Roles and permissions
Choose a built-in or custom access role, understand every available permission, apply department coverage, and verify the result.
Updated September 11, 2026
In this article
- Permissions
- Understand built-in access roles
- Understand every permission
- Keep financial access separate
- Department coverage
- Save department coverage
- Create a custom access role
- Review issues within your access
- Example: choose roles for a department manager
- Review a person’s access
- Test before broad assignment
An access role answers two questions: what can this person do, and where can they do it? The permissions in the role define what the person is allowed to do. Assignment to an approval step determines which review work generates personal alerts. Department coverage limits the records included in those responsibilities.
FTE Tree provides built-in access roles for common responsibilities. Your organization can also create custom access roles when a built-in role is too broad or does not combine permissions in the way your team works.
Help articles use the exact permission names, such as View positions and Manage employees, when explaining the access you need. These permissions are granted through your access roles.
Some exact permission names use HRIS, which means a human resources information system.
Permissions
| Activity | Permission and scope required |
|---|---|
| Review roles, assignments, and department coverage | Review user access |
| Create a custom role or assign, move, or remove a role | Manage user access |
| Review your own assigned roles | No additional organization permission is required |
Built-in access roles that normally include the permissions in this article:
| Permission | Built-in access roles |
|---|---|
| Manage user access | Organization administrator, User access and sign-in administrator |
| Review user access | Organization administrator, User access and sign-in administrator |
Custom access roles can also include these permissions. The department coverage requirements above still determine which records a person can use.
Understand built-in access roles
Built-in access roles cannot be edited, so their meaning stays consistent. An organization administrator can make a built-in role unavailable for new assignments without changing people who already have it.
| Built-in access role | Intended responsibility | Assignment coverage |
|---|---|---|
| Organization administrator | Full organization administration and all-departments access, including protected financial areas | All departments |
| User access and sign-in administrator | Manage users, access roles, sign-in requirements, and email security choices | Organization wide |
| Billing administrator | View and manage the subscription and billing information | Organization wide |
| Position setup administrator | Maintain the job catalog, schedules, position settings, numbering, and assignment types | Organization wide |
| Workforce administrator | Maintain positions and employees, administer active requests, correct authorized staffing issues, and export authorized reports | Assigned departments |
| Budget and forecast planner | Maintain labor budgets and forecasts and view the supporting positions and employees | Assigned departments |
| Compensation administrator | Maintain protected actual compensation and resolve compensation work | Assigned departments |
| Department requester | Create and maintain positions and submit position requests without managing employees or administering requests | Assigned departments |
| Analyst | View positions and employees and export authorized reports without changing records | Assigned departments |
| Viewer | View positions and employees without changing records or exporting reports | Assigned departments |
Choose the narrowest built-in role that matches the person’s real responsibility. Add a second role only when that person truly performs both responsibilities. Do not assign Organization administrator merely to make a missing page appear.
Understand every permission
| Permission | What it allows | Built-in access roles that include it |
|---|---|---|
| View positions | View approved position structure in assigned departments | Organization administrator, Workforce administrator, Budget and forecast planner, Compensation administrator, Department requester, Analyst, Viewer |
| Manage positions | Create and maintain positions in assigned departments; also includes viewing positions | Organization administrator, Workforce administrator, Department requester |
| Manage position setup | Maintain numbering, assignment types, schedules, and annual hours | Organization administrator, Position setup administrator |
| Manage job catalog | Maintain job groups, job codes, department availability, labels, and job-code external IDs | Organization administrator, Position setup administrator |
| View employees | View employees in assigned departments | Organization administrator, Workforce administrator, Budget and forecast planner, Compensation administrator, Analyst, Viewer |
| Manage employees | Maintain employees and assignments in assigned departments; also includes viewing employees | Organization administrator, Workforce administrator |
| View labor budgets | Review budget rates and labor budget results in assigned departments | Organization administrator, Budget and forecast planner |
| Manage labor budgets | Maintain budget rates, adjustments, work items, and results in assigned departments; also includes viewing labor budgets | Organization administrator, Budget and forecast planner |
| View workforce forecasts | Review forecasts in assigned departments | Organization administrator, Budget and forecast planner |
| Manage workforce forecasts | Create and maintain forecasts in assigned departments; also includes viewing forecasts | Organization administrator, Budget and forecast planner |
| View actual compensation | Review protected actual compensation in assigned departments | Organization administrator, Compensation administrator |
| Manage actual compensation | Maintain protected compensation records, adjustments, and work items in assigned departments; also includes viewing actual compensation | Organization administrator, Compensation administrator |
| View HRIS integrations | Review connection status, recent updates, matching information, and compensation responsibility when human resources system connections are available | Organization administrator |
| Manage HRIS integrations | Configure connections, update sign-in and matching information, and choose compensation responsibility when human resources system connections are available; also includes viewing connections | Organization administrator |
| Submit position requests | Submit requests for positions the person is allowed to view | Organization administrator, Workforce administrator, Department requester |
| Administer active approval requests | Decide for an assigned approver or override an active request the person is allowed to view | Organization administrator, Workforce administrator |
| Export reports | Download report files after the person has the permission needed to view the report | Organization administrator, Workforce administrator, Analyst |
| Manage organization settings | Maintain departments, shared fields, request setup, and other organization choices | Organization administrator |
| Run batch imports | Validate and apply organization-wide imports after the person also has the management permission for the imported information | Organization administrator |
| Manage user access | Manage members, access roles, assignments, and department coverage; also includes reviewing user access | Organization administrator, User access and sign-in administrator |
| Review user access | Review members, roles, assignments, and department coverage without changing them | Organization administrator, User access and sign-in administrator |
| Manage sign-in security | Maintain organization MFA and email-domain requirements | Organization administrator, User access and sign-in administrator |
| View billing | Review subscription and billing information | Organization administrator, Billing administrator |
| Manage billing | Change subscription and billing information; also includes viewing billing | Organization administrator, Billing administrator |
The permission names shown on the access-role page are the final choices available to your organization. Some optional features appear only when they are available for your organization.
