Access and permissions

Which permission each Human Resources screen needs, who may see and change what, and the rules that keep people from approving their own work.

On this page (46)

Permissions by screen

ScreenMenuPermission needed
HR HomeEmployees > HomeAny HR permission; company tiles need hr.employee.view (else own team only); Probation tile hr.contract.view; Documents tile hr.private.view
Employee directoryEmployees > Employeeshr.employee.view (list), hr.employee.manage (New employee)
Employee record - OverviewEmployees > open an employee > Overviewhr.employee.view (read), hr.employee.manage (general, photo, actions), hr.private.view / hr.private.manage (private block)
Assignments and contractsEmployee record > Job & payhr.employee.manage (assignments); hr.contract.view / hr.contract.manage (contracts); hr.pay.view (salary figures and Why?)
Documents and IDs & visasEmployee record > Documentshr.employee.view (see that documents exist and expiry); hr.private.view (numbers, files, IDs & visas section); hr.private.manage (add/upload/remove)
Record panelsEmployee record > Time & attendance / Access / Historyhr.employee.view; Access request state needs hr.employee.manage
Approvals inboxEmployees > ApprovalsAny member; each item type needs its own deciding right (profile change / document renewal: hr.private.manage)
My HREmployees > My HRAny member whose login is linked to an employee (server finds the employee from the login, never from an id)
Headcount and FTEEmployees > Reporting > Headcount & FTEhr.report.view
Document expiryEmployees > Reporting > Document expiryhr.private.view (and company-wide employee view)
Document renewalsEmployees > Reporting > Renewal campaignshr.private.view (see), hr.private.manage (campaign builder, decide)
Departments and cost centresEmployees > Configuration > Organization > Departments / Cost centresreference.manage (server); menu shows for everyone in HR
HR mastersEmployees > Configuration > Organization > Jobs / Positions / Grades / Contract typeshr.configure (save); any HR permission (read)
AssignmentsEmployees > Configuration > Organization > Assignmentshr.employee.view (list), hr.employee.manage (changes)
Approval escalationEmployees > Configuration > Approval escalationhr.employee.view (read), hr.configure (Edit)
Employees app configurationApplications > Employees > Features / FieldsCompany administrator; proposer cannot approve
New hire (guided flow)Employees > Hiring > New hirehr.recruit.manage (menu and flow); pay lines need hr.pay.manage; approve needs hr.recruit.approve; Create employee needs hr.employee.manage + hr.recruit.manage + hr.private.manage + hr.contract.manage
CandidatesEmployees > Hiring > Candidateshr.recruit.view (list), hr.recruit.manage (New candidate)
Candidate recordCandidates > open a candidatehr.recruit.view (read), hr.recruit.manage (save, screen, reject, withdraw), hr.private.view / hr.private.manage (ID number)
OffersEmployees > Hiring > Offershr.recruit.view (list), hr.recruit.manage (New hire)
Offer recordOffers > open an offerhr.recruit.manage / hr.recruit.approve / hr.pay.manage (pay lines) / hr.pay.view (see pay)
Pay changesEmployees > Pay & benefits > Pay changeshr.pay.view (list - the whole screen is pay data), hr.pay.manage (New change)
Pay change recordPay changes > open a changehr.pay.manage (submit, apply, withdraw), hr.pay.approve (approve, reject)
Benefit plansEmployees > Pay & benefits > Benefit planshr.pay.view (list), hr.pay.manage (New plan, Save)
TerminationsEmployees > Offboarding > Terminationshr.employee.view (list; rows narrowed to your scope), hr.offboard (Start offboarding)
Termination recordTerminations > open a terminationhr.employee.view (read); hr.offboard (run the process); hr.offboard.approve (approve, decide waivers, revoke access now, terminate early, reinstate); hr.hold.manage (holds)
Start offboarding (guided flow)Terminations > Start offboardinghr.offboard (and hr.employee.view)
Dispute holdsEmployees > Offboarding > Dispute holdshr.employee.view (list), hr.hold.manage (Place hold, Release)
Onboarding checklistsEmployees > Configuration > Organization > Onboarding checklistshr.configure (save); menu shows to any HR user
