in user, never a request valueThe request is raised for Aisha (the id is ignored); no ESS route accepts an employee id; Aisha sees only her own records everywhere
Each page needs its own permission403 'You do not have permission for this action.' for that feature only; the others still work; menu entries that need the permission are hidden

Payroll

RuleWhat the system does
A payslip of another employee cannot be openedLayla's: 404 'Record not found.'; Aisha's own unpublished draft: 'This payslip is not published yet.'; lists never contain other people's slips
Salary account is masked everywhereOnly 'AE07••••3456' is returned (first 4 and last 4); the full IBAN never reaches the browser from these pages
Payslip views and decisions are audited without salary figuresEvents ess.payslip.viewed / ess.request.approved with record id and actor; no amounts, IBAN or free text inside

Requests

RuleWhat the system does
Another employee's request is invisible404 'Record not found.' for both; only the owner, the current-step approvers and HR (hr.private.manage, hr.employee.manage, ess.configure) can open a request by id
Nobody decides their own request (maker-checker)'You cannot decide your own request.' every time; the request goes to a different approver and the requester is never in the approver list
Only the approver of the current step can decide'This step is not yours to decide.'; a request not waiting: 'This request is not waiting for a decision.'
Manager step needs the permission for that kindOmar is not an approver for overtime (only for the kinds he holds); the step goes to the administrators if nobody else qualifies
An asset request only for an asset I hold'That asset is not assigned to you.'

Tasks, Timesheets, Expenses, Letters, Learning, Employment

RuleWhat the system does
Other people's records answer not foundEvery attempt is 404 'Record not found.'; nothing changes

Leave

RuleWhat the system does
Cannot withdraw or cancel someone else's leave404 'Record not found.'; Layla's leave unchanged

Attendance

RuleWhat the system does
Photos only for self, manager, team and HRPeer 404; Omar (manager), Hanan (hr.employee.view) and Aisha succeed

My Team / Approvals

RuleWhat the system does
A manager sees only the own teamOnly Aisha and Hamad appear; deciding Layla's leave is 404 'Record not found.'; Layla's timesheet 'That timesheet is not your team's.'

My Team

RuleWhat the system does
mss.* without a team shows nothingEmpty team / empty queues, never someone else's data; the left Manager menu is hidden

Approvals

RuleWhat the system does
Leave: own leave cannot be decided by oneselfLeave: 'A different HR user must decide this leave request.'; cancellation: 'A different manager must decide this request.'
Expense claims and profile changes: no self approvalClaim: 'A different approver must decide your own claim.'; profile change: 'A different HR user must decide this request.'; neither appears in the person's own queue
Stale approvals are refusedLeave: 'This request changed. Reload before deciding.'; claim: 'This claim changed. Reload before deciding.' (409)

Team Documents

RuleWhat the system does
Document numbers never reach a managerOnly employee, document type, expiry, days and status; no number, issue date or file

Documents

RuleWhat the system does
Restricted document numbers are hidden even from the owner's listNumber column shows '••••' for restricted types

Self-service setup / Payroll runs

RuleWhat the system does
HR functions need ess.configure403 'You do not have permission for this action.' for every call; the menu entry is hidden; payroll figures of others never visible

Self-service setup

RuleWhat the system does
Company isolation of masters'Choose a employee from this company.'; 404 'Record not found.'; membership missing -> 404 'Record not found.'; lists are per company

Payroll runs

RuleWhat the system does
Paid payslips are immutablePaid payslips skipped and unchanged; only drafts can be regenerated or published

Tasks

RuleWhat the system does
Task assignment and timer rules'You can assign tasks only to yourself or your team.'; 'Only the person doing the task times it.'

Letters & Certificates

RuleWhat the system does
Letter verification is company scoped'No letter carries that code.' and only the number, type, date and name for a valid one

ESS feature switches

RuleWhat the system does
Switched-off features refuse changes but keep readsPOST 409 'capability_disabled'; GET still works

ESS field settings

RuleWhat the system does
Hidden fields are refused on the server tooRefused 400 '... is turned off for this company.'; other fields still accepted

Home

RuleWhat the system does
The AI assistant answers only for the askerOnly Aisha's own data is returned; there is no tool that reads another employee's pay; team attendance only for Omar's team