Settings and roles
Who sees what: owner, HR admin, manager, and employee.
Four roles. Each is enforced by row-level security in the database, so what somebody cannot see is not returned to their browser at all — the interface is not what is protecting it.
What each role can do
- Owner — everything an HR admin can do, plus billing and the organisation itself. An organisation always keeps at least one active owner; the last one cannot be removed or demoted.
- HR admin — the whole organisation: every person, every request, compensation, payroll, hiring, performance and settings.
- Manager — their reporting line, recursively. Their team's requests, timesheets, goals and reviews. No access to compensation, anywhere, for anyone.
- Employee — themselves, plus the public directory fields of colleagues.
Managers are excluded from compensation entirely and deliberately. Everywhere else in this product a manager sees their line; here they see nothing, because 'what does my report earn?' is not a question the reporting relationship entitles anyone to answer.
Does this not match what you see on screen? That's a bug in the guide — tell us and we'll fix it.