Skip to main content

Permission Groups

Written by StaffAny

Contents of this article are applicable to the following users

Tier: ESSENTIAL, GROWTH, SCALE

Platform: Web

Use Permission Groups to allow or restrict specific functions for the default StaffAny access levels to suit your organizational structure better.

  • You can use permission groups to set custom-defined permissions for different groups of users.

  • Users in those permission groups will now have the new permissions as per defined in the permission group.

For example, suppose a group of your staff should be allowed to do everything within the default manager access level besides approving leave and approving unscheduled shifts. In that case, you can create and tag those staff to a custom-defined permission group to achieve this.

Permission group only applicable for Managers & Owners access level. Employee and Supervisor access level will always follow the default permission and cannot be customized.

Refer here to learn more about our default access levels.

This guide will cover the following:


Setting up Permission Groups for your team

Go to Settings > Team Management > Permission Groups to create and manage permission groups for your organisation.

If the menu is not visible, first confirm that your organisation plan supports Permission Groups and that your account has access to manage permission group settings.

Creating Permission Groups

  1. Go to Settings > Team Management > Permission Groups.

  2. Click on Add Permission Group.

  3. You will be directed to a new page. Fill in:

    1. Group Name
      You can customize the name of the permission group according to your preference. We recommend using clear and explanatory names, such as "Owner access to block managing payroll for other owners."

    2. Base Access Level
      The base access level is the default permission inherited if no specific permission is set to the permission group.

    3. Permission Target

      Allows you to specify which group of staff, sections, or teams that the permission group will be able to view and manage.

      1. All Staff
        Example: Scheduling manager not allowed to see payroll data of all staff.

      2. Assigned Section
        Example: HR with owner access level not allowed to see payroll data of staff in the same section.

      3. Assigned Teams
        Example: HR with owner access level not allowed to see fellow HR salaries.

      4. Selected Teams
        Example: HR with owner access level not allowed to see boss and fellow HR/managers salaries.

      5. Selected Sections
        Example: Area manager with manager access level is not allowed to publish schedule in a specific section

  4. If you want this to be the default permission group for future staff at the same access level, tick Assign New Users at This Access Level to This Permission Group (optional).

  5. Click on the Next button to proceed.

  6. In this page, you can change the permissions on the Custom Permission column to:

    1. Allow

    2. Deny

    3. Not Set - This will fall back to the default access level setting. To learn more about access level permissions, refer to this article.

  7. Refer to the Result column for the newest permissions.

  8. After you finish, click on the Add Permission Group button at the bottom.

Note: Review the Result column before saving so you can confirm the final access that this permission group will apply.

List of customizable permissions

Permission name

Description

Applicable to the permission target?

Default Permission - Manager

Default Permission - Owner

View audit log report

To view the audit log report.

No

Deny

Deny

Add and edit permission group on settings

To view, create, and edit the permission group settings.

No

Deny

Allow

Add staff for own sections

To add and invite staff to the assigned sections of the organisation.

No

Allow

Allow

Deactivate and reactivate staff

To deactivate and reactivate staff from the organisation.

No

Deny

Allow

View staff profile

To view the staff on the list of My Team page and view the profile details. The staff hidden from My Team will also be hidden in the mass edit details export.

Yes

Allow for Assigned Sections

Allow for All Staff

View child information

To view child information on the staff profile details.

Yes

Deny for All Staff

Allow for All Staff

Add and edit child information

To add and edit child information on the staff profile details.

Yes

Deny for All Staff

Allow for All Staff

View employee wage details

To view employee wage details on the employee profile page.

Yes

Deny for All Staff

Allow for All Staff

Add and edit employee wage details

To add and edit employee wage details on the employee profile page.

Yes

Deny for All Staff

Allow for All Staff

View & edit payroll details

To view and edit specific information related to the current wages setup, additional pay items, statutory, and identification information. If it is hidden on the staff details, it will also be hidden in the mass edit details export.

Yes

Deny for All Staff

Allow for All Staff

View custom employee fields

To view custom employee fields that have already been set in the system.

