Access and permissions
Which permission each Human Resources screen needs, who may see and change what, and the rules that keep people from approving their own work.
On this page (46)
Permissions by screenEmployee directoryEmployee recordDocumentsIDs & visasDocument filesDocuments / IDsContractsApprovalsMy HRHeadcount & FTEDocument expiryAuditHR mastersAccess requestEmployees app configurationOffersCandidatesNew hireHiring menusPay changesTerminationsDispute holdsOnboarding tasksChecklists and mastersHiring / pay / offboardingTime offTime off > Request leaveApprovals > Leave requestLeave typesAccrual plansAllocations & adjustmentsAccrual runsLeave ledgerLeave balancesAttendance daysAttendance day recordCorrectionsOvertime approvalsTimesheetsShiftsApplications > Employees > FeaturesAttendance exceptionsExpensesExpense claim recordTalent (API)
Permissions by screen
| Screen | Menu | Permission needed |
|---|---|---|
| HR Home | Employees > Home | Any HR permission; company tiles need hr.employee.view (else own team only); Probation tile hr.contract.view; Documents tile hr.private.view |
| Employee directory | Employees > Employees | hr.employee.view (list), hr.employee.manage (New employee) |
| Employee record - Overview | Employees > open an employee > Overview | hr.employee.view (read), hr.employee.manage (general, photo, actions), hr.private.view / hr.private.manage (private block) |
| Assignments and contracts | Employee record > Job & pay | hr.employee.manage (assignments); hr.contract.view / hr.contract.manage (contracts); hr.pay.view (salary figures and Why?) |
| Documents and IDs & visas | Employee record > Documents | hr.employee.view (see that documents exist and expiry); hr.private.view (numbers, files, IDs & visas section); hr.private.manage (add/upload/remove) |
| Record panels | Employee record > Time & attendance / Access / History | hr.employee.view; Access request state needs hr.employee.manage |
| Approvals inbox | Employees > Approvals | Any member; each item type needs its own deciding right (profile change / document renewal: hr.private.manage) |
| My HR | Employees > My HR | Any member whose login is linked to an employee (server finds the employee from the login, never from an id) |
| Headcount and FTE | Employees > Reporting > Headcount & FTE | hr.report.view |
| Document expiry | Employees > Reporting > Document expiry | hr.private.view (and company-wide employee view) |
| Document renewals | Employees > Reporting > Renewal campaigns | hr.private.view (see), hr.private.manage (campaign builder, decide) |
| Departments and cost centres | Employees > Configuration > Organization > Departments / Cost centres | reference.manage (server); menu shows for everyone in HR |
| HR masters | Employees > Configuration > Organization > Jobs / Positions / Grades / Contract types | hr.configure (save); any HR permission (read) |
| Assignments | Employees > Configuration > Organization > Assignments | hr.employee.view (list), hr.employee.manage (changes) |
| Approval escalation | Employees > Configuration > Approval escalation | hr.employee.view (read), hr.configure (Edit) |
| Employees app configuration | Applications > Employees > Features / Fields | Company administrator; proposer cannot approve |
| New hire (guided flow) | Employees > Hiring > New hire | hr.recruit.manage (menu and flow); pay lines need hr.pay.manage; approve needs hr.recruit.approve; Create employee needs hr.employee.manage + hr.recruit.manage + hr.private.manage + hr.contract.manage |
| Candidates | Employees > Hiring > Candidates | hr.recruit.view (list), hr.recruit.manage (New candidate) |
| Candidate record | Candidates > open a candidate | hr.recruit.view (read), hr.recruit.manage (save, screen, reject, withdraw), hr.private.view / hr.private.manage (ID number) |
| Offers | Employees > Hiring > Offers | hr.recruit.view (list), hr.recruit.manage (New hire) |
| Offer record | Offers > open an offer | hr.recruit.manage / hr.recruit.approve / hr.pay.manage (pay lines) / hr.pay.view (see pay) |
| Pay changes | Employees > Pay & benefits > Pay changes | hr.pay.view (list - the whole screen is pay data), hr.pay.manage (New change) |
| Pay change record | Pay changes > open a change | hr.pay.manage (submit, apply, withdraw), hr.pay.approve (approve, reject) |
