This article explains the Employee profile and Employment details permission groups and the access that each one controls. Use it as a reference when you set up or update permissions in your account.
Employee profile
This permission group controls access to each of the subsections in the Personal Information tab of the employee profile, like Public profile and HR information. Every subsection you create appears in this group as its own permission. For each one, you set the following:
- Access level: what role members can do in that subsection.
- Access scope: which employee profiles they can do it for, like their own profile, their direct reports, a custom group, or all employees.
Access levels control the following:
- View: role members can see the subsection within the Personal information tab and the attributes it contains.
- Propose: role members can submit changes to attributes within that subsection for approval. The proposed changes stay pending until a supervisor or another employee approves them, based on the defined approval process. If no approval process applies, the changes are saved immediately.
- Edit: role members can change attributes in that subsection directly, with no approval needed.
Public profile
This permission controls access to the Personal Information tab of employee profiles, which includes the visibility of an employee’s profile picture, last login date, email invite status, and any other attributes that section contains.
With this permission, users can also find Active employees in Personio through the People list, search bar, and Org chart. Be aware of the following dependencies:
- To see and access other employees in the People list, users need a minimum of View access to at least one profile section. Without it, the People list appears empty.
- To see other employees in the Org chart, users need a minimum of View access for the Public profile permission. Without it, the Org chart appears empty, regardless of their access to other profile sections.
- To see employees with a status other than Active, like Onboarding, Leave, or Inactive, users need View access to the profile section that contains the Status attribute.
- The attributes a user has access to determines what they see in the About tab.
Tip: Because so many people need this permission, only store non-sensitive details in the Public profile section like preferred name, position, workplace, department, and supervisor.
HR Information
This permission controls access to the HR Information subsection and the attributes it contains. This section usually includes details like Gender, Employee ID, Cost center. The exact attributes in this section depend on how your organization has configured the employee profile.
Custom section
Each custom profile section you create in Personal information settings appears as a separate permission under the Employee profile permission group. You set the access level and scope for each one.
Employment details
This permission group controls access to employee data and configuration options.
Employee history overview
This permission controls access to the History tab in the employee profile, which shows a record of all data changes made to an employee's attributes. For example, changes related to Salary, Position, Department, etc. To see a detailed view of the changes, users need access to the Employee history - Details permission.
Employee history - Details
This permission controls access to the Detail view in the History tab. Users must also have access to the Employee history overview permission. Depending on access level, they can:
| View | Edit |
|
|
Employee notes
This permission controls access to the Notes tab in the employee profile. Depending on access level, they can:
| View | Edit |
| See the Notes tab in an employee’s profile and all notes in it. | See the Notes tab in an employee’s profile and add and delete notes in it. |
Job families
This permission controls access to see the job family, if configured, next to the Job Name attribute in an employee's profile.
To edit a job family through an employee profile, users need:
- Edit access to the profile section containing the Job Name attribute.
- Minimum of view access to Job Architecture & Catalog.
Job tracks
This permission controls access to see the job track, if configured, next to the Job Name attribute in an employee's profile.
To edit a job track through an employee profile, users need:
- Edit access to the profile section containing the Job Name attribute.
- Minimum of view access to Job Architecture & Catalog.
Job levels
This permission controls access to see the job level, if configured, next to the Job Name attribute in an employee's profile.
To edit a job level through an employee profile, users need:
- Edit access to the profile section containing the Job Name attribute.
- Minimum of view access to Job Architecture & Catalog.
Start/end dates visibility
This permission controls access to the iCal export link for employee Start/end dates. When enabled, users can sync employee start and end dates with their Google or Outlook calendars.
Note: To view these dates in an employee profile, users must have view access to the profile section containing the Hire Date and Termination Date attributes. To restrict access to only one of these dates, place them in separate profile sections with different view permissions.
Birthday visibility
This permission controls visibility of employee birthdays.
When enabled, users can see their colleagues' birthdays on the dashboard. They also need minimum view access for the profile section containing the Date of birth attribute. Users can also subscribe to the iCal calendar export for birthdays of employees.
On-/Offboarding
This permission controls access to the Onboarding and Offboarding tab in the employee profile. By default, employees can see and complete their own tasks. Depending on the access level assigned, they can:
| View | Edit |
| See all the on/offboarding steps from the on/offboarding template and send emails. | Assign, edit, and delete on/offboarding steps from the template. |
- To see employees who are still onboarding before their hire date, a role needs view access to the profile section containing the Status attribute.
- Assigning someone an onboarding or offboarding step gives anyone with access to the Onboarding and Offboarding tab limited extra access: they can view or update the data tied to that step and open the profile header of the employee they're helping, even when their usual permissions wouldn't allow it.
Assigning roles to employees
This permission controls access to assign roles. With edit access, users can add and remove roles in the Roles tab of individual employee profiles, except for the Admin role.
Note: The Administrator role can only be provisioned by other admins. Adding or removing roles in bulk through the People list is only available to Administrators.
Create employee profile or rehire
This permission controls access to create or rehire employees.
When enabled, users can create a new employee profile using the Add employee option in the People list or the Rehire this person option on inactive, terminated profiles
Delete employee profile
This permission controls access to permanently delete an employee profile and all related data like time off periods, documents and employee data history.
Import - Employee data import
This permission controls access to Import employee data into Personio. To import employee data, users also need:
- Edit access for the relevant employee profile sections for the employees they need to import data for.
- Edit access for the add new employees permission, if they want to create new employees via import.
Learn more about import permissions.
People list & org chart (export)
This permission controls the ability to export data from the People list and Org chart.
Role members can only export data they have access to.
View Archived Attributes
This permission controls access to view attributes that have been archived in the Personal Information tab. Users can only see archived attributes that we in profile sections they have access to view.