Offboarding checklistsEmployees > Configuration > Organization > Offboarding checklistshr.configure (save); menu shows to any HR user
Time off (requests)Employees > Time offAny HR access or a manager's team (server: 'You do not have access to time off.' otherwise); hr.employee.view to see the button
Request leave for an employee (dialog)Employees > Time off > Request leavehr.employee.view (quote and submit)
Leave balancesEmployees > Reporting > Leave balancesAny HR access or a manager's team; menu entry follows the Time off switch
Leave ledger reportEmployees > Reporting > Leave ledgerhr.report.view (menu entry and server)
Leave types (list)Employees > Configuration > Time & leave > Leave typeshr.employee.view (screen); hr.configure (create / change)
Leave type recordLeave types > open a leave typehr.configure to edit; read-only otherwise
Accrual plans (list)Employees > Configuration > Time & leave > Accrual planshr.employee.view (screen); hr.configure (create, activate, retire, new version); hr.leave.policy.approve (cases and approve)
Accrual plan recordAccrual plans > open a planhr.configure; hr.leave.policy.approve (second person)
HolidaysEmployees > Configuration > Time & leave > Holidayshr.employee.view (screen); hr.configure (add / remove)
Calendar previewHolidays / Accrual plans > Calendar previewhr.employee.view
Accrual runsEmployees > Configuration > Time & leave > Accrual runshr.employee.view (read history); hr.configure (every run); hr.leave.policy.approve (decide a review)
Allocations and adjustmentsEmployees > Configuration > Time & leave > Allocations & adjustmentshr.employee.view (read); hr.leave.allocate (request, withdraw); hr.leave.policy.approve (decide)
Attendance daysEmployees > Time & attendance > Attendance daysCompany scope with hr.employee.view, else a manager's own team ('You do not have access to attendance.')
Attendance day recordAttendance days > open a dayhr.attendance.approve (company) or mss.approve_attendance (manager of the team); hr.attendance.manage for corrections
Attendance correctionsEmployees > Time & attendance > CorrectionsScope as attendance; raise: hr.attendance.manage, the employee themselves, or a manager with mss.approve_attendance
Overtime approvalsEmployees > Time & attendance > Overtime approvalshr.attendance.approve (company) or mss.approve_overtime (manager of the team)
Weekly timesheets (list)Employees > Time & attendance > TimesheetsScope as attendance, or your own sheets; create: yourself or hr.attendance.manage
Weekly timesheet recordTimesheets > open a timesheetEmployee (own) or hr.attendance.manage; decide: hr.attendance.approve or mss.approve_timesheet
ShiftsEmployees > Configuration > Time & leave > Shiftshr.employee.view (screen); hr.configure (shift); hr.attendance.manage (assign)
RostersEmployees > Configuration > Time & leave > Rostershr.employee.view (screen); hr.configure (roster); hr.attendance.manage (assign)
Working calendarsEmployees > Configuration > Time & leave > Working calendarshr.employee.view (list); hr.configure (create / change)
Attendance exceptions reportEmployees > Reporting > Attendance exceptionsScope as attendance
Time off and Time and attendance switchesApplications > Employees > FeaturesCompany admin; two-person change
Expense claimsEmployees > Expenses > Expense claimshr.expense.view (list); hr.expense.claim (new)
Expense claim recordExpense claims > open a claimhr.expense.claim / approve / settle
TravelEmployees > Expenses > Travelhr.expense.view; hr.expense.claim (new); hr.expense.approve; hr.expense.settle (advance)
Company cardsEmployees > Expenses > Company cardshr.expense.view; hr.expense.configure (load)
Expense categoriesEmployees > Configuration > Expense categorieshr.expense.view; hr.expense.configure
Travel policiesEmployees > Configuration > Travel policieshr.expense.view; hr.expense.configure
Talent: recruitment pipeline(no menu - API only) /talent/vacancies, /applications, /interviewshr.vacancy.manage / approve, hr.applicant.all / hold, hr.recruit.manage, vacancy team
Talent: performance(no menu - API only) /talent/cycles, /reviews, /appeals, /goalshr.review.manage / view / publish
Talent: skills and learning(no menu - API only) /talent/employee-skills, /courses, /sessions, /planshr.training.view / manage / approve

