Permission levels determine what each staff member is able to view and edit in Workforce.
What's covered in this guide?
Permission Levels
The default permission levels are Admin, General Manager, Payroll Officer, Manager and Employee, which can be found by going to a staff profile > Personal > Personal Details.
Admin
Admins can access everything in Workforce and can assign permissions to other staff. Admins can also impersonate other users by selecting 'See Workforce as' from the profile circle dropdown, which is useful for testing permission changes. The native Admin role cannot be customised.
Manager
Managers can manage the schedules, timesheets and leave for the teams they are a Manager Of. To select which teams a manager is responsible for, first set the permission level, then navigate to the Teams tab, set the team(s) under Manager Of, and select Update Teams.
Managers cannot edit organisation settings or assign permissions to others.
Go in the Personal Details tab > Permission levels > Manager > Update Employee Details:
Then navigate to the Teams tab, set the team(s) in Manager of and select Update Teams:
General Manager
General Managers have org-wide operational access. They can manage rosters, timesheets, wages, locations, department groups, and contracts across the entire organisation. General Managers can also lock rosters and export timesheets.
General Managers cannot manage permissions, payroll groups, ATS, organisation settings, position templates, or access sensitive employee data. They also cannot use the 'See Workforce as' impersonation feature.
Note: A General Manager can also hold the Manager role simultaneously, which allows them to be assigned as a manager of specific teams in addition to their org-wide access. The General Manager role alone does not include team manager assignment.
Payroll Officer
Payroll Officers have access to payroll-related functions including exporting timesheets and managing pay-related data. They cannot access organisation settings or assign permissions to others.
Employee
The Employee permission gives the ability to record worked hours, submit leave applications and be scheduled in Workforce. This is the permission required for anyone who uses Workforce for their own employment. Employees are allocated to teams they work in — this determines where they can be scheduled and which managers can manage them.
To select which teams an employee works in, set the permission level to Employee in Personal Details.
Then navigate to the Teams tab, set the team(s) under Add a Team, and select Update Teams.
Admins, General Managers, or Managers who also use Workforce for their own employment will need the Employee permission level assigned in addition to their other permission level.
The below table is a summary of the main differences between the permission levels:
| Admin | General Manager | Payroll Officer | Manager | Employee |
Can have own timesheets* | ❌ | ❌ | ❌ | ❌ | ✅ |
Can be scheduled* | ❌ | ❌ | ❌ | ❌ | ✅ |
Edit organisation settings | ✅ | ❌ | ❌ | ❌ | ❌ |
Assign user permissions | ✅ | ❌ | ❌ | ❌ | ❌ |
Edit schedule | ✅ | ✅ | ✅ | ✅ | ❌ |
Approve leave | ✅ | ✅ | ✅ | ✅ | ❌ |
Approve timesheets | ✅ | ✅ | ✅ | ✅ | ❌ |
Edit wages | ✅ | ✅ | ✅ | ❌ | ❌ |
Manage locations | ✅ | ✅ | ❌ | ❌ | ❌ |
Impersonate staff ('See Workforce as') | ✅ | ❌ | ❌ | ❌ | ❌ |
Customise default permission levels
What each permission level can do can be customized under Settings > Permissions. Examples of actions you can restrict include:
The ability to see costs
The ability to approve leave
The ability to edit or approve timesheets
The ability to see the full schedule or leave calendar for a team or location
The ability to enter time off
Additionally, you can configure visibility settings for schedules and rotas. For example, you can allow employees to view schedules beyond their immediate team or enable managers to access rotas for multiple teams.
Advanced permissions customisation
You can create and edit permission levels. To see how, refer to the Customise Roles & Permission Levels (Advanced Permissions) guide.
Grant account access
New staff gain access to Workforce via an invitation email. If the blue 'Invite to Workforce' button is visible on the employee profile, that means this employee has not yet been sent an invitation to join the account.
Remove account access
Account access is removed by deactivating the employee profile, or by clicking 'Unlink Workforce profile' under the email field on the profile.
Best practices for managing security and privacy
Consider who has visibility of employment records and match those people to the correct permission level.
Test the impact of permission changes by having an admin use 'See Workforce as' in the profile circle dropdown to confirm what a role can see and do.
When any permissions are added or removed, an audit trail is recorded on the employee profile showing when the change was made and who made it.
Regularly review and update permissions to ensure they align with organisational needs and employee roles.
Communicate changes to employees and managers to avoid confusion.
Test visibility settings before rolling out changes to confirm they work as intended.
FAQs and Troubleshooting
Can a manager change a default team?
Can a manager change a default team?
No, managers don’t have access to permission settings. Only admins can update permission levels.






