Home › HRMS › Features › Roles and access control › Role permissions
Roles and access control feature

Eight actions per module for every role

A simple view, edit and export matrix cannot say that a payroll executive may prepare a payroll run but not seal it, or that a visiting auditor may export but not change anything. ZeniaHR roles have eight actions per module: view, create, edit, delete, approve, export, finalize and configure. The Company Head ticks them in one table per role, and changes save as they are made. Enforcement is switched on for the whole company when the roles are ready.

How it works

  1. The Company Head opens Access Control in Settings and seeds the default roles, or clicks New role and names it.
  2. The role editor lists every module with eight tick boxes: view, create, edit, delete, approve, export, finalize and configure.
  3. Each tick saves at once, and the same screen sets the role's data scope and field masking.
  4. While enforcement is off, the older per-user matrix still decides access, so roles can be prepared safely.
  5. Switching enforcement on applies the roles to every user whose login role matches, and switching it off returns everyone to the older matrix.
  6. System roles cannot be deleted; deleting a custom role returns its users to the older matrix.

What you can set

Why eight actions instead of three

Real HR teams split work in ways a three-box matrix cannot express. The executive who enters payroll inputs should not be the person who seals the run. An auditor visiting for the statutory audit needs to export registers but must not edit anything. A recruiter may create candidates but should not delete employee records. Separate create, delete, approve, export, finalize and configure actions let each of these be set exactly, without giving someone edit rights they do not need.

Worked example: separating payroll preparation from sign-off

A 300-person pharma distributor in Indore wants two people involved in every payroll. The Company Head reviews the seeded HR role: it has view, create, edit, delete, approve and export on payroll, but not finalize. The Finance role gets finalize ticked on payroll. After enforcement is switched on, the HR executive prepares the October run and moves it to review. The finance manager checks the totals and finalizes it, and the run is sealed and read-only. If the HR executive tries to finalize, ZeniaHR refuses the action with an access denied message.

Practical advice on roles

Roles are easier to maintain when they are few and clear. Every extra role is one more table to review when a module is added or a policy changes, so resist creating a role for each person and group people by what they actually do.

See role permissions in a demo

We show it on a video call with your own shifts, leave types and rules. Free for your first 50 employees.

Book a free demoSee pricing

Frequently asked questions

What are the eight permissions in ZeniaHR access control?

View, create, edit, delete, approve, export, finalize and configure, set separately for each module. Finalize covers actions such as sealing a Direct Payroll run, and configure covers settings. The older matrix had only view, edit and export, which is why it could not separate preparing payroll from finalizing it.

What happens when I switch enforcement off again?

Everyone returns to the older per-user permission matrix at once. The roles, scopes and masking you built stay saved in Access Control, so you can fix what was wrong and switch enforcement back on. The Company Head keeps full access either way.

Can a role approve leave but not see salaries?

Yes. Give the role approve on the leave module and set salary to hidden in its field masking. The ready Manager role works in a similar way: it has attendance and leave rights for its reporting line, while salary and bank details are masked.

Who can manage roles in ZeniaHR?

Access Control belongs to the Company Head, who creates and edits roles, sets scopes and masking, seeds the default roles and turns enforcement on or off. Other users cannot change their own rights, which keeps access decisions with the person who owns the business.