Yes

Deny for Assigned Sections

Allow for All Staff

Edit custom employee fields

To edit custom employee fields that have already been set in the system.

Yes

Deny for Assigned Sections

Allow for All Staff

Manage staff permission group & access level on employee profile

Access to edit the permission group and the access level on a staff profile.

Yes

Deny for All Staff

Allow for All Staff

View leave tab

Blocks or allows viewing the Leave tab in web, which also controls adding and editing OIL and viewing the leave balance report.

Yes

Allow for All Staff

Allow for All Staff

Add leave type

To create a new leave type in the settings.

No

Deny

Allow

Edit leave type

To edit the existing leave type settings.

No

Deny

Allow

Edit leave hours

To edit the default leave hours on the staff profile details.

No

Allow

Allow

Leave approve & reject on behalf of all staff

To approve and reject leave requests on behalf of all staff.

No

Deny

Deny

Approve leave based on routing settings

If the user is within the leave routing, denying this permission allows the staff to receive the incoming leave application but not click the approve button.

No

Allow

Allow

Reject leave based on routing settings

If the user is within the leave routing, denying this permission allows the staff to receive the incoming leave application but not click the reject button.

No

Allow

Allow

Access dynamic QR webpage for own sections

To access the dynamic QR webpage for own sections.

No

Deny

Allow

Approve unscheduled clock request

Managers and owners within the assigned section receive notifications of unscheduled shifts or clock requests by default. Denying this prevents them from approving the request.

No

Allow

Allow

Reject unscheduled clock request

Managers and owners within the assigned section receive notifications of unscheduled shifts or clock requests by default. Denying this prevents them from rejecting the request.

No

Allow

Allow

Manage timesheets & work more approval for own sections

To edit timesheets and approve or reject unscheduled clock requests and work more requests for staff within scope.

Yes

Allow for Assigned Sections

Allow for All Staff

Manage timesheets & work more approval (for manager & owner access level) for own sections

To edit timesheets and approve or reject unscheduled clock requests and work more requests for managers and owners within scope.

Yes

Allow for Assigned Sections

Allow for All Staff

Edit actual sales for own sections

To edit actual sales in the web app or mobile app.

No

Allow

Allow

Run / Edit payroll

To access payroll functionalities and create or edit payroll for staff. This also includes access to the IR8A feature.

Yes

Deny for All Staff

Allow for All Staff

View payroll

To view payroll data, payroll reports, and payslip-related payroll pages for staff within scope.

Yes

Deny for All Staff

Allow for All Staff

View section labour cost report

To view and download section labour cost reports.

No

Deny

Allow

Create announcement for own sections

To send announcements for staff within the selected sections.

No

Allow

Allow

View schedule cost data

To view schedule cost data, including the schedule cost wheel, schedule cost per employee, and schedule cost per day.

No

Deny

Allow

View ReportAny reports

To access the ReportAny reports page.

Yes

Deny for All Staff

Allow for All Staff

Create and edit ReportAny reports

To create new reports and edit existing ReportAny reports.

No

Deny

Allow

Manage face enrollment for staff

To register and update staff face enrollment data.

Yes

Deny

Allow

Publish schedule

To publish schedule. Works for All Staff, Assigned Sections, and Selected Sections. It does not work when the selection target is Assigned Teams or Selected Teams.

Yes

Allow for Assigned Sections

Allow for All Staff

Edit published schedule

To unpublish a schedule or edit and remove shifts or leave in a schedule. Works for All Staff, Assigned Sections, and Selected Sections. It does not work when the selection target is Assigned Teams or Selected Teams.

Yes

Allow for Assigned Sections

Allow for All Staff

Add and edit payment field

To add and edit payment details on the employee profile page.

Yes

Allow

Allow

Access Disbursement

To access the disbursement menu.

