Overview
RBAC (Role-Based Access Control) manages who can perform which actions on which employees. With Employee-Based Privilege Scoping, permissions can be restricted to specific employee groups (Legal Entity, Location, Business Unit, Department, etc.), enabling local HR teams to work independently while maintaining secure access.
RBAC now supports both:
- Employee-level permissions
- Selected Core HR configuration permissions
This allows scoped HR admins to manage employees and supported HR configurations within their assigned scope.
RBAC Support for Scoped HR Admins: Users with scoped HR permissions can create, view, and manage document template scopes only for the legal entities included in their assigned scope. Legal entities outside their scope are not available for selection or modification.
What Problem Does It Solve?
Previously, many HR permissions and configuration settings were available only to Global Admins, causing:
- Dependency on Global Admins
- Delays in routine tasks
- Operational bottlenecks
RBAC Scoping helps by:
- Enabling independent HR operations
- Restricting access to employees within assigned scope
- Restricting configuration access to authorised employee groups
- Following least-privilege access principles
How RBAC Scoping Works
RBAC Scoping is based on:
- Role → What actions a user can perform
- Scope → Which employees or configurations the user can access
Scoped users can perform actions only within their assigned scope and cannot access employees or configurations outside it.
What's Included in RBAC?
Employee-Level Permissions
Employee Profile Actions
- Enable/Disable Login
- Manage Mobile App Access
- Send Password Reset Email
- Change Employee Password
- View/Download ID Card
- View Audit
Login
- View Employee Login History
- View Employee Email History
Documents
- Manage Bulk Upload Documents
Private Profiles
- Manage Private Profiles
Configuration-Level Permissions
Scoped HR admins can now manage the following configurations within their assigned scope:
Exit
- Notice Period Policies
- Exit Surveys
- Exit Task Templates
- Exit Task Lists
Onboarding
- Onboarding Task Templates
Employee Settings
- Job Titles
- Identity Document Configuration
- Employee Profile Field Customisation
Probation
- Probation Policies
- Probation Feedback Forms
Documents
- Employee Document Definitions
- Organisation Document Folders
- Organisation Documents
Important Notes
Organisation-Wide Settings
The following settings remain common across all legal entities. Any changes made by a scoped admin affect the entire organisation:
- Resignation Settings
- Termination Settings
- Background Verification (BGV) Settings
- Form I-9 Settings
- Employee Timeline Settings
- Employees → Settings
Probation Policy Limitation
A scoped admin can edit a probation policy only when their scope fully covers the policy assignment.
Policies with partial overlap remain hidden.
Country-Specific Configurations
For Identity Documents and Employee Profile Field Customisation:
- Admins can view only country tabs mapped to their legal entities.
- Tabs for other countries remain hidden.
Document Configuration
When creating document folders or definitions, the Legal Entity selector displays only the admin's assigned entities.
Example
Without RBAC Scoping, regional HR teams must rely on Global Admins to configure onboarding tasks, probation policies, document definitions, exit settings, and employee access controls.
With RBAC Scoping, regional HR teams can manage employees and supported Core HR configurations within their own scope while remaining restricted from accessing employees or settings outside their assigned boundary.
Frequently Asked Questions
Can scoped HR admins access employees outside their scope?
No. Access is restricted to employees within the assigned scope.
Can scoped HR admins manage onboarding tasks?
Yes. They can create and manage onboarding task templates within their scope.
Can scoped HR admins manage probation policies?
Yes, provided their scope fully covers the policy assignment.
Can scoped HR admins customise employee profile fields?
Yes. They can configure profile fields only for countries mapped to their legal entities.
Do Global Admins lose any access?
No. Global Admins continue to have unrestricted access.
Comments
0 comments
Please sign in to leave a comment.