The Manage job catalog permission alone keeps financial reference fields hidden. Add the View labor budgets permission for All departments only when the catalog manager must view or select those fields. Pay grades, ranges, and pay adjustment rules require the Manage labor budgets permission for All departments.
Keep financial access separate
Position access does not grant employee, labor budget, actual compensation, or forecast access. Labor budget and actual compensation do not grant one another. This lets a department manager maintain position structure without seeing employee or protected financial information.
For example, a workforce administrator can maintain a position and its employee assignments without seeing labor budget rates or employee compensation. A compensation administrator can maintain protected compensation without being able to change the position.
Department coverage
A department-based access role must be paired with department coverage. Coverage can identify one department, selected departments, or all departments. It can also include departments placed beneath a selected department when that choice is enabled.
The same role can be assigned more than once with different coverage. For example, a person could be a Workforce administrator for Operations and a Viewer for Finance.
Organization-wide roles do not use department coverage. They cover responsibilities such as billing, sign-in security, and access administration.
When a person needs to complete one task across several departments, confirm that every required department is covered. A report or comparison that includes an uncovered department may be unavailable even if the person can view the same kind of information elsewhere.
Save department coverage
A department scope is a named selection of departments that you can reuse when assigning roles. You need the Manage user access permission, and you can grant only coverage within your own authority.
- Open Settings, then Department scopes and Create department scope. Labels may use your organization’s name for departments.
- Enter a recognizable name and description.
- Under Coverage, choose all departments or specific starting departments.
- For selected departments, choose Include lower-level departments if the selection should also cover departments beneath them.
- Save, then select this coverage when assigning a department-based role.
Open a saved selection to review its departments and the people using it. Before editing, check every affected role assignment. Including lower-level departments follows the dated hierarchy, so a department move can change access during the dates being reviewed.
Disable retains assignments and history but stops this selection from granting department access. Enable restores its contribution to existing assignments. Review the people affected before either action; another role may still provide access. Built-in selections cannot be edited like custom ones.
Create a custom access role
Create a custom role when none of the built-in roles matches the responsibility closely enough.
- Open Settings > Access roles.
- Select Create access role.
- Enter a name that describes the business responsibility, such as “Regional position reviewer.”
- Add only the permissions required for that responsibility. FTE Tree determines whether the role needs department coverage from those permissions. Organization-wide capabilities do not expand access to position, employee, or financial records.
- Save the role.
- Review the role’s Reporting access to see which reports it enables.
- Assign the role to a representative person with the intended department coverage.
- Verify the pages, actions, protected values, and report downloads that person can use.
Avoid naming a custom role after one person. A responsibility-based name remains understandable when assignments change.
Review issues within your access
Issues uses each area’s existing read and management permissions. A position reader cannot see missing budget or employee pay information. A person who can read an issue but cannot correct it sees an explanation without an active correction link. A shared issue can be reviewed as a whole only with authority over all affected records or its shared setup correction.
Example: choose roles for a department manager
Taylor maintains positions and submits position requests for the West department. Taylor does not manage employees, approvals, reports, labor budget, forecasts, or compensation.
The Department requester role is the narrowest built-in choice for Taylor. Assign it with West department coverage, then verify that Taylor can create and submit position work for West, cannot open another department, and cannot see employee or protected financial areas.
If Taylor also needs to manage employees or download reports, add a separate role only for those responsibilities or create a custom department-based role with the required permissions.
Review a person’s access
Open the member’s access page or run Access Review. Check:
- every active access role;
- the department coverage attached to each role;
- whether a role is built in or custom;
- the start and end dates for temporary assignments;
- which reports the combined access enables; and
- whether protected financial access is still necessary.
One person can receive the same permission from more than one role. Review the combined result before removing a single assignment. Removing one role may not remove the permission if another active role still includes it.
Test before broad assignment
Use a representative account to confirm navigation, records, downloads, and protected values before assigning a new role widely. Seeing a page does not mean every action or record on it should be available.
Check at least one department that should be included and one that should be excluded. For protected areas, also confirm that employee names, financial amounts, and exported files follow the intended access.