Employee directory

RuleWhat the system does
View vs manageList and record visible; no New employee; Edit disabled; API POST/PATCH refused (403)
Company isolationNot found; nothing of company B returned

Employee record

RuleWhat the system does
Private block hidden without the private grantNo Private information section and no 'private' key in the response; directory, search and headcount never contain private values

Documents

RuleWhat the system does
Document numbers restrictedRows show type and expiry; Number 'Restricted', no authority, no files; 'Add a document' absent

IDs & visas

RuleWhat the system does
Identifier maskingidentifier_value empty, masked shows only the last 4 (e.g. ••••••••••••••4-1); the IDs & visas section is not offered on screen

Document files

RuleWhat the system does
File download needs the private grantRefused; an employee can download only files of their own documents via My HR

Documents / IDs

RuleWhat the system does
Writing needs hr.private.manageRefused 403

Contracts

RuleWhat the system does
Pay figures need hr.pay.viewNo Gross/bases/components/hourly; /explain refused

Approvals

RuleWhat the system does
Requester cannot decide own profile change / renewalNot listed in their inbox; API refused 'A different HR user must decide this request.' (renewal: 'A different HR user must decide this renewal.')
Inbox scopeOnly own team's leave/cancellations ('My team'); no profile changes, renewals or other employees

My HR

RuleWhat the system does
Own record onlyServer resolves the employee from the login; other ids return 'not found'

Headcount & FTE

RuleWhat the system does
Report permissionRefused by the server (menu entry is still shown)

Document expiry

RuleWhat the system does
Expiry report is private'You do not have access to this list.'; no tile on Home

Audit

RuleWhat the system does
No private values in the audit trailEntries name the action and revision (or identifier type) only - never numbers, emails or reasons

HR masters

RuleWhat the system does
Configuration needs hr.configureRefused 403

Access request

RuleWhat the system does
Raiser cannot fulfilRefused 'You cannot decide a request you raised.'; fulfil without a linked login -> 'Create the login and link it to this employee first; this request only records that it exists.'

Employees app configuration

RuleWhat the system does
Proposer cannot approveRefused; a second admin must approve

Offers

RuleWhat the system does
Pay is not recruitment dataNo pay lines and no 'compensation' key in the response; 'Pay is restricted'; saving pay is refused with 'Setting pay needs the pay permission.'
Offer approver is not the authorEach tries Approve and Reject (API) -> 403 'You cannot decide an offer you prepared.'; buttons not shown; a third person can decide

Candidates

RuleWhat the system does
Identity number restrictedID number field absent; response has has_id_number true and no id_number; PATCH with a different number refused 'Recording an identifier needs the private personnel permission.'; PATCH without it keeps the number on file

New hire

RuleWhat the system does
Hire needs four permissionsCreate employee refused (403) without employee.manage, private.manage and contract.manage; creates nothing; all four succeed

Hiring menus

RuleWhat the system does
View versus manageCandidates and Offers open read-only; New hire menu entry hidden; New candidate / New hire buttons absent; POST/PATCH refused (403)

Pay changes

RuleWhat the system does
Whole pay area needs hr.pay.viewPay changes and Benefit plans menu entries hidden; GET /hr/pay-changes, /benefit-plans and /pay-adjustments refused; employee Job & pay shows no pay history
Maker-checker on payCannot approve or reject it (403 'A pay change is approved by somebody other than whoever wrote or submitted it.'); a different approver can; the requester can still withdraw it
Apply needs manage, decide needs approveApprover cannot Apply or Submit; manager cannot Approve; both are refused server-side (403)
History is append-only and retro is never quietNo edit or delete of a version is offered; PATCH on an Applied change refused 'A applied request can no longer be edited.'; retroactive apply needs the explicit acknowledgement

Terminations

RuleWhat the system does
Maker-checker on terminationCannot approve it (403 'A different person must approve a separation you recorded.'); cannot decide a waiver they requested; another approver can
Approver-only actionsApprove, Revoke access now, decide waivers, terminate before the last day and Reinstate are refused (403) and their buttons are inactive; running the process (clearances, freeze, terminate on the day) works
View versus runList and record readable; no Start offboarding; every command refused (403)
Own team scopeOnly terminations of their own scope are listed; others are not in the list or by id
Settlement shows no moneySettlement card, handoff and event carry state, number, dates and identifiers only; no amounts anywhere in HR
Edits conflict safelyStale revision refused 'This separation changed. Reload before continuing.'; the same request id replays the first answer; the same id with different data -> 'This request ID was already used with different command data.'

Dispute holds

RuleWhat the system does
Placer cannot releaseRefused 'A different person must release a hold you placed.'; holds need hr.hold.manage; viewer with hr.employee.view only sees the list but no Place / Release

Onboarding tasks

RuleWhat the system does
Who may tick a taskAssignee and HR can mark Done; unrelated employee gets 404 (task hidden); only HR can waive or reopen

Checklists and masters

RuleWhat the system does
Configure rightRefused (403); with hr.configure the save works and is audited

Hiring / pay / offboarding

RuleWhat the system does
Company isolationCandidates, offers, pay changes, plans, terminations and holds of company 1 are not listed and return 404 by id

Time off

RuleWhat the system does
Scope of the request list1 sees every request; 2 sees only his direct reports' requests; 3 gets 'You do not have access to time off.'