| Benefit plans | Employees > Pay & benefits > Benefit plans | hr.pay.view (list), hr.pay.manage (New plan, Save) |
| Terminations | Employees > Offboarding > Terminations | hr.employee.view (list; rows narrowed to your scope), hr.offboard (Start offboarding) |
| Termination record | Terminations > open a termination | hr.employee.view (read); hr.offboard (run the process); hr.offboard.approve (approve, decide waivers, revoke access now, terminate early, reinstate); hr.hold.manage (holds) |
| Start offboarding (guided flow) | Terminations > Start offboarding | hr.offboard (and hr.employee.view) |
| Dispute holds | Employees > Offboarding > Dispute holds | hr.employee.view (list), hr.hold.manage (Place hold, Release) |
| Onboarding checklists | Employees > Configuration > Organization > Onboarding checklists | hr.configure (save); menu shows to any HR user |
| Offboarding checklists | Employees > Configuration > Organization > Offboarding checklists | hr.configure (save); menu shows to any HR user |
| Time off (requests) | Employees > Time off | Any HR access or a manager's team (server: 'You do not have access to time off.' otherwise); hr.employee.view to see the button |
| Request leave for an employee (dialog) | Employees > Time off > Request leave | hr.employee.view (quote and submit) |
| Leave balances | Employees > Reporting > Leave balances | Any HR access or a manager's team; menu entry follows the Time off switch |
| Leave ledger report | Employees > Reporting > Leave ledger | hr.report.view (menu entry and server) |
| Leave types (list) | Employees > Configuration > Time & leave > Leave types | hr.employee.view (screen); hr.configure (create / change) |
| Leave type record | Leave types > open a leave type | hr.configure to edit; read-only otherwise |
| Accrual plans (list) | Employees > Configuration > Time & leave > Accrual plans | hr.employee.view (screen); hr.configure (create, activate, retire, new version); hr.leave.policy.approve (cases and approve) |
| Accrual plan record | Accrual plans > open a plan | hr.configure; hr.leave.policy.approve (second person) |
| Holidays | Employees > Configuration > Time & leave > Holidays | hr.employee.view (screen); hr.configure (add / remove) |
| Calendar preview | Holidays / Accrual plans > Calendar preview | hr.employee.view |
| Accrual runs | Employees > Configuration > Time & leave > Accrual runs | hr.employee.view (read history); hr.configure (every run); hr.leave.policy.approve (decide a review) |
| Allocations and adjustments | Employees > Configuration > Time & leave > Allocations & adjustments | hr.employee.view (read); hr.leave.allocate (request, withdraw); hr.leave.policy.approve (decide) |
| Attendance days | Employees > Time & attendance > Attendance days | Company scope with hr.employee.view, else a manager's own team ('You do not have access to attendance.') |
| Attendance day record | Attendance days > open a day | hr.attendance.approve (company) or mss.approve_attendance (manager of the team); hr.attendance.manage for corrections |
| Attendance corrections | Employees > Time & attendance > Corrections | Scope as attendance; raise: hr.attendance.manage, the employee themselves, or a manager with mss.approve_attendance |
| Overtime approvals | Employees > Time & attendance > Overtime approvals | hr.attendance.approve (company) or mss.approve_overtime (manager of the team) |
| Weekly timesheets (list) | Employees > Time & attendance > Timesheets | Scope as attendance, or your own sheets; create: yourself or hr.attendance.manage |
| Weekly timesheet record | Timesheets > open a timesheet | Employee (own) or hr.attendance.manage; decide: hr.attendance.approve or mss.approve_timesheet |
| Shifts | Employees > Configuration > Time & leave > Shifts | hr.employee.view (screen); hr.configure (shift); hr.attendance.manage (assign) |
| Rosters | Employees > Configuration > Time & leave > Rosters | hr.employee.view (screen); hr.configure (roster); hr.attendance.manage (assign) |
| Working calendars | Employees > Configuration > Time & leave > Working calendars | hr.employee.view (list); hr.configure (create / change) |
| Attendance exceptions report | Employees > Reporting > Attendance exceptions | Scope as attendance |
| Time off and Time and attendance switches | Applications > Employees > Features | Company admin; two-person change |
