Organization Admin

Configure the workspace and run every operating module, control, integration, and business lifecycle.

Organization AdminLaunch14 min read

Add people, roles, and permissions

Create employee records, invite people to the platform, assign stable roles, and test least-privilege access.

Who can do this

Organization Owner or Organization Admin

Primary route

/settings/organization/permissions

Last verified

4 August 2026

What you need
Have these ready before you start.
  • A responsibility matrix for each job function
  • The person’s work email and employee details
  • Separation-of-duties decisions for Finance and payroll

01

Understand the access model

Organization membership establishes tenant access. The organization role controls administrative authority, while module roles and page grants control day-to-day access.

  • Organization Owner: highest tenant authority and continuity owner.
  • Organization Admin: manages organization configuration and operational access.
  • Organization Member: ordinary tenant member; module/page grants determine available work.
  • Permission roles should represent stable jobs such as Finance Preparer, Finance Approver, HR Operator, or Payroll Approver.

02

Create a least-privilege role

Open Settings → Organization → Permissions. Start with the smallest useful role and add only the modules and pages the responsibility needs.

  1. Create or select a permission role.
  2. Enable the required product modules.
  3. Grant page-level View access before Edit or approval authority.
  4. Keep preparation and approval in different roles where staffing allows.
  5. Save the role and review its effective module and page summary.
Organization permissions settings showing roles and module access
Settings → Organization → Permissions is the role catalogue. Access is granted by module and page, not by copying an administrator’s account.

03

Create the employee, then invite the person

For HR-backed users, create the employee record first so identity, employment, permissions, and self-service remain linked.

  1. Open Human Resources → Manpower or /hr/employees.
  2. Create the employee with legal name, work email, employee number, department, and employment dates.
  3. Open the employee record and assign the appropriate permission role.
  4. Use Invite to platform from the employee record.
  5. Ask the person to accept the invitation, secure the account, and confirm the active organization.

Expected result: The employee record has a linked user account and the user sees only the assigned module/page set.

HR employee directory used to create and manage employees
Human Resources → Manpower is the starting point for employee-backed user access.

04

Test and review access

A role is not verified until it is exercised as a non-admin user.

  1. Sign in with a synthetic or designated test member carrying the role.
  2. Confirm hidden modules and pages cannot be reached by direct URL.
  3. Complete one allowed read and one allowed write workflow.
  4. Review Settings → Organization → Audit Trail for the change evidence.
  5. Repeat access review after transfers, leave, offboarding, or role redesign.

Troubleshooting

  • The user has no workspace: confirm invitation acceptance and organization membership.
  • The user can enter HR but sees no manager pages: verify their HR permission role and page grants.
  • A role change appears ineffective: refresh the session by signing out and back in, then verify the active organization.