This article explains how to create an employee role, configure its permissions, and assign employees to it. Roles and permissions are closely linked in Personio. You can't grant permissions directly to individuals and need to manage what people can access through employee roles.
Before you start
- To set up employee roles and permissions, you need an Administrator role.
- If you're new to roles and permissions, read the Overview of permissions and employee roles article first. It explains the key concepts you need before setting up roles and permissions in Personio.
Create a new employee role and set permissions
To set up permissions for a new employee role, follow these steps:
- Go to Settings.
- In the People section, click Roles & permissions.
- Click Create role.
- Enter a role name and add an optional description.
- Configure the permissions for members in this role:
- Expand each group to select the level of access role members should have for each permission. Then, select the scope of employees this access applies to.
- Optionally, select the checkbox next to multiple permissions to bulk apply access for those permissions.
- Click Next to continue to the assignment step.
In the Assignees tab, you can review the permissions granted to an employee across all their assigned roles.
Assign individual people to an employee role
Once you create a new employee role, you can select individual people you want to assign to it. This always includes them in the role, regardless of any condition-based rules you also set up. Follow these steps:
- Go to the Add people tab.
- Under Select members, search for and select the employees from the dropdown. You can select multiple people at once.
- The people you choose appear under People always included.
- Check the Members tab in the Preview panel to confirm you've added the correct people.
- Save the changes.
Assign multiple employees to an employee role based on attributes
Instead of manually adding individual employees to a role, you can set up rules to automatically assign them based on attributes. For example, you can create a rule to add everyone to a role when they belong to a specific department or location.
Personio automatically adds anyone who matches the conditions to the role. This includes new employees who join later and match the same rule.
How rules work:
- Attribute types: You can create rules using predefined attributes or custom attributes with a single selection, date, or number type.
- One rule per attribute: You can only create one rule for each attribute type, like Department, but you can select multiple values within that rule.
-
Multiple values in one rule: If you select multiple values for a single attribute, Personio adds all employees who match any of those selections.
For example, if you select the departments HR and IT, Personio adds all employees who belong to the HR department and everyone in the IT department. -
Multiple distinct rules: When you add multiple rules across different attributes, Personio only includes employees who match all of them.
For example, if you add the rules "Department is HR" and "Workplace is London", Personio only adds employees who work in the HR department and are based in London. - Combined rules and values: If any of the rules have multiple values selected, employees must meet the criteria for every rule. For example, if you add the rules "Department is HR or IT" and "Workplace is London", Personio adds employees based in London who work in either HR or IT.
To automatically add employees to a role based on conditions, follow these steps:
- Go to the Add people tab.
- Under People added based on conditions, click + Add rule.
- Choose an attribute from the dropdown and set the criteria. For example, Workplace contains London. You can only set one rule per attribute. If you select multiple values for one attribute, Personio adds employees who match any of those options.
- Check the Members tab in the Preview panel to confirm you've added the correct people.
- Optionally, exclude specific people from the role who otherwise match the rules.
- Save the changes.
Note: If you set a rule using the "does not contain" option, for example, "Department does not contain Sales," this also adds employees with no value assigned for that attribute, not just those in other departments.
More information
To add, exclude, or remove people from an existing role, or to delete a role, see Manage employee roles and permissions. Or, see how to Review and compare employee roles and permissions.