Skip to main content

Role-Permission Matrix

This matrix summarizes the base permissions for each role. Note that SUPER_ADMIN is exempt from most ABAC rules (like Company Boundaries).

Resource / ActionSUPER_ADMINADMINHRMANAGEREMPLOYEE
Companies (Global)FullNoNoNoNo
System SettingsFullNoNoNoNo
Company Data (Own)FullFullReadReadRead
DepartmentsFullFullFullRead/Update [1]No
Users (Employee)FullFullFullOwn DeptNo
Users (HR)FullFullRead [2]NoNo
Users (ADMIN)FullFullReadNoNo
InvitesFullFullFullNoNo

Notes:

  • [1] Manager Scope: Limited to their own department.
  • [2] HR Rule: Cannot modify other HR members (Horizontal blocking).
  • SUPER_ADMIN always sees all data across all companies.