Skip to content
All guides

Getting Started · Updated September 5, 2026

Roles & Permissions

Check the permissions attached to a company role and understand why a screen or action is available.

Inspect your company roles

Open Company Settings / Roles & Permissions (/permissions). Access requires manage_role. The page lists company roles and a searchable Role / Permission Matrix loaded from the server.

This page is read-only. It does not create roles, edit grants, or assign users. Use the account controls on an employee profile to choose a role while creating an account. See Company Setup & User Management for account setup.

Default roles

New companies receive these seven role definitions. The matrix shows your company's actual grants; role names are display labels and may differ from the defaults.

RoleDefault focus
AdminAll tenant permissions; excludes platform-only administration
HR ManagerEmployee management, payroll, leave, attendance, recruiting, performance, benefits, expenses and compliance
Finance ManagerPayroll, compensation, benefits, expenses, salary advances, compliance and integrations; employee records are read-only
Department ManagerTeam operations, including employee, leave, attendance, scheduling, performance and expense management
RecruiterRecruiting management and access to supporting records
Compliance OfficerCompliance and document management, audit access and company-wide performance visibility
EmployeeOwn profile and payslips, leave requests, clocking, shifts, reviews, benefits, expenses, documents and published policies

Access is determined by grants and record scope, not a role's name. A tenant Admin is different from a platform administrator: platform access is an account-level flag used for Arche's operator surfaces.

Read, manage, and self-service permissions

Names describe an action and resource, such as view_employees, manage_employees, or view_own_payslip. They are separate grants; do not assume every manage_ grant includes every read or approval action.

Useful distinctions:

  • manage_payroll and approve_payroll are separate payroll permissions.
  • manage_leave enables leave operations; manage_leave_config controls policy configuration.
  • manage_attendance and manage_attendance_config separate attendance operations from configuration.
  • manage_salary_advance and disburse_salary_advance separate approval from payment.
  • manage_expenses provides scoped expense approval; approve_all_expenses adds company-wide approval authority.
  • view_performance does not itself grant company-wide visibility. That requires view_all_performance or platform-admin access.
  • view_documents, view_benefits, and view_expenses are also used by Employee self-service. A view_ prefix does not universally mean access to everybody's records.

Why a page or action is unavailable

Check these separately:

  1. Current company. Your company selection determines which membership and records you are using.
  2. Licensed module. Feature access also depends on the company's module licence.
  3. Permission. Inspect the relevant grant in the role matrix.
  4. Record scope and state. An approver may need to be assigned to the current step; a team manager may be limited to direct reports; completed records may reject edits.

The UI filters navigation and actions. The backend checks permissions and any applicable ownership, team, and lifecycle conditions again when a request is made. A visible button does not bypass those checks.

Web and mobile use shared permission names, but their available screens and controls differ. Use each surface's actual navigation rather than assuming every web action has a mobile equivalent.