| Expense claims | Employees > Expenses > Expense claims | hr.expense.view (list); hr.expense.claim (new) |
| Expense claim record | Expense claims > open a claim | hr.expense.claim / approve / settle |
| Travel | Employees > Expenses > Travel | hr.expense.view; hr.expense.claim (new); hr.expense.approve; hr.expense.settle (advance) |
| Company cards | Employees > Expenses > Company cards | hr.expense.view; hr.expense.configure (load) |
| Expense categories | Employees > Configuration > Expense categories | hr.expense.view; hr.expense.configure |
| Travel policies | Employees > Configuration > Travel policies | hr.expense.view; hr.expense.configure |
| Talent: recruitment pipeline | (no menu - API only) /talent/vacancies, /applications, /interviews | hr.vacancy.manage / approve, hr.applicant.all / hold, hr.recruit.manage, vacancy team |
| Talent: performance | (no menu - API only) /talent/cycles, /reviews, /appeals, /goals | hr.review.manage / view / publish |
| Talent: skills and learning | (no menu - API only) /talent/employee-skills, /courses, /sessions, /plans | hr.training.view / manage / approve |
Employee directory
| Rule | What the system does |
|---|---|
| View vs manage | List and record visible; no New employee; Edit disabled; API POST/PATCH refused (403) |
| Company isolation | Not found; nothing of company B returned |
Employee record
| Rule | What the system does |
|---|---|
| Private block hidden without the private grant | No Private information section and no 'private' key in the response; directory, search and headcount never contain private values |
Documents
| Rule | What the system does |
|---|---|
| Document numbers restricted | Rows show type and expiry; Number 'Restricted', no authority, no files; 'Add a document' absent |
IDs & visas
| Rule | What the system does |
|---|---|
| Identifier masking | identifier_value empty, masked shows only the last 4 (e.g. ••••••••••••••4-1); the IDs & visas section is not offered on screen |
Document files
| Rule | What the system does |
|---|---|
| File download needs the private grant | Refused; an employee can download only files of their own documents via My HR |
Documents / IDs
| Rule | What the system does |
|---|---|
| Writing needs hr.private.manage | Refused 403 |
Contracts
| Rule | What the system does |
|---|---|
| Pay figures need hr.pay.view | No Gross/bases/components/hourly; /explain refused |
Approvals
| Rule | What the system does |
|---|---|
| Requester cannot decide own profile change / renewal | Not listed in their inbox; API refused 'A different HR user must decide this request.' (renewal: 'A different HR user must decide this renewal.') |
| Inbox scope | Only own team's leave/cancellations ('My team'); no profile changes, renewals or other employees |
My HR
| Rule | What the system does |
|---|---|
| Own record only | Server resolves the employee from the login; other ids return 'not found' |
Headcount & FTE
| Rule | What the system does |
|---|---|
| Report permission | Refused by the server (menu entry is still shown) |
Document expiry
| Rule | What the system does |
|---|---|
| Expiry report is private | 'You do not have access to this list.'; no tile on Home |
Audit
| Rule | What the system does |
|---|---|
| No private values in the audit trail | Entries name the action and revision (or identifier type) only - never numbers, emails or reasons |
HR masters
| Rule | What the system does |
|---|---|
| Configuration needs hr.configure | Refused 403 |
Access request
| Rule | What the system does |
|---|---|
| Raiser cannot fulfil | Refused 'You cannot decide a request you raised.'; fulfil without a linked login -> 'Create the login and link it to this employee first; this request only records that it exists.' |
Employees app configuration
| Rule | What the system does |
|---|---|
| Proposer cannot approve | Refused; a second admin must approve |
Offers
| Rule | What the system does |
|---|---|
| Pay is not recruitment data | No pay lines and no 'compensation' key in the response; 'Pay is restricted'; saving pay is refused with 'Setting pay needs the pay permission.' |
| Offer approver is not the author | Each tries Approve and Reject (API) -> 403 'You cannot decide an offer you prepared.'; buttons not shown; a third person can decide |
Candidates
| Rule | What the system does |
|---|---|