Time off > Request leave

RuleWhat the system does
Request leave button vs rightsOmar sees the list but no 'Request leave' button; the viewer sees the button.
Retry safetySame answer, no duplicate; conflict for a changed body.

Approvals > Leave request

RuleWhat the system does
Nobody approves their own leave403 'A different HR user must decide this leave request.'; the other user succeeds.
Manager decides only the team's leaveRefused or not found; only the reporting manager or HR decides.

Leave types

RuleWhat the system does
Configure permission for leave setupScreens readable; New, Save, Add holiday, Run are not offered; the API refuses writes (hr.configure).
Edit conflictsThe second gets 'This leave type changed. Reload before continuing.' / 'This request changed. Reload before deciding.' / revision conflict; nothing is overwritten.

Accrual plans

RuleWhat the system does
Author is not the reviewer403 'A plan is approved by somebody other than its author.'; adding cases needs hr.leave.policy.approve; Hamdan succeeds; a case by the author never counts.
Approved figures cannot change'Only a configured plan can be edited. Make a new version to change the figures.'; a changed figure after approval is refused at activation 'The plan's figures changed after it was approved.'
Company isolationNot found, or 'Choose an employee of this company.' / "Choose one of this company's leave types."; nothing of company B is read or changed.

Allocations & adjustments

RuleWhat the system does
Maker-checker on balances403 'A different HR user must decide this request.'; 403 'Nobody decides a change to their own leave balance.'; no permission -> refused; 403 'Only the person who asked can withdraw it.'
Who may askRefused (permission hr.leave.allocate); the button is not offered.

Accrual runs

RuleWhat the system does
Real runs need configureRefused; Preview rights follow the screen; the screen disables the buttons with 'Needs the HR configure permission.'

Leave ledger

RuleWhat the system does
Report permissionMenu entry hidden; the screen says 'The leave ledger needs the HR report permission.'; the API refuses.

Leave balances

RuleWhat the system does
Balances stay inside scopeOnly his team's balances appear; nobody outside the scope is returned.

Attendance days

RuleWhat the system does
Scope of attendanceCompany viewer: all; manager: direct reports only; no scope: 'You do not have access to attendance.'; a day outside the scope opens as not found.

Attendance day record

RuleWhat the system does
Decide your own day403 'You cannot decide your own day.' (approve) and 403 'You cannot correct your own day.'
Payroll-locked days'Payroll has this day already.' / 'Payroll has this day. Correct it in the next period.'; nothing in frozen pay is rewritten.

Corrections

RuleWhat the system does
Maker-checker on corrections403 'A correction is decided by somebody other than the person who raised it.'; 403 'You cannot decide your own correction.'; 403 'This correction is not yours to decide.'

Overtime approvals

RuleWhat the system does
Overtime decision rights403 'You cannot decide your own overtime.'; 403 'This overtime is not yours to decide.'; HR succeeds (still not their own).

Timesheets

RuleWhat the system does
Own sheets and decisions1 sees only own; 2 not found; 3 403 'You cannot decide your own timesheet.'; 4 403 'A timesheet is decided by somebody other than the person who submitted it.'
Who may create or edit a sheet1 'You cannot start a timesheet for this employee.' (or not found); 2 allowed; 3 'Only a draft or returned timesheet can be edited.'

Shifts

RuleWhat the system does
Shifts, rosters and calendars need the right permission1 refused; 2 assignment refused; 3 creation refused (create = hr.configure, assign = hr.attendance.manage).

Applications > Employees > Features

RuleWhat the system does
Switches refuse writes but keep readsWrites refused with 'capability_disabled'; menus disappear; old records still read.

Attendance exceptions

RuleWhat the system does
Export respects scopeManager's file has only the team; HR's the company within filters; no scope -> 403 'You do not have access to attendance.'

Expenses

RuleWhat the system does
Three separate authoritiesRefused 'You do not have permission for this action.'
Company isolationNot found

Expense claim record

RuleWhat the system does
No approving your own claim or tripRefused 'A different approver must decide your own claim.' / '... own trip.'
Stale decisionRefused 'This claim changed. Reload before deciding.'

Talent (API)

RuleWhat the system does
Reviews privatePeer sees nothing (not even that it exists); manage sees progress, not content