How it works
- The Company Head opens Access Control in Settings and seeds the default roles, or clicks New role and names it.
- The role editor lists every module with eight tick boxes: view, create, edit, delete, approve, export, finalize and configure.
- Each tick saves at once, and the same screen sets the role's data scope and field masking.
- While enforcement is off, the older per-user matrix still decides access, so roles can be prepared safely.
- Switching enforcement on applies the roles to every user whose login role matches, and switching it off returns everyone to the older matrix.
- System roles cannot be deleted; deleting a custom role returns its users to the older matrix.
What you can set
- Actions per module: view, create, edit, delete, approve, export, finalize, configure.
- Custom roles with your own names, such as Regional Manager.
- Data scope per role: all, branch, department, hierarchy or self.
- Field masking per role for salary, bank and contact: full, masked or hidden.
- Enforcement switch per company, off by default.
- Company Head and Super Admin always have full access.
- Finalizing a Direct Payroll run needs the finalize action once enforcement is on.
Why eight actions instead of three
Real HR teams split work in ways a three-box matrix cannot express. The executive who enters payroll inputs should not be the person who seals the run. An auditor visiting for the statutory audit needs to export registers but must not edit anything. A recruiter may create candidates but should not delete employee records. Separate create, delete, approve, export, finalize and configure actions let each of these be set exactly, without giving someone edit rights they do not need.
Worked example: separating payroll preparation from sign-off
A 300-person pharma distributor in Indore wants two people involved in every payroll. The Company Head reviews the seeded HR role: it has view, create, edit, delete, approve and export on payroll, but not finalize. The Finance role gets finalize ticked on payroll. After enforcement is switched on, the HR executive prepares the October run and moves it to review. The finance manager checks the totals and finalizes it, and the run is sealed and read-only. If the HR executive tries to finalize, ZeniaHR refuses the action with an access denied message.
Practical advice on roles
Roles are easier to maintain when they are few and clear. Every extra role is one more table to review when a module is added or a policy changes, so resist creating a role for each person and group people by what they actually do.
- Start from the seeded roles and change only what your company does differently.
- Give configure only to people who should change settings.
- Keep finalize on payroll with one or two people.
- Review roles whenever someone changes jobs, not once a year.
See role permissions in a demo
We show it on a video call with your own shifts, leave types and rules. Free for your first 50 employees.
Book a free demoSee pricingFrequently asked questions
What are the eight permissions in ZeniaHR access control?
View, create, edit, delete, approve, export, finalize and configure, set separately for each module. Finalize covers actions such as sealing a Direct Payroll run, and configure covers settings. The older matrix had only view, edit and export, which is why it could not separate preparing payroll from finalizing it.
What happens when I switch enforcement off again?
Everyone returns to the older per-user permission matrix at once. The roles, scopes and masking you built stay saved in Access Control, so you can fix what was wrong and switch enforcement back on. The Company Head keeps full access either way.
Can a role approve leave but not see salaries?
Yes. Give the role approve on the leave module and set salary to hidden in its field masking. The ready Manager role works in a similar way: it has attendance and leave rights for its reporting line, while salary and bank details are masked.
Who can manage roles in ZeniaHR?
Access Control belongs to the Company Head, who creates and edits roles, sets scopes and masking, seeds the default roles and turns enforcement on or off. Other users cannot change their own rights, which keeps access decisions with the person who owns the business.