Overview
RBAC (Role-Based Access Control) manages who can perform which actions on which employees. With Employee-Based Privilege Scoping, permissions can be restricted to specific employee groups (Legal Entity, Location, Business Unit, Department, etc.), enabling local HR teams to work independently while maintaining secure access.
RBAC now supports both:
- Employee-level permissions
- Selected Core HR configuration permissions
This allows scoped HR admins to manage employees and supported HR configurations within their assigned scope.
Additionally, certain country-specific configurations now follow Legal Entity-based access, allowing Legal-Entity-scoped admins to manage configurations for the countries mapped to their legal entities.
What Problem Does It Solve?
Previously, many HR permissions and configuration settings were available only to Global Admins, causing:
- Dependency on Global Admins
- Delays in routine tasks
- Operational bottlenecks
For country-specific configurations such as Employee Profile Layout and Identity Document Configuration, separate configurations already existed for each country. However, even country-specific HR teams could not manage their own country's configuration.
For example, an HR admin scoped to the India Legal Entity had to depend on a Global Admin to configure India's employee profile fields or identity requirements.
RBAC Scoping helps by:
- Enabling independent HR operations
- Restricting access to employees within assigned scope
- Restricting configuration access to authorised employee groups
- Following least-privilege access principles
How RBAC Scoping Works
RBAC Scoping is based on:
- Role → What actions a user can perform
- Scope → Which employees or configurations the user can access
Scoped users can perform actions only within their assigned scope and cannot access employees or configurations outside it.
For country-specific configurations, access is derived from the existing Legal Entity → Country mapping configured in the organisation structure.
For example:
- A user scoped to the India Legal Entity can access India-specific configurations.
- A user scoped to US and UK Legal Entities can access both US and UK configurations.
- A Global Admin retains access to all configurations.
What's Included in RBAC?
Employee-Level Permissions
Employee Profile Actions
- Enable/Disable Login
- Manage Mobile App Access
- Send Password Reset Email
- Change Employee Password
- View/Download ID Card
- View Audit
Login
- View Employee Login History
- View Employee Email History
Documents
- Manage Bulk Upload Documents
Private Profiles
- Manage Private Profiles
Configuration-Level Permissions
Scoped HR admins can manage the following configurations within their assigned scope.
Exit
- Notice Period Policies
- Exit Surveys
- Exit Task Templates
- Exit Task Lists
Onboarding
- Onboarding Task Templates
Employee Settings
Country-Specific Configurations
- Customize Employee Profile Fields
- Manage Identities Configuration
These permissions are available only to users with Legal Entity-scoped access. Users can view and edit configurations only for countries mapped to their assigned legal entities.
Non-Country Configurations
- Manage Job Titles
- Manage Employee Settings
- Manage Employee Timeline
Probation
- Probation Policies
- Probation Feedback Forms
Documents
- Employee Document Definitions
- Organisation Document Folders
- Organisation Documents
Document Template Scoping
Users with scoped HR permissions can create, view, and manage document template scopes only for the legal entities included in their assigned scope. Legal entities outside their scope are not available for selection or modification.
Permission Rules
The following permissions are restricted to Legal Entity-scoped roles:
- Customize Employee Profile Fields
- Manage Identities Configuration
- Manage Job Titles
- Manage Employee Timeline
- Manage Employee Settings
Users scoped only through Business Unit, Location, Department, or other dimensions cannot be assigned these permissions.
Access to country-specific configurations is automatically determined using the existing Legal Entity → Country mapping.
Important Notes
Country-Specific Configurations
For Customize Employee Profile Fields and Manage Identities Configuration:
- Admins can view and edit only countries mapped to their legal entities.
- Countries outside their scope are hidden.
- If multiple legal entities map to the same country, admins scoped to either entity can manage that country's configuration.
- Global Admins can access all country configurations, including countries not mapped to any scoped role.
Organisation-Wide Settings
The following settings remain common across all legal entities. Changes made by a scoped admin affect the entire organisation:
- Resignation Settings
- Termination Settings
- Background Verification (BGV) Settings
- Form I-9 Settings
- Employee Timeline Settings
- Employees → Settings
Probation Policy Limitation
A scoped admin can edit a probation policy only when their scope fully covers the policy assignment.
Policies with partial overlap remain hidden.
Document Configuration
When creating document folders, document definitions, or document template scopes, the Legal Entity selector displays only the admin's assigned legal entities.
Example
Without RBAC Scoping, regional HR teams must rely on Global Admins to configure employee profile fields, identity documents, onboarding tasks, probation policies, document definitions, exit settings, and employee access controls.
With RBAC Scoping:
- An India HR admin can manage India's employee profile layout and identity document requirements.
- A UAE HR admin can configure UAE-specific employee settings.
- A Canada HR admin can manage onboarding and exit configurations for Canada employees.
Each admin can access only the configurations mapped to their scope, while Global Admins continue to have unrestricted access.
RBAC Support Across Engage Module
RBAC Scoping is not limited to Core HR. Similar scope-based permissions are also available across other Keka modules.
Scoped admins can now manage:
- Announcements
- Polls
- Surveys
- Rewards
Access is restricted to employees within their assigned scope, while Global Admins continue to have organisation-wide access.
Frequently Asked Questions
Can scoped HR admins access employees outside their scope?
No. Access is restricted to employees within the assigned scope.
Can scoped HR admins manage onboarding tasks?
Yes. They can create and manage onboarding task templates within their scope.
Can scoped HR admins manage probation policies?
Yes, provided their scope fully covers the policy assignment.
Can scoped HR admins customise employee profile fields?
Yes. Legal-Entity-scoped admins can configure profile fields for countries mapped to their legal entities.
Can scoped HR admins manage identity document configurations?
Yes. Legal-Entity-scoped admins can manage identity document requirements only for countries mapped to their legal entities.
Can a user scoped only by Location or Business Unit manage country-specific configurations?
No. These permissions require Legal Entity scope.
Do Global Admins lose any access?
No. Global Admins continue to have unrestricted access across all employees and configurations.
What happens if two legal entities belong to the same country?
Admins scoped to either legal entity can access that country's configuration.
Comments
0 comments
Please sign in to leave a comment.