Skip to content
Search docs⌘K

    Roles, data access, and approvals

    At the end of this stage, representative users see only their intended data and a sample request reaches the correct approver.

    Before you begin

    Owner: an organisation administrator. The owner of each business process should help verify the result.

    The organisation structure and positions should already exist. Prepare a list of who performs each job, whose data they need, and who covers an absent approver.

    Choose or create a role

    Path: System → Settings → Roles & Permissions.

    1. Review an existing system role before creating a new one.
    2. If the work requires a distinct role, choose Create role.
    3. Enter a clear Role name, choose only the permissions required for the job, and keep the role Active.
    4. Choose Save and wait for the saved state.

    A role answers “what may this person do?”. Data access answers “whose data may they do it with?”.

    Grant the role with the right data access

    From the selected role, choose Grant this role…, or open Granted assignments and choose Grant new assignment:

    1. Select the employee, position, or group receiving the assignment.
    2. Select the Role.
    3. Select the narrowest suitable data access:
      • Organization-wide — eligible data across the organisation;
      • By group — only the selected groups, with optional descendants;
      • Self only — the recipient’s own data.
    4. For By group, select the groups and check Include subtree carefully.
    5. Choose Grant role, then confirm the assignment appears in the list.

    Use Organization-wide only when the responsibility genuinely covers the whole organisation. For a department manager or regional HR owner, prefer By group.

    Verify access before configuring approvals

    Ask a representative user to sign in again and confirm:

    • the navigation contains only the functions they need;
    • lists contain only employees or groups within their responsibility;
    • the required business screen opens;
    • records outside the assigned data access cannot be opened.

    Correct the assignment before configuring approvals if any result is wrong.

    Create an approval workflow

    Path: System → Settings → Approval workflows.

    1. Choose New.
    2. Give the workflow a recognisable name, choose the business resource and set priority.
    3. Add conditions if different workflows apply to the same request type.
    4. Add approval steps in order. Choose an approver by person, role, position, or manager where the screen supports it.
    5. Set deadlines and escalation behaviour only when the organisation has agreed rules for them.
    6. Choose Save changes.
    7. Review readiness and resolve a missing approver or insufficient approver access.
    8. Choose Activate.

    Reorder controls work only while the definition is Inactive. Before deactivating and rearranging it, review pending requests and decide whether they retain the old route or a new definition should serve future submissions.

    Run one sample request

    1. Use a test employee account to submit a request of the configured type.
    2. Confirm the request enters a pending state.
    3. Use the expected approver account and open HR → Approvals.
    4. Confirm the request appears, review it, and make the agreed test decision.
    5. Return to the sender account and confirm the final state.

    If the request reaches the wrong person, check that the workflow is Active, then review its conditions, step order, approver role, and data access. Do not send duplicate requests until one concrete condition has changed.

    Next step: Configure time and attendance policies, then repeat the test with leave and overtime.

    If a user cannot see the expected request, screen, or in-scope action, see Access and notification problems.