Account and access
Roles and permissions
Understand permissions, department access, access roles, approver assignments, and how to review a person's current access.
Updated August 9, 2026
Overview
Permissions determine what a user can see and do in FTE Tree. Access roles group permissions for common responsibilities, and department access limits position, employee, and compensation information to the appropriate parts of your organization.
Start with a standard role. Create a custom role only when a person’s responsibilities genuinely differ from those roles.
Standard access roles
| Role | Responsibility |
|---|---|
| Organization administrator | Full organization access across all departments, including compensation, access, security, and billing. |
| User access and sign-in administrator | Invitations, users, access roles, department access, company group mappings, identity providers, sign-in enforcement, and access review. |
| Billing administrator | Plans, usage, subscription, invoices, and billing portal access. |
| Position setup administrator | Job codes, schedules, position numbering and defaults, FTE options, Position statuses, hours per FTE, reference pay guidance, and HR handoff steps. It does not include workforce records, field configuration, pay grade ranges, or adjustment rules. |
| HR handoff coordinator | Approved-position HR handoffs for selected departments. It includes viewing those positions, but not changing positions, deciding approvals, changing setup, viewing employees or sensitive data, or downloading reports. |
| Workforce administrator | Approved-position HR handoffs, positions, employees, assignments, sensitive workforce data, requests, active-request administration, reports, and workforce imports for selected departments. It does not include organization-wide position setup. |
| Department requester | View positions and approved-handoff progress, and submit position requests for selected departments. It cannot change positions, employees, or handoff steps. |
| Analyst | Position and employee viewing, approved-handoff progress, and report downloads for selected departments. Exact pay amounts and handoff changes are not included. |
| Viewer | Read-only position, employee, and approved-handoff progress for selected departments. Exact pay, report downloads, and handoff changes are not included. |
Managing positions and managing HR handoffs each include viewing positions in the same departments. Managing HR handoffs does not include changing positions. Managing employees similarly includes viewing those employees and participating in employee comments. Users with only View employees can read existing comments but cannot add, reply to, edit, or redact comments. None of these responsibilities automatically includes View sensitive workforce data.
The standard combined administrator is intended for the person or small team responsible for both user access and company sign-in. If those duties must be separated, create one custom role with Manage user access and another with Manage sign-in security. Keep at least one active local user for each responsibility; the same person may satisfy both.
Organizations that used an earlier Access administrator, Security administrator, Manager, or broader Workforce administrator keep those assigned permissions in a custom role labeled (preserved permissions). Existing users, pending invitations, and company group mappings are not silently broadened or reduced. Use the current standard roles for new assignments and review preserved roles when convenient.
Permission names
FTE Tree provides 17 permission choices. Roles combine these choices; custom roles can use the same catalog without creating a permission for every button or page.
| Permission | What it covers |
|---|---|
| View positions | Positions, department structure, and approved-handoff progress in the selected departments. It does not allow changing handoff steps. |
| Manage positions | Creating and maintaining positions; includes viewing them. |
| Manage position setup | Job codes, schedules, annual hours, numbering, FTE options, Position statuses, reference-pay guidance, and HR handoff steps. |
| Manage HR handoffs | Approved-position HR handoffs; includes viewing the related positions. |
| View employees | Employee records and existing employee comments in the selected departments. |
| Manage employees | Employee records, assignments, status changes, and employee comments; includes viewing employees. |
| View sensitive workforce data | Protected pay, cost, compensation-rule, approval, and sensitive custom-field values in the selected departments. |
| Submit position requests | Position requests for positions already available to the user. |
| Administer active approval requests | Needs-attention work, responses on behalf of approvers, and request overrides within existing Position access. |
| Export reports | Downloading report data the user is already allowed to read. |
| Manage organization settings | Organization structure, field setup, approval settings, organization-owned imports, and other shared configuration. |
| Reverse imports | Reversing completed imports when the user still has the matching data authority. |
| Manage user access | Invitations, users, roles, assignments, department access, and company group mappings; includes access review. |
| Review user access | Read-only review of users, roles, assignments, department access, and access evidence. |
| Manage sign-in security | Identity providers and company sign-in enforcement. |
| View billing | Plans, usage, subscription, and billing information. |
| Manage billing | Subscription and billing changes; includes viewing billing. |
Stop offering or disable an access role
These actions have different effects:
| Action | New assignments | Existing assignments |
|---|---|---|
| Make unavailable | The role can no longer be selected. | Existing access keeps working. |
| Disable | A custom role cannot be selected. | Access from the role stops immediately. |
Use Make unavailable when you want to stop offering a standard or custom role without removing anyone’s current access. Existing user assignments and company group connections keep working. Choose Make available to offer the role again.
Use Actions > Disable on a custom role when its existing access must stop immediately. FTE Tree keeps the role, assignments, company group connections, and activity history, but they grant no access while the role is disabled. Choose Enable to restore that access. Review affected users before disabling a role.
Department access
Department access applies to six areas:
- Viewing positions.
- Managing positions.
- Managing approved-position HR handoffs.
- Viewing employees.
- Managing employees.
- Viewing compensation.
The standard access form uses one workforce department selection for these areas. Choose All departments only when the person genuinely needs organization-wide access. A blank department selection grants no department access.
Advanced access can use different boundaries when necessary. For example, someone might view positions across the organization, manage employees in one division, and view compensation only in Finance. Keep these exceptions intentional and review them regularly.
