Access and permissions
Which permission each Employee Self Service screen needs, who may see and change what, and the rules that keep people from approving their own work.
On this page (20)
Permissions by screenAll ESS screensPayrollRequestsTasks, Timesheets, Expenses, Letters, Learning, EmploymentLeaveAttendanceMy Team / ApprovalsMy TeamApprovalsTeam DocumentsDocumentsSelf-service setup / Payroll runsSelf-service setupPayroll runsTasksLetters & CertificatesESS feature switchesESS field settingsHome
Permissions by screen
| Screen | Menu | Permission needed |
|---|---|---|
| Home | Employee Self Service > Home | ess.home (and the permission of each card's own page) |
| Attendance | Employee Self Service > Attendance | ess.attendance (view), ess.check_in (check in and breaks), ess.check_out, ess.attendance_correction |
| My Tasks | Employee Self Service (left menu) > Tasks | ess.tasks |
| My Leave | Employee Self Service > Leave | ess.leave |
| My Requests | Employee Self Service > Requests | ess.requests |
| Payroll | Employee Self Service > Payroll | ess.payslip |
| My Documents | Employee Self Service (left menu) > Documents | ess.documents |
| Employment | Employee Self Service (left menu) > Employment | ess.employment |
| Benefits | Employee Self Service (left menu) > Benefits | ess.benefits |
| My Expenses | Employee Self Service (left menu) > Expenses | ess.expenses |
| Timesheets | Employee Self Service (left menu) > Timesheets | ess.timesheet |
| Learning | Employee Self Service (left menu) > Learning | ess.home |
| My Assets | Employee Self Service (left menu) > Assets | ess.home |
| Letters & Certificates | Employee Self Service (left menu) > Letters & Certificates | ess.letter_request |
| My Profile | Employee Self Service (left menu) > My Profile | ess.home (view), ess.profile_change (change) |
| My Team | Employee Self Service > Manager > My Team | mss.team |
| Team Attendance | Employee Self Service > Manager > Team Attendance | mss.team_attendance |
| Approvals queue | Employee Self Service > Manager > Leave Approvals / Attendance Corrections / Overtime Approvals / Timesheet Approvals; Configuration > All Approvals | mss.approve_leave / mss.approve_attendance / mss.approve_overtime / mss.approve_timesheet / mss.approve_request, hr.expense.approve, hr.private.manage |
| Probation Reviews | Employee Self Service > Manager > Probation Reviews | mss.probation_review |
| Team Documents / Team Calendar | Employee Self Service > Manager > Team Documents and Team Calendar | mss.team_documents / mss.team |
| Self-service setup (masters) | Employee Self Service > Configuration > Self-service setup | ess.configure |
| Payroll runs | Employee Self Service > Configuration > Self-service setup > Payroll runs | ess.configure |
| ESS feature switches and field settings | Administration > Workspace > Apps > Employees (HRM) > Features and Fields | company.manage |
All ESS screens
| Rule | What the system does |
|---|---|
| The employee is the signed-in user, never a request value | The request is raised for Aisha (the id is ignored); no ESS route accepts an employee id; Aisha sees only her own records everywhere |
| Each page needs its own permission | 403 'You do not have permission for this action.' for that feature only; the others still work; menu entries that need the permission are hidden |
Payroll
| Rule | What the system does |
|---|---|
| A payslip of another employee cannot be opened | Layla's: 404 'Record not found.'; Aisha's own unpublished draft: 'This payslip is not published yet.'; lists never contain other people's slips |
| Salary account is masked everywhere | Only 'AE07••••3456' is returned (first 4 and last 4); the full IBAN never reaches the browser from these pages |
| Payslip views and decisions are audited without salary figures | Events ess.payslip.viewed / ess.request.approved with record id and actor; no amounts, IBAN or free text inside |
Requests
| Rule | What the system does |
|---|---|
| Another employee's request is invisible | 404 'Record not found.' for both; only the owner, the current-step approvers and HR (hr.private.manage, hr.employee.manage, ess.configure) can open a request by id |