| Identity number restricted | ID number field absent; response has has_id_number true and no id_number; PATCH with a different number refused 'Recording an identifier needs the private personnel permission.'; PATCH without it keeps the number on file |
New hire
| Rule | What the system does |
|---|---|
| Hire needs four permissions | Create employee refused (403) without employee.manage, private.manage and contract.manage; creates nothing; all four succeed |
Hiring menus
| Rule | What the system does |
|---|---|
| View versus manage | Candidates and Offers open read-only; New hire menu entry hidden; New candidate / New hire buttons absent; POST/PATCH refused (403) |
Pay changes
| Rule | What the system does |
|---|---|
| Whole pay area needs hr.pay.view | Pay changes and Benefit plans menu entries hidden; GET /hr/pay-changes, /benefit-plans and /pay-adjustments refused; employee Job & pay shows no pay history |
| Maker-checker on pay | Cannot approve or reject it (403 'A pay change is approved by somebody other than whoever wrote or submitted it.'); a different approver can; the requester can still withdraw it |
| Apply needs manage, decide needs approve | Approver cannot Apply or Submit; manager cannot Approve; both are refused server-side (403) |
| History is append-only and retro is never quiet | No edit or delete of a version is offered; PATCH on an Applied change refused 'A applied request can no longer be edited.'; retroactive apply needs the explicit acknowledgement |
Terminations
| Rule | What the system does |
|---|---|
| Maker-checker on termination | Cannot approve it (403 'A different person must approve a separation you recorded.'); cannot decide a waiver they requested; another approver can |
| Approver-only actions | Approve, Revoke access now, decide waivers, terminate before the last day and Reinstate are refused (403) and their buttons are inactive; running the process (clearances, freeze, terminate on the day) works |
| View versus run | List and record readable; no Start offboarding; every command refused (403) |
| Own team scope | Only terminations of their own scope are listed; others are not in the list or by id |
| Settlement shows no money | Settlement card, handoff and event carry state, number, dates and identifiers only; no amounts anywhere in HR |
| Edits conflict safely | Stale revision refused 'This separation changed. Reload before continuing.'; the same request id replays the first answer; the same id with different data -> 'This request ID was already used with different command data.' |
Dispute holds
| Rule | What the system does |
|---|---|
| Placer cannot release | Refused 'A different person must release a hold you placed.'; holds need hr.hold.manage; viewer with hr.employee.view only sees the list but no Place / Release |
Onboarding tasks
| Rule | What the system does |
|---|---|
| Who may tick a task | Assignee and HR can mark Done; unrelated employee gets 404 (task hidden); only HR can waive or reopen |
Checklists and masters
| Rule | What the system does |
|---|---|
| Configure right | Refused (403); with hr.configure the save works and is audited |
Hiring / pay / offboarding
| Rule | What the system does |
|---|---|
| Company isolation | Candidates, offers, pay changes, plans, terminations and holds of company 1 are not listed and return 404 by id |
Time off
| Rule | What the system does |
|---|---|
| Scope of the request list | 1 sees every request; 2 sees only his direct reports' requests; 3 gets 'You do not have access to time off.' |
Time off > Request leave
| Rule | What the system does |
|---|---|
| Request leave button vs rights | Omar sees the list but no 'Request leave' button; the viewer sees the button. |
| Retry safety | Same answer, no duplicate; conflict for a changed body. |
Approvals > Leave request
| Rule | What the system does |
|---|---|
| Nobody approves their own leave | 403 'A different HR user must decide this leave request.'; the other user succeeds. |
| Manager decides only the team's leave | Refused or not found; only the reporting manager or HR decides. |
Leave types
| Rule | What the system does |
|---|---|
| Configure permission for leave setup | Screens readable; New, Save, Add holiday, Run are not offered; the API refuses writes (hr.configure). |
