An access role answers two questions: what can this person do, and where can they do it? The permissions in the role define what the person is allowed to do. Assignment to an approval step determines which review work generates personal alerts. Department coverage limits the records included in those responsibilities.

FTE Tree provides built-in access roles for common responsibilities. Your organization can also create custom access roles when a built-in role is too broad or does not combine permissions in the way your team works.

Help articles use the exact permission names, such as View positions and Manage employees, when explaining the access you need. These permissions are granted through your access roles.

Some exact permission names use HRIS, which means a human resources information system.

Permissions

Activity Permission and scope required
Review roles, assignments, and department coverage Review user access
Create a custom role or assign, move, or remove a role Manage user access
Review your own assigned roles No additional organization permission is required

Built-in access roles that normally include the permissions in this article:

Permission Built-in access roles
Manage user access Organization administrator, User access and sign-in administrator
Review user access Organization administrator, User access and sign-in administrator

Custom access roles can also include these permissions. The department coverage requirements above still determine which records a person can use.

Understand built-in access roles

Built-in access roles cannot be edited, so their meaning stays consistent. An organization administrator can make a built-in role unavailable for new assignments without changing people who already have it.

Built-in access role Intended responsibility Assignment coverage
Organization administrator Full organization administration and all-departments access, including protected financial areas All departments
User access and sign-in administrator Manage users, access roles, sign-in requirements, and email security choices Organization wide
Billing administrator View and manage the subscription and billing information Organization wide
Position setup administrator Maintain the job catalog, schedules, position settings, numbering, and assignment types Organization wide
Workforce administrator Maintain positions and employees, administer active requests, correct authorized staffing issues, and export authorized reports Assigned departments
Budget and forecast planner Maintain labor budgets and forecasts and view the supporting positions and employees Assigned departments
Compensation administrator Maintain protected actual compensation and resolve compensation work Assigned departments
Department requester Create and maintain positions and submit position requests without managing employees or administering requests Assigned departments
Analyst View positions and employees and export authorized reports without changing records Assigned departments
Viewer View positions and employees without changing records or exporting reports Assigned departments

Choose the narrowest built-in role that matches the person’s real responsibility. Add a second role only when that person truly performs both responsibilities. Do not assign Organization administrator merely to make a missing page appear.

Understand every permission

Permission What it allows Built-in access roles that include it
View positions View approved position structure in assigned departments Organization administrator, Workforce administrator, Budget and forecast planner, Compensation administrator, Department requester, Analyst, Viewer
Manage positions Create and maintain positions in assigned departments; also includes viewing positions Organization administrator, Workforce administrator, Department requester
Manage position setup Maintain numbering, assignment types, schedules, and annual hours Organization administrator, Position setup administrator
Manage job catalog Maintain job groups, job codes, department availability, labels, and job-code external IDs Organization administrator, Position setup administrator
View employees View employees in assigned departments Organization administrator, Workforce administrator, Budget and forecast planner, Compensation administrator, Analyst, Viewer
Manage employees Maintain employees and assignments in assigned departments; also includes viewing employees Organization administrator, Workforce administrator
View labor budgets Review budget rates and labor budget results in assigned departments Organization administrator, Budget and forecast planner
Manage labor budgets Maintain budget rates, adjustments, work items, and results in assigned departments; also includes viewing labor budgets Organization administrator, Budget and forecast planner
View workforce forecasts Review forecasts in assigned departments Organization administrator, Budget and forecast planner
Manage workforce forecasts Create and maintain forecasts in assigned departments; also includes viewing forecasts Organization administrator, Budget and forecast planner
View actual compensation Review protected actual compensation in assigned departments Organization administrator, Compensation administrator
Manage actual compensation Maintain protected compensation records, adjustments, and work items in assigned departments; also includes viewing actual compensation Organization administrator, Compensation administrator
View HRIS integrations Review connection status, recent updates, matching information, and compensation responsibility when human resources system connections are available Organization administrator
Manage HRIS integrations Configure connections, update sign-in and matching information, and choose compensation responsibility when human resources system connections are available; also includes viewing connections Organization administrator
Submit position requests Submit requests for positions the person is allowed to view Organization administrator, Workforce administrator, Department requester
Administer active approval requests Decide for an assigned approver or override an active request the person is allowed to view Organization administrator, Workforce administrator
Export reports Download report files after the person has the permission needed to view the report Organization administrator, Workforce administrator, Analyst
Manage organization settings Maintain departments, shared fields, request setup, and other organization choices Organization administrator
Run batch imports Validate and apply organization-wide imports after the person also has the management permission for the imported information Organization administrator
Manage user access Manage members, access roles, assignments, and department coverage; also includes reviewing user access Organization administrator, User access and sign-in administrator
Review user access Review members, roles, assignments, and department coverage without changing them Organization administrator, User access and sign-in administrator
Manage sign-in security Maintain organization MFA and email-domain requirements Organization administrator, User access and sign-in administrator
View billing Review subscription and billing information Organization administrator, Billing administrator
Manage billing Change subscription and billing information; also includes viewing billing Organization administrator, Billing administrator

The permission names shown on the access-role page are the final choices available to your organization. Some optional features appear only when they are available for your organization.