No

Deny

Allow

Assign or tag staff to permission group

There are 2 ways to assign staff to a permission group:

A. Mass assign permission group with Mass Edit Staff Details

  1. Go to My Team.

  2. Open Mass Edit Staff Details.

  3. Download the current staff details file in CSV or Excel.

  4. Update the Permission Groups column with the correct permission group name.

  5. Upload the updated file and click Submit.

B. Assign permission groups from a staff profile

  1. Go to My Team and open the relevant staff profile.

  2. In the Work Information card, edit the Permission Groups field.

  3. Select the relevant permission group and click Save.

Note:

Staff can only be assigned to permission groups with the same access level. For example, managers can only be assigned to manager-based permission groups.

You cannot create a new permission group from the staff profile. Create it first in Settings > Team Management > Permission Groups.


Creating and Assigning staff to Teams

Teams are used as permission targets, so they help define which staff a permission group can view and manage.

For example, an owner in the HR team can be placed in an owner-based permission group that restricts payroll visibility for selected teams.

Create Teams

  1. Go to My Team and open the relevant staff profile.

  2. In the Work Information card, edit the Teams field.

  3. Select an existing team or type a new team name and create it.

  4. Click Save.

Assign Teams with Mass Edit Staff

  1. Go to My Team.

  2. Open Mass Edit Staff Details.

  3. Download the current staff details file in CSV or Excel.

  4. Update the Teams column with the correct team name.

  5. Upload the updated file and click Submit.


Seeing Permission Groups for your staff

To check whether the correct permission groups are assigned:

  1. Go to My Team and open the staff profile.

  2. Check the Permission Groups field in the Work Information card.


Permission Group Templates

Owner access level with all access to the app

  • Group name: Owner access all
    Note: You can customize the group name based on your preference.

  • Base access level: Owner

  • Target Group: All Staff

  • (optional) check Assign New Users at This Access Level to This Permission Group checkbox if you want a newly onboarded owner account to automatically be tagged to this permission group.

  • Custom permissions: Allow for all permissions

Owner access level not allowed to manage permission group

  • Group name: Owner block manage permission group
    Note: You can customize the group name based on your preference.

  • Base access level: Owner

  • Target Group: All Staff

  • (optional) check Assign New Users at This Access Level to This Permission Group checkbox if you want a newly onboarded owner account to automatically be tagged to this permission group.

  • Custom permissions:

Permission Name

Custom Permission

Add and edit permission group on settings

Deny

Manage staff permission group on employee profile

Deny

Other permissions

Not Set

Default Manager Staff View

  • Group name: Default manager staff view
    Note: You can customize the group name based on your preference.

  • Base access level: Manager

  • Target Group: All Staff

  • Check the “Assign New Users at This Access Level to This Permission Group” checkbox

  • Custom permissions:

Permission Name

Custom Permission

Add staff for own sections

Allow

View staff profile

Allow

Edit leave hours

Allow

Approve leave based on routing settings

Allow

Reject leave based on routing settings

Allow

Manage timesheets & work more approval for own sections

Allow

Manage timesheets & work more approval (for manager & owner access level) for own sections

Allow*

*If manager not allowed to edit their own, fellow managers, and owners’ timesheet, set this permission to Deny

Edit actual sales for own sections

Allow

Create announcement for own sections

Allow

Other permissions

Not Set

Manager with Owner access level is not allowed to see all owners salary

  1. Before creating a permission group, you have to create teams for all owners. As an example, the team will be called “Owners”.

  2. Tag all staff with owner access level to “Owners” team.

  3. Then create a permission group with following settings:

    1. Group name: Owner block see owner wages
      Note: You can customize the group name based on your preference.

    2. Base access level: Owner

    3. Target Group: Assigned Teams

    4. (optional) check Assign New Users at This Access Level to This Permission Group checkbox if you want a newly onboarded owner account to automatically be tagged to this permission group.

    5. Custom permissions:

Permission Name

Custom Permission

View & edit payroll details

Deny

Run payroll

Deny

Other permissions

Not Set

Manager with Owner access level is allowed to manage payroll for all staff under them (same section)

  • Group name: Owner allow manage payroll on same sections
    Note: You can customize the group name based on your preference.