| Edit conflicts | The second gets 'This leave type changed. Reload before continuing.' / 'This request changed. Reload before deciding.' / revision conflict; nothing is overwritten. |
Accrual plans
| Rule | What the system does |
|---|---|
| Author is not the reviewer | 403 'A plan is approved by somebody other than its author.'; adding cases needs hr.leave.policy.approve; Hamdan succeeds; a case by the author never counts. |
| Approved figures cannot change | 'Only a configured plan can be edited. Make a new version to change the figures.'; a changed figure after approval is refused at activation 'The plan's figures changed after it was approved.' |
| Company isolation | Not found, or 'Choose an employee of this company.' / "Choose one of this company's leave types."; nothing of company B is read or changed. |
Allocations & adjustments
| Rule | What the system does |
|---|---|
| Maker-checker on balances | 403 'A different HR user must decide this request.'; 403 'Nobody decides a change to their own leave balance.'; no permission -> refused; 403 'Only the person who asked can withdraw it.' |
| Who may ask | Refused (permission hr.leave.allocate); the button is not offered. |
Accrual runs
| Rule | What the system does |
|---|---|
| Real runs need configure | Refused; Preview rights follow the screen; the screen disables the buttons with 'Needs the HR configure permission.' |
Leave ledger
| Rule | What the system does |
|---|---|
| Report permission | Menu entry hidden; the screen says 'The leave ledger needs the HR report permission.'; the API refuses. |
Leave balances
| Rule | What the system does |
|---|---|
| Balances stay inside scope | Only his team's balances appear; nobody outside the scope is returned. |
Attendance days
| Rule | What the system does |
|---|---|
| Scope of attendance | Company viewer: all; manager: direct reports only; no scope: 'You do not have access to attendance.'; a day outside the scope opens as not found. |
Attendance day record
| Rule | What the system does |
|---|---|
| Decide your own day | 403 'You cannot decide your own day.' (approve) and 403 'You cannot correct your own day.' |
| Payroll-locked days | 'Payroll has this day already.' / 'Payroll has this day. Correct it in the next period.'; nothing in frozen pay is rewritten. |
Corrections
| Rule | What the system does |
|---|---|
| Maker-checker on corrections | 403 'A correction is decided by somebody other than the person who raised it.'; 403 'You cannot decide your own correction.'; 403 'This correction is not yours to decide.' |
Overtime approvals
| Rule | What the system does |
|---|---|
| Overtime decision rights | 403 'You cannot decide your own overtime.'; 403 'This overtime is not yours to decide.'; HR succeeds (still not their own). |
Timesheets
| Rule | What the system does |
|---|---|
| Own sheets and decisions | 1 sees only own; 2 not found; 3 403 'You cannot decide your own timesheet.'; 4 403 'A timesheet is decided by somebody other than the person who submitted it.' |
| Who may create or edit a sheet | 1 'You cannot start a timesheet for this employee.' (or not found); 2 allowed; 3 'Only a draft or returned timesheet can be edited.' |
Shifts
| Rule | What the system does |
|---|---|
| Shifts, rosters and calendars need the right permission | 1 refused; 2 assignment refused; 3 creation refused (create = hr.configure, assign = hr.attendance.manage). |
Applications > Employees > Features
| Rule | What the system does |
|---|---|
| Switches refuse writes but keep reads | Writes refused with 'capability_disabled'; menus disappear; old records still read. |
Attendance exceptions
| Rule | What the system does |
|---|---|
| Export respects scope | Manager's file has only the team; HR's the company within filters; no scope -> 403 'You do not have access to attendance.' |
Expenses
| Rule | What the system does |
|---|---|
| Three separate authorities | Refused 'You do not have permission for this action.' |
| Company isolation | Not found |
Expense claim record
| Rule | What the system does |
|---|---|
| No approving your own claim or trip | Refused 'A different approver must decide your own claim.' / '... own trip.' |
| Stale decision | Refused 'This claim changed. Reload before deciding.' |
Talent (API)
| Rule | What the system does |
|---|---|
| Reviews private | Peer sees nothing (not even that it exists); manage sees progress, not content |