This article explains how permissions and employee roles work in Personio. The two are closely linked, as permissions can’t be granted directly to individuals—they’re always managed through employee roles.
Tip:
Already have a specific task in mind and want to know which permissions are needed? Learn how to grant permissions for everyday tasks in Personio.
Access employee roles and permissions
You need an Administrator role to see the Roles and permissions settings. Account Owners, Contract Owners, and Payroll Owners cannot access Roles and permissions unless they also hold the Administrator role.
To access employee roles:
- Go to Settings.
- In the People section, click Roles & permissions.
To access permissions for an employee role:
- Go to Settings.
- In the People section, click Roles & permissions.
- Click an employee role.
- Click the Permissions tab.
Understand how employee roles work
Personio manages permissions through employee roles — you cannot grant them directly to an individual. Personio has two types of employee roles: preset roles and custom roles. Preset roles are built into Personio and link to other system functionality. See the table below for more details.
| Role type | Role name | Who gets added | Access level |
|---|---|---|---|
| Preset role | All employees | This role includes all active employees. Every new employee joins this role automatically. | Basic set of permissions. |
| Preset role | Administrator (or roles with administrator rights) | Personio doesn't add anyone to this role automatically — you manually add and remove members. | Full permissions. You cannot change these permissions. |
| Custom role |
Examples:
|
You manually add employees. Personio doesn't add anyone to this role automatically. | Custom permissions. Personio applies the same permissions as the All Employees role by default, with the option to add more as needed. |
Personio adds all employees to the All employees role by default, and you cannot remove them. This role provides employees with a basic set of permissions.
To grant employee permissions beyond those in the basic All employees role, assign them to an additional role (like "Supervisor") and grant the extra permissions through that role.
Tip:
Add conditions to assign employees to roles automatically, so you don't need to add new employees manually.
Understand how permissions work
Once you add an employee to an additional role (such as “Supervisor”), you can grant them extra access by setting up specific permissions for that role.
Permissions control what information employees can view or change. They are organized by topic, like Attendance, Documents, or Recruiting. There are two types of permissions:
- People: control access to employee data.
- Feature: control access to applications, features, and company settings.
You control access using access levels and scopes:
1. Access levels
Access levels define what actions role members can take. Choose between the following:
| View | Role members can see the data. |
| Propose | Role members can submit changes to the data for approval. The proposed changes stay pending until a supervisor or another employee approves them, based on the defined approval process. If you select this level of permission, you need to configure an approval process. If a user has this permission but no approval process applies to them, the changes save immediately. |
| Edit | Role members can edit the data without needing approval. A warning alerts you when you grant permissions to sensitive data. |
2. Access scopes
Access scopes specify the employees whose information role members can access. It defines which employees the role members can do it for, like their own profile, their direct reports, a custom group, or all employees. specify whose information employees can access.
For example, employees should only see their own salary details but should be able to see time off information for other employees.
There are four access areas in permissions:
| Self | The employee's own data. |
| Reporting line |
The employees who report to the employee. By default, Personio defines reporting lines based on the primary supervisor, which includes both direct and indirect reports. To use an alternative reporting line, such as a dotted-line report, you must select it manually. |
| Custom | A specific selection of employees that you define through filters. |
| All | All employees. |
Note:
The Reporting line, Custom, and All access areas exclude the employee's own data. To grant access to their own data, select the Own access area along with the relevant access area.
More information
Here are some related articles with further information:
- Set up both permissions and employee roles
- Summary of access rights for Administrators
- Grant permissions for everyday tasks in Personio
- Summary of permissions
- Best practices: Employee roles and permissions
- Set up primary and additional supervisors