When saving a reusable department selection, choose All departments or Selected departments. For Selected departments, choose one or more starting departments and whether every department below them should be included. Disabling a saved selection takes effect immediately: existing assignments that use it grant no department access, and the selection cannot be used for new assignments until you enable it again.
Employee access follows the employee’s owning department, not whichever positions the employee happens to fill. Moving or ending an assignment therefore does not silently change who can see the employee.
View sensitive workforce data
View sensitive workforce data is separate permission for protected workforce values. It does not make an employee or position visible by itself.
To see protected position information, a user needs both position access and View sensitive workforce data for every department included in the view. Protected information includes:
- Position pay rates, calculated costs, and pay rate basis.
- Assigned cost.
- Pay grade dollar ranges and where pay falls within the range.
- Bonus and adjustment amounts.
- Custom currency fields and fields marked as sensitive.
- Protected approval information.
When a view covers several positions, dates, or departments, both kinds of access must cover all of them.
When View sensitive workforce data is combined with Position management, the user can also update Position pay assumptions. Department requesters, Analysts, and Viewers do not receive View sensitive workforce data by default.
For an approval request, exact pay, costs, pay grade amounts, explanations, comments, additional files, and named files labeled Sensitive access required require current position access and sensitive data access for every part of the request. A named file labeled All request reviewers is available to anyone who can review the active request. Being the requester, assigned approver, or approval administrator does not bypass the sensitive-information check. An assigned approver may still be able to record a decision while protected information appears as Restricted.
How access combines
| Access part | Question it answers | Example |
|---|---|---|
| Access role | What can this person do? | Manage positions or export reports. |
| Department access | Where can they do it? | All departments or selected departments and the departments beneath them. |
| View sensitive workforce data | May they see protected workforce values? | Exact values for the departments included in their sensitive data access. |
All required parts must be present. A role does not make records visible outside its department access, and View sensitive workforce data does not make a position or employee visible by itself.
Organization-wide capabilities
FTE Tree separates two setup responsibilities:
- Manage organization settings covers the department structure, standard and custom field setup, option sets, approval settings, and other shared organization policies.
- Manage position setup covers job code records, schedules, position numbering and defaults, FTE options, Position status choices, hours per FTE, reference pay guidance, and the approved-position HR handoff checklist. Position standard and custom fields, option sets, field order, and display settings remain under Manage organization settings because they are shared field configuration.
Neither responsibility grants access to Position or Employee records. Manage position setup is sufficient to maintain Job code reference pay guidance. Pay grade ranges and adjustment rules, including their current-value templates and imports, also require View sensitive workforce data for All departments. Assign both responsibilities through separate roles when a setup specialist needs that compensation authority.
Some responsibilities are simple organization-wide switches, such as submitting requests, administering approvals, exporting reports, changing settings, reversing imports, managing access, reviewing access, managing security, and managing billing.
Sensitive access, security, company sign-in, invitation, and recovery changes require a multi-factor authentication (MFA) check. For most protected administrative work, one completed check is accepted for up to 24 hours while the session remains active. Critical company sign-in, recovery, and support-access changes require a check within 15 minutes. Most everyday account use does not require MFA.
These capabilities do not expand data access. For example:
- Export reports permits a file only for information the user can already read.
- Request submission applies only to positions already inside the user’s position access.
- Administer active approval requests applies only to requests for positions the user can already access. It provides the Needs attention list, responses recorded on behalf of approvers, and the Override request action; it does not provide approval setup, which requires Manage organization settings.
- Import reversal still requires permission to manage the affected information.
Import access comes from the matching management responsibility. Because import files and results cover the organization, Position, Employee, and assignment imports require the matching management access across All departments. Adjustment imports additionally require Manage position setup and View sensitive workforce data across All departments. Imports that include Position pay or a custom Currency value also require sensitive data access across all departments.
Review available permissions
Users with Review user access can open Settings > Users & access > Permissions for a read-only list of the permissions available in FTE Tree. Open a permission to see what it allows, whether it can be limited to selected departments, which users currently receive it, and how reports use it.
To change a person’s access, update an access role or the person’s department access. The Permissions pages explain the available choices but do not assign access.
Approver groups
Approver groups are different from access roles. Access roles determine what a user can see and do. Approver groups identify who should approve a request for a department.
For example, a Finance Review stage in the New position workflow can name eligible members for each department. A Finance Review stage in Position elimination is a separate stage and may name different members for the same department. FTE Tree uses the request department’s assignment or the nearest assignment from a higher-level department for the exact request-type stage. Being an assigned approver allows that person to respond to the active stage; it does not grant broad approval-administration access.
At each active stage, any one assigned approver for the request’s department can decide the stage. When one person acts, the other assigned approvers no longer need to act. There is no setting to require every assigned approver or unanimous agreement.
That assignment provides access to the request while it is active. After the request closes, only the person who submitted it or someone with current access to the position can review it; the earlier approver assignment does not provide permanent access.
Best practices
- Start with a standard role and the narrowest practical department selection.
- Grant View sensitive workforce data separately and only to people who need exact pay information.
- Use the Access review report after organizational changes and at regular intervals.
- Review advanced access exceptions so they do not become permanent by accident.
- Give import reversal and approval-administration access only to trusted administrators.
- Remove access promptly when a user changes responsibilities or leaves the organization.