Roles and data scope
Access to Rifena is determined by two independent questions:
- What can you do? — determined by the role.
- Whose data can you act on? — determined by data scope.
Permission to view a profile with Self only scope does not grant access to the employee list. Belonging to a group does not automatically grant permission to manage it.
Swipe horizontally to see every column in the tables.
A role determines actions
A role is a set of actions needed for a job, such as:
- viewing or updating employee profiles;
- handling timesheets;
- creating, approving, or paying a payroll run;
- managing organisation structure; and
- configuring policies and access.
A person may receive several roles. When checking access, find the required action across every active role instead of relying on a role name that merely sounds appropriate.
Scope determines data
| Displayed scope | The user can work with | Common use |
|---|---|---|
| Organization-wide | Eligible data across the organisation | Administrators, organisation-wide HR, central payroll |
| By group | Selected groups, plus child groups when included | Department manager, HR responsible for one division |
| Self only | The user’s own data | Employee Portal, payslips, personal requests |
When someone sees too much, find every other assignment with a wider scope. Narrowing one row does not remove scope inherited from another row.
Where access can come from
| Assignment source | Meaning | Suitable when |
|---|---|---|
| Direct grant | A role is assigned to one named person | A justified exception or temporary responsibility |
| By group | A role follows group membership | Responsibility belongs to a department or team |
| By position | A role follows the person holding a position | Responsibility stays with a job, not one individual |
Each assignment can have its own scope, child-group choice, and validity. When a person changes group or position, review every related assignment instead of assuming access now matches the new job.
Why a menu or action is missing
- Administration areas appear only with the required action and scope.
- Self-service areas may still appear without administration access.
- A record state may hide an action even when the user has its permission.
- Seeing a screen does not guarantee every action on it is available.
Check in this order: organisation → record state → role → scope → assignment source.
Grant access safely
- Open System → Settings → Roles & Permissions.
- Select a role containing the action genuinely required for the job.
- Select the narrowest scope that still permits the task.
- Check the subject, child groups, and validity before granting.
- Open Assignments and confirm the new record.
- Test with a representative account: one in-scope and one out-of-scope record.
- Read Audit log when you need to identify who granted or revoked it.
See Approvals and permissions for the complete setup and Access and notification issues for incorrect scope.