Overview
RBAC (Role-Based Access Control) manages who can perform which actions on which employees. With Employee-Based Privilege Scoping (RBAC V1), selected employee-level permissions can be restricted to specific employee groups (location, entity, business unit, department, etc.), enabling local HR teams to work independently while maintaining secure access.
What Problem Does It Solve?
Previously, many HR permissions were available only to Global Admins, causing:
- Dependency on Global Admins
- Delays in routine tasks
- Operational bottlenecks
RBAC Scoping helps by:
- Enabling independent HR operations
- Restricting access to employees within assigned scope
- Following least-privilege access principles
What's Included in RBAC V1?
Only Emp-ID–based permissions are scoped.
Modules Covered
- Data Imports
- Employee Profile Actions
- Login
- Documents
- Private Profiles
How RBAC Scoping Works
RBAC Scoping is based on:
- Role → What actions a user can perform
- Scope → Which employees the user can act on
Scoped users can perform actions only for employees within their scope and cannot access out-of-scope employees.
Scoped Permissions
Employee Profile Actions
- Enable/Disable Login
- Manage Mobile App Access
- Send Password Reset Email
- Change Employee Password
- View/Download ID Card
- View Audit
Login
- View Employee Login History
- View Employee Email History
Documents
- Manage Bulk Upload Documents
Private Profiles
- Manage Private Profiles
All permissions apply only to employees within the user's assigned scope.
Important Notes
- Only Emp-ID–based permissions are scoped in V1
- System and configuration-level permissions remain Global (Phase 2)
- Existing permission eligibility rules remain unchanged
- Supports AND/OR scoping logic
- Ensures organisational data isolation
- Follows the least-privilege principle
Example
Without RBAC Scoping, HR managers must rely on Global Admins to reset passwords, manage access, and update employee details.
With RBAC Scoping, HR managers can perform these actions for employees within their own location or business unit, but cannot view or modify employees outside their assigned scope. This enables secure and independent local HR operations.
Comments
0 comments
Please sign in to leave a comment.