Skip to content
Search docs⌘K

    Roles and data scope

    Access to Rifena is determined by two independent questions:

    1. What can you do? — determined by the role.
    2. Whose data can you act on? — determined by data scope.

    Permission to view a profile with Self only scope does not grant access to the employee list. Belonging to a group does not automatically grant permission to manage it.

    Swipe horizontally to see every column in the tables.

    A role determines actions

    A role is a set of actions needed for a job, such as:

    • viewing or updating employee profiles;
    • handling timesheets;
    • creating, approving, or paying a payroll run;
    • managing organisation structure; and
    • configuring policies and access.

    A person may receive several roles. When checking access, find the required action across every active role instead of relying on a role name that merely sounds appropriate.

    Scope determines data

    Displayed scope The user can work with Common use
    Organization-wide Eligible data across the organisation Administrators, organisation-wide HR, central payroll
    By group Selected groups, plus child groups when included Department manager, HR responsible for one division
    Self only The user’s own data Employee Portal, payslips, personal requests

    When someone sees too much, find every other assignment with a wider scope. Narrowing one row does not remove scope inherited from another row.

    Where access can come from

    Assignment source Meaning Suitable when
    Direct grant A role is assigned to one named person A justified exception or temporary responsibility
    By group A role follows group membership Responsibility belongs to a department or team
    By position A role follows the person holding a position Responsibility stays with a job, not one individual

    Each assignment can have its own scope, child-group choice, and validity. When a person changes group or position, review every related assignment instead of assuming access now matches the new job.

    Why a menu or action is missing

    • Administration areas appear only with the required action and scope.
    • Self-service areas may still appear without administration access.
    • A record state may hide an action even when the user has its permission.
    • Seeing a screen does not guarantee every action on it is available.

    Check in this order: organisation → record state → role → scope → assignment source.

    Grant access safely

    1. Open System → Settings → Roles & Permissions.
    2. Select a role containing the action genuinely required for the job.
    3. Select the narrowest scope that still permits the task.
    4. Check the subject, child groups, and validity before granting.
    5. Open Assignments and confirm the new record.
    6. Test with a representative account: one in-scope and one out-of-scope record.
    7. Read Audit log when you need to identify who granted or revoked it.

    See Approvals and permissions for the complete setup and Access and notification issues for incorrect scope.