| Nobody decides their own request (maker-checker) | 'You cannot decide your own request.' every time; the request goes to a different approver and the requester is never in the approver list |
| Only the approver of the current step can decide | 'This step is not yours to decide.'; a request not waiting: 'This request is not waiting for a decision.' |
| Manager step needs the permission for that kind | Omar is not an approver for overtime (only for the kinds he holds); the step goes to the administrators if nobody else qualifies |
| An asset request only for an asset I hold | 'That asset is not assigned to you.' |
Tasks, Timesheets, Expenses, Letters, Learning, Employment
| Rule | What the system does |
|---|---|
| Other people's records answer not found | Every attempt is 404 'Record not found.'; nothing changes |
Leave
| Rule | What the system does |
|---|---|
| Cannot withdraw or cancel someone else's leave | 404 'Record not found.'; Layla's leave unchanged |
Attendance
| Rule | What the system does |
|---|---|
| Photos only for self, manager, team and HR | Peer 404; Omar (manager), Hanan (hr.employee.view) and Aisha succeed |
My Team / Approvals
| Rule | What the system does |
|---|---|
| A manager sees only the own team | Only Aisha and Hamad appear; deciding Layla's leave is 404 'Record not found.'; Layla's timesheet 'That timesheet is not your team's.' |
My Team
| Rule | What the system does |
|---|---|
| mss.* without a team shows nothing | Empty team / empty queues, never someone else's data; the left Manager menu is hidden |
Approvals
| Rule | What the system does |
|---|---|
| Leave: own leave cannot be decided by oneself | Leave: 'A different HR user must decide this leave request.'; cancellation: 'A different manager must decide this request.' |
| Expense claims and profile changes: no self approval | Claim: 'A different approver must decide your own claim.'; profile change: 'A different HR user must decide this request.'; neither appears in the person's own queue |
| Stale approvals are refused | Leave: 'This request changed. Reload before deciding.'; claim: 'This claim changed. Reload before deciding.' (409) |
Team Documents
| Rule | What the system does |
|---|---|
| Document numbers never reach a manager | Only employee, document type, expiry, days and status; no number, issue date or file |
Documents
| Rule | What the system does |
|---|---|
| Restricted document numbers are hidden even from the owner's list | Number column shows '••••' for restricted types |
Self-service setup / Payroll runs
| Rule | What the system does |
|---|---|
| HR functions need ess.configure | 403 'You do not have permission for this action.' for every call; the menu entry is hidden; payroll figures of others never visible |
Self-service setup
| Rule | What the system does |
|---|---|
| Company isolation of masters | 'Choose a employee from this company.'; 404 'Record not found.'; membership missing -> 404 'Record not found.'; lists are per company |
Payroll runs
| Rule | What the system does |
|---|---|
| Paid payslips are immutable | Paid payslips skipped and unchanged; only drafts can be regenerated or published |
Tasks
| Rule | What the system does |
|---|---|
| Task assignment and timer rules | 'You can assign tasks only to yourself or your team.'; 'Only the person doing the task times it.' |
Letters & Certificates
| Rule | What the system does |
|---|---|
| Letter verification is company scoped | 'No letter carries that code.' and only the number, type, date and name for a valid one |
ESS feature switches
| Rule | What the system does |
|---|---|
| Switched-off features refuse changes but keep reads | POST 409 'capability_disabled'; GET still works |
ESS field settings
| Rule | What the system does |
|---|---|
| Hidden fields are refused on the server too | Refused 400 '... is turned off for this company.'; other fields still accepted |
Home
| Rule | What the system does |
|---|---|
| The AI assistant answers only for the asker | Only Aisha's own data is returned; there is no tool that reads another employee's pay; team attendance only for Omar's team |