The Manage job catalog permission alone keeps financial reference fields hidden. Add the View labor budgets permission for All departments only when the catalog manager must view or select those fields. Pay grades, ranges, and pay adjustment rules require the Manage labor budgets permission for All departments.

Keep financial access separate

Position access does not grant employee, labor budget, actual compensation, or forecast access. Labor budget and actual compensation do not grant one another. This lets a department manager maintain position structure without seeing employee or protected financial information.

For example, a workforce administrator can maintain a position and its employee assignments without seeing labor budget rates or employee compensation. A compensation administrator can maintain protected compensation without being able to change the position.

Department coverage

A department-based access role must be paired with department coverage. Coverage can identify one department, selected departments, or all departments. It can also include departments placed beneath a selected department when that choice is enabled.

The same role can be assigned more than once with different coverage. For example, a person could be a Workforce administrator for Operations and a Viewer for Finance.

Organization-wide roles do not use department coverage. They cover responsibilities such as billing, sign-in security, and access administration.

When a person needs to complete one task across several departments, confirm that every required department is covered. A report or comparison that includes an uncovered department may be unavailable even if the person can view the same kind of information elsewhere.

Save department coverage

A department scope is a named selection of departments that you can reuse when assigning roles. You need the Manage user access permission, and you can grant only coverage within your own authority.

  1. Open Settings, then Department scopes and Create department scope. Labels may use your organization’s name for departments.
  2. Enter a recognizable name and description.
  3. Under Coverage, choose all departments or specific starting departments.
  4. For selected departments, choose Include lower-level departments if the selection should also cover departments beneath them.
  5. Save, then select this coverage when assigning a department-based role.

Open a saved selection to review its departments and the people using it. Before editing, check every affected role assignment. Including lower-level departments follows the dated hierarchy, so a department move can change access during the dates being reviewed.

Disable retains assignments and history but stops this selection from granting department access. Enable restores its contribution to existing assignments. Review the people affected before either action; another role may still provide access. Built-in selections cannot be edited like custom ones.

Create a custom access role

Create a custom role when none of the built-in roles matches the responsibility closely enough.

  1. Open Settings > Access roles.
  2. Select Create access role.
  3. Enter a name that describes the business responsibility, such as “Regional position reviewer.”
  4. Add only the permissions required for that responsibility. FTE Tree determines whether the role needs department coverage from those permissions. Organization-wide capabilities do not expand access to position, employee, or financial records.
  5. Save the role.
  6. Review the role’s Reporting access to see which reports it enables.
  7. Assign the role to a representative person with the intended department coverage.
  8. Verify the pages, actions, protected values, and report downloads that person can use.

Avoid naming a custom role after one person. A responsibility-based name remains understandable when assignments change.

Review issues within your access

Issues uses each area’s existing read and management permissions. A position reader cannot see missing budget or employee pay information. A person who can read an issue but cannot correct it sees an explanation without an active correction link. A shared issue can be reviewed as a whole only with authority over all affected records or its shared setup correction.

Example: choose roles for a department manager

Taylor maintains positions and submits position requests for the West department. Taylor does not manage employees, approvals, reports, labor budget, forecasts, or compensation.

The Department requester role is the narrowest built-in choice for Taylor. Assign it with West department coverage, then verify that Taylor can create and submit position work for West, cannot open another department, and cannot see employee or protected financial areas.

If Taylor also needs to manage employees or download reports, add a separate role only for those responsibilities or create a custom department-based role with the required permissions.

Review a person’s access

Open the member’s access page or run Access Review. Check:

  • every active access role;
  • the department coverage attached to each role;
  • whether a role is built in or custom;
  • the start and end dates for temporary assignments;
  • which reports the combined access enables; and
  • whether protected financial access is still necessary.

One person can receive the same permission from more than one role. Review the combined result before removing a single assignment. Removing one role may not remove the permission if another active role still includes it.

Test before broad assignment

Use a representative account to confirm navigation, records, downloads, and protected values before assigning a new role widely. Seeing a page does not mean every action or record on it should be available.

Check at least one department that should be included and one that should be excluded. For protected areas, also confirm that employee names, financial amounts, and exported files follow the intended access.