  • Base access level: Owner

  • Target Group: Assigned Sections

  • (optional) check Assign New Users at This Access Level to This Permission Group checkbox if you want a newly onboarded owner account to automatically be tagged to this permission group.

  • Custom permissions:

Permission Name

Custom Permission

View staff profile

Allow

View & edit payroll details

Allow

Run payroll

Allow

Other permissions

Not Set

Supervisor with Manager access level is not allowed to edit their own, fellow manager level, and owner’s timesheets

  • Group name: Manager block edit timesheet
    Note: You can customize the group name based on your preference.

  • Base access level: Manager

  • Target Group: All Staff

  • (optional) check Assign New Users at This Access Level to This Permission Group checkbox if you want a newly onboarded owner account to automatically be tagged to this permission group.

  • Custom permissions:

Permission Name

Custom Permission

Manage timesheets & work more approval (for manager & owner access level)

Deny

Other permissions

Not Set

Prevent Supervisor access level from sales data input

  • Group name: Prevent Supervisor from sales data input
    Note: You can customize the group name based on your preference.

  • Base access level: Supervisor

  • Target Group: All Staff

  • (optional) check Assign New Users at This Access Level to This Permission Group checkbox if you want a newly onboarded owner account to automatically be tagged to this permission group.

  • Custom permissions:

Permission Name

Custom Permission

Edit actual sales for own sections

Deny

Other permissions

Not Set

View Custom Employee Fields

To view custom employee fields on the employee profile. Applies to ALL custom fields; you cannot specify permissions by individual field.

No

Allow

Allow

Edit Custom Employee Fields

To edit custom employee fields on the employee profile. Applies to ALL custom fields; you cannot specify permissions by individual field.

No

Allow

Allow


Frequently Asked Questions

Q: Why can't I add a new permission group? Why is the button gray or disabled?

A: When creating a new permission group, there should be at least one permission that is set to allow or deny instead of not set

Q: What happens if one staff has 2 or more permission groups assigned?

A: Both permission groups would be effective. But if some permissions have different allow/deny settings, it will take the priority as follows:

  • Deny

  • Allow

  • Unset – equal to the base access level.

Q: Can one staff be in multiple permission groups, and each permission group has a different permission target?

A: Yes. Example:

  • HR is assigned to the “Allow to manage payroll except HQ” permission group which allows HR to run payroll for all assigned teams except HQ.

  • HR is also assigned to “Allow edit payroll details” of “Assigned sections” that allows HR to see and edit anyone’s payroll data who are in the same sections as HR.

  • Result: HR would be able to view and edit payroll details of assigned sections, and they’re able to run payroll for all staff except for HQ team.

Q: All managers are able to do payroll for each section but StaffAny manager access levels are not allowed to access payroll. However, I don’t want them to have same access as owner. What should I do?

A: Unfortunately manager access level can’t access any payroll feature in web app. If you want your manager to be able to run and access payroll for staff under them, you can change their access level to “Owner” and tag them to “Owner block see owner wages” and “Owner allow manage payroll on same sections”.

Q: If I set Run Payroll permission to "Allow" for "All Staff" and "Deny" for "Selected Teams". Will I be able to see the payroll report for all of the staff except those ones that belongs on the team or i shouldn't be able to see for everyone?

A: You will be able to see all of the staff payroll report expect the ones that's tagged into that specific team that you set before.

Q: Help, my staff can't see the IR8A Feature! What did i do wrong?

A: Make sure that you have set "Run Payroll" permission to be allowed for All Staff if you wanted the staff to be able to access IR8A Feature.

Q: Can i set so that my supervisor/employee access level can access/use feature that's not available by defeault? For example i want my supervisor access level to be able to manage schedule like manager access level. Can this be done?

A: Unfortunately no, permission group access can only be denied or allowed if the original access level is ‘allow’ by default. Since both employee and supervisors doesn't have access to these features in the first place, this cannot be customized with permission group.

Did this answer your question?