This article provides recommended permission settings for common employee roles in Personio. It includes the preset role All Employees, as well as examples of custom roles such as "Working Students", "HR Manager", "Finance", and "Recruiter".
Only users with the Administrator role can set up permissions and employee roles. For a list of actions exclusive to the Administrator role, see access rights for Administrators.
Tip:
If you're new to setting up employee roles and permissions, start by reading the Overview of permissions and employee roles article. It covers the basics of permissions and how employee roles function.
All Employees
The All Employees role is a preset role that includes every employee. As a best practice, it has limited permissions. Employees can view their own data. They also have propose rights in specific sections. The propose rights include uploading medical certificates in case of illness.
Personal data
| Access Area | View | Propose | Edit | |
|---|---|---|---|---|
|
Public profile |
Own | |||
| My reports | ||||
| Custom | ||||
| All | ||||
|
HR information |
Own | |||
| My reports | ||||
| Custom | ||||
| All | ||||
|
Payroll information |
Own | |||
| My reports | ||||
| Custom | ||||
| All | ||||
Bank details |
Own | |||
| My reports | ||||
| Custom | ||||
| All | ||||
|
Emergency contact |
Own | |||
| My reports | ||||
| Custom | ||||
| All | ||||
|
Personal data |
Own | |||
| My reports | ||||
|
Custom |
||||
| All |
Salary information
| Access Area | View | Propose | Edit | |
|---|---|---|---|---|
|
Salary information |
Own | |||
| My reports | ||||
|
Custom |
||||
| All |
Attendance data
| Access Area | View | Propose | Edit | |
|---|---|---|---|---|
|
Attendance data |
Own | |||
| My reports | ||||
|
Custom |
||||
| All |
Documents
| Access Area | View | Propose | Edit | |
|---|---|---|---|---|
| Work contracts | Own | |||
| My reports | ||||
|
Custom |
||||
| All | ||||
| Time off certificates | Own | |||
| My reports | ||||
|
Custom |
||||
| All | ||||
| Application documents | Own | |||
| My reports | ||||
|
Custom |
||||
| All | ||||
Payroll |
Own | |||
| My reports | ||||
|
Custom |
||||
| All | ||||
| Other Documents | Own | |||
| My reports | ||||
|
Custom |
||||
| All | ||||
|
Performance |
Own | |||
| My reports | ||||
|
Custom |
||||
| All |
Performance & Development
Employees don't need specific permissions to give or receive feedback or to participate in review cycles.
| Access Area | View | Propose | Edit | |
|---|---|---|---|---|
|
Continuous Feedback and Performance Notes
|
Custom |
|||
| All | ||||
| Cycles and Cycle Reviews | Own |
|||
Custom |
||||
All |
||||
| Goals | Custom |
|||
All |
Manage accounts
| Access Area | View | Propose | Edit | |
|---|---|---|---|---|
|
Manage accounts |
Own | |||
| My reports | ||||
|
Custom |
||||
| All | ||||
|
Reset password |
Own | |||
| My reports | ||||
| Custom | ||||
| All |
Time off
| Access Area | View | Propose | Edit | |
|---|---|---|---|---|
| Paid Vacation | Own |
|
||
| My reports | ||||
|
Custom |
||||
| All | ||||
| Sickness | Own | |||
| My reports | ||||
|
Custom |
||||
| All | ||||
| Parental Leave | Own | |||
| My reports | ||||
|
Custom |
||||
| All | ||||
Maternity Leave |
Own | |||
| My reports | ||||
|
Custom |
||||
| All | ||||
| Home Workplace | Own | |||
| My reports | ||||
|
Custom |
||||
| All |
Employee history
| Access Area | View | Propose | Edit | |
|---|---|---|---|---|
|
Overview |
Own | |||
| My reports | ||||
|
Custom |
||||
| All | ||||
|
Detailed View |
Own | |||
| My reports | ||||
|
Custom |
||||
| All |
Org Chart
| Access Area | View | Propose | Edit | |
|---|---|---|---|---|
|
Org Chart |
All |
Working Students
The "Working Students" role is a custom role that uses the All Employees role as a basis. It also includes edit rights for study-related documents, such as enrollment certificates. With these rights, they can upload these documents themselves.
This roles has propose rights for attendance data so users can enter their daily working hours in Personio. You can also add an approval process requiring the supervisor to confirm the hours. Learn more about how to set up an approval process.
Documents
| Access Area | View | Propose | Edit | |
|---|---|---|---|---|
|
Study documents |
Own | |||
| My reports | ||||
|
Custom |
||||
| All |
Attendance data
| Access Area | View | Propose | Edit | |
|---|---|---|---|---|
|
Attendance data |
Own | |||
| My reports | ||||
|
Custom |
||||
| All |
HR Manager
The "HR Manager" role is a custom role with similar rights to the Administrator. The key difference relates to salary information. In this best practice, a filter prevents HR managers from viewing or editing their colleagues' salaries in the HR department. To set up a filter like this:
- Create the attributes "Department" and "HR"
- Customize the filter using "Department" is not "HR"
The "HR Manager" role also has edit rights for HR documents.
