This article explains the permissions in the Employee profile and Employment details permission groups and what each access level provides. Use it as a reference when you set up or update permissions in your account.
Every profile section you create appears in this group as its own permission. For each section, you set the following:
- Access level: what role members can do in that profile section
- Access scope: which employee profiles they can do it for, like their own profile, their direct reports, or all employees.
Access levels control the following:
- View: role members can see the profile section,the attributes and the assigned values inside it.
- Propose: role members can submit changes to the section's attributes for approval. The changes stay pending until a supervisor or another employee approves them, based on the defined approval process. If no approval process applies, the changes are saved immediately.
- Edit: role members can change attributes in that section directly, with no approval needed.
Employee profile
This permission group controls access to the profile sections in the Personal Information tab of the employee profile, such as Public profile and HR information.
Public profile
Employees need this permission to find Active employees across Personio, including the People List, search bar, and Org chart. Without it, the Org Chart appears empty, even if the employee has access to other sections.
Because so many people need this permission, store only non-sensitive details in the Public profile section, like preferred name, position, workplace, department, and supervisor.
Keep these points in mind:
- With view access, a user can find and access active employees by default throughout the system, like the People List or their profile.
- To also see employees with an Onboarding, Leave, or Inactive status, the role member needs view access to the section containing the Status attribute.
- To see other employees in the People List, the role member needs view access to at least one profile section. Without it, they can’t see anyone.
HR Information
This permission controls access to the HR Information section and its attributes. This section usually includes details like Gender, Employee ID, Cost center. The exact attributes in this section depend on how your organization has configured the employee profile.
Custom section
Each custom profile section you create in Personal information settings appears as a separate permission under the Employee profile permission group. You set the access level and scope for each one, using the same view, propose, and edit levels described above.
Employment details
This permission group controls access to employee data and configuration options.
Employee history
| Controls access to | Considerations |
| The History tab in the employee profile. |
Employee history - Details
| Controls access to | Considerations |
|
The detail view in the History tab. Depending on access level, they can:
|
Employees can see and edit the date of an attribute change if you grant them Edit access. |
Employee notes
The Notes tab in the employee profile. Depending on access level, they can:
- View: see the Notes tab and all notes in it.
- Edit: see the Notes tab, and add and delete notes in it.
Job families
See the job family, if configured, included next to the Job Name in an employee's profile.
To edit a job family through an employee profile, users need:
- Edit access to the profile section containing the attribute Job Name.
- Minimum of view access to Job Architecture & Catalog.
Job tracks
See the job track, if configured, included next to the Job Name in an employee's profile.
To edit a job track through an employee profile, users need:
- Edit access to the profile section containing the attribute Job Name.
- Minimum of view access to Job Architecture & Catalog.
Job levels
See the job level, if configured, included next to the Job Name in an employee's profile.
To edit a job level through an employee profile, users need:
- Edit access to the profile section containing the attribute Job Name.
- Minimum of view access to Job Architecture & Catalog.
Start/end dates visibility
This permission controls visibility of employee start and end dates.
If enabled, a user can see work anniversaries of their colleagues on the dashboard, if they additionally have view permissions for the profile section holding the hire date attribute. Users can also subscribe to the iCal calendar export for start and employment end dates of employees.
Birthday visibility
This permission controls visibility of employee birthdays.
If enabled, a user can see birthdays of their colleagues on the dashboard, if they additionally have view permissions for the profile section holding the date of birth attribute. Users can also subscribe to the iCal calendar export for birthdays of employees.
On-/Offboarding
This permission controls access to the Onboarding and Offboarding tab in the employee profile. By default, employees can see and complete their own tasks. Depending on the access level assigned, they can:
- View: see all the steps from the on/offboarding template and send emails.
- Edit: have all view capabilities and also assign templates, create tasks, and mark steps as completed.
Considerations:
- By default, employees can see and complete their own tasks. Only users with edit rights can change a step's status directly in the tab.
- To see employees who are still onboarding before their hire date, a role needs view rights to the section holding the Status attribute.
- Assigning someone an onboarding or offboarding step gives them limited extra access: they can view or update the data tied to their step, and open the profile header of the employee they're helping, even when their usual permissions wouldn't allow it.
Assigning roles to employees
This permission controls access to assign roles. With edit access, users can add and remove roles in the Roles tab of individual employee profiles, except for the Admin role.
Note: The Administrator role can only be provisioned by other admins. Adding or removing roles in bulk through the people list is available to Administrators only.
Create employee profile or rehire
This permission controls access to create or rehire employees. If toggled on, users can create a new employee profile using the Add employee option in the people list or the Rehire this person option on inactive, terminated profiles
Delete employee profile
This permission controls access to permanently delete an employee profile including all related data such as time off periods, documents and employee data history.
Import - Employee data import
This permission controls access to Import employee data into Personio. To import employee data, a user needs:
- Edit access for Import - Employee data in Employment details.
- Edit access for the relevant profile sections in the Employee profile permission group for the employees they want to import data for, like the Public profile section.
- Edit access to add new employees, if they want to create new employees via import.
Learn more about import permissions.
People list & org chart (export)
This permission controls the ability to export data from the People List and Org chart.
Role members can only export data they have access to.
View Archived Attributes
This permission controls access to archived attributes in the Personal Information tab. Users can see an archived attribute only if they have permission to view the section it belongs to.