Salary information
| Access Area | View | Propose | Edit | |
|---|---|---|---|---|
|
Salary information |
Own | |||
| My reports | ||||
|
Custom |
||||
| All |
To ensure salary data isn't visible during onboarding, use these recommended settings. These settings prevent the visibility of attributes that contain salary data. Example attributes include:
- "Fixed Salary"
- "Hourly Salary"
- "Recurring Compensations"
| Access Area | View | Propose | Edit | |
|---|---|---|---|---|
|
Onboarding |
Own | |||
| My reports | ||||
|
Custom |
||||
| All |
Documents
| Access Area | View | Propose | Edit | |
|---|---|---|---|---|
| Work contracts | Own | |||
| My reports | ||||
|
Custom |
||||
| All | ||||
| Time off certificates | Own | |||
| My reports | ||||
|
Custom |
||||
| All | ||||
| Application documents | Own | |||
| My reports | ||||
|
Custom |
||||
| All | ||||
Payroll |
Own | |||
| My reports | ||||
|
Custom |
||||
| All | ||||
| Other Documents | Own | |||
| My reports | ||||
|
Custom |
||||
| All | ||||
|
Performance |
Own | |||
| My reports | ||||
|
Custom |
||||
| All |
Finance
The "Finance" role is a custom role with permissions for payroll accounting and salary reports. Employees in this role have access to salary data for all employees.
Salary information
| Access Area | View | Propose | Edit | |
|---|---|---|---|---|
|
Salary information |
Own | |||
| My reports | ||||
|
Custom |
||||
| All |
Documents
| Access Area | View | Propose | Edit | |
|---|---|---|---|---|
|
Payroll |
Own | |||
| My reports | ||||
|
Custom |
||||
| All |
Reporting
| Access Area | View | Propose | Edit | |
|---|---|---|---|---|
| Salary | Custom | |||
| All |
Account configuration
| Access Area | View | Propose | Edit | |
|---|---|---|---|---|
|
Cost centers |
All | |||
| Payroll | All |
Imports
| Access Area | View | Propose | Edit | |
|---|---|---|---|---|
|
Document Import |
All |
Recruiter
The "Recruiter" role is a custom role with all the permissions necessary for the application pipeline. Learn more about recruiting role permissions.
Documents
| Access Area | View | Propose | Edit | |
|---|---|---|---|---|
|
Application documents |
Own | |||
| My reports | ||||
|
Custom |
||||
| All | ||||
|
Recruiting email attachments |
Own | |||
| My reports | ||||
|
Custom |
||||
| All |
Reporting
| Access Area | View | Propose | Edit | |
|---|---|---|---|---|
| Headcount | Custom | |||
| All | ||||
| Hires | Custom | |||
| All | ||||
| Applications | All | |||
Channels |
Custom | |||
| All | ||||
| Application Funnel | All | |||
| Rejected Applicants | All |
Recruiting
| Access Area | View | Propose | Edit | |
|---|---|---|---|---|
|
Recruiting |
All |
Combinations to avoid
While the roles above work individually, you need to prevent overlapping roles and permissions. This section describes permission combinations to avoid so your safeguards don't get overridden elsewhere.
When an employee has multiple roles, Personio applies the most permissive setting from any role to each data area. One role's safeguard—like a filter—can get overridden by another role the same person holds.
Avoid these combinations
- Edit and All access on sensitive financial data (such as salary, bank details, and payroll) with no approval step. With this combination, one person can change anyone's pay without a second reviewer. Instead, use View, not Edit, for broad visibility, and route changes through Propose with an approval process.
| Access Area | View | Propose | Edit | |
|---|---|---|---|---|
| Salary / Bank details / Payroll | All |
with approval process |
⚠️ avoid |
- Account management (Manage accounts and Reset password) and rights to edit sensitive financial data (for example, payroll data). Combined, one role can both take over an account and redirect its payout details. Keep these apart.
| Access Area | View | Propose | Edit | |
|---|---|---|---|---|
| Manage accounts / Reset password | All | ⚠️ avoid if also holding Edit on pay data |
Other combinations to avoid
- A filtered role and an unfiltered role over the same data. If a person holds a role with a department filter (for example, an HR Manager role that hides HR's own salaries) and also holds a role with View or Edit access to All salary data (for example, Finance or Administrator), the unfiltered role overrides the filter.
- Propose rights with no approval process set up. If you grant Propose rights without setting up an approver, submissions stay unreviewed. Only grant Propose rights after you configure an approver.
- All access areas on temporary roles. Working students, interns, and contractors should use Own or a narrow Custom filter as their scope. Don't grant them All access.
- Recruiter access combined with HR document edit access on the same person. If one person holds both, this removes the boundary between the hiring pipeline and post-hire HR and payroll records.