Who sees what in an HR system: the roles and the classic mistake
Echipa HR 365 · reviewed 2026-09-05 · 5 min read
Permissions in an HR system break in exactly one way: by copying. A new person gets “the same rights as X”, because it is faster than thinking about what they need. After two years of copying, half the company has the rights of the most privileged person from two years ago.
The four base roles
Almost any organisation works with four levels. Exceptions get added on top, but exceptions have to be few and named.
| Role | Sees | Can change |
|---|---|---|
| Employee | Their own data, balance and schedule | Their contact details; submits requests |
| Manager | Their team: schedule, absences, reviews, requests | Approves requests, completes reviews |
| HR | The whole company, sensitive data included | Almost everything, with a trace on sensitive actions |
| Administrator | The system configuration | Settings, roles — not the content of the data |
What a manager sees and does not
The area with the most bad decisions. A manager needs what lets them lead: who is away and when, what was agreed at reviews, which requests are waiting on them. They do not need the medical reason for an absence, the full history from previous employers, or reviews written by a previous manager in another department.
The practical rule, easy to apply: the manager sees what relates to the period and the team in which the person worked with them. What came before stays with HR, except what is operationally relevant — usually current skills and valid training.
What one colleague sees about another
More than we like to think, in most systems. The check is worth doing with a real employee account rather than from the configuration screen: open a colleague’s profile and see what appears. There are usually two surprises — personal contact details, and the job title with an effective date that reveals a recent promotion or move.
Not all of it is a problem. An HR director who wants people to know who does what has good reasons. What matters is that the visibility is a decision, not a default setting discovered by accident.
The periodic review
Twice a year, one hour
- HR and IT — list every user with rights above the employee level
- HR — checks whether each still holds the role the right was granted for — internal moves are the main cause of accumulation
- HR — removes access for people who have left; it is the most frequent discovery
- HR and IT — records the remaining exceptions and their reasons, so the next review does not re-litigate them
The second step produces the most corrections. Somebody moved from HR into an operational role usually keeps their old rights — not by intent, but because nobody owned the task of withdrawing them.
Where to start
Open the list of users with rights above employee level and count them. If there are more than you expected, you already have your answer about whether a review is worth it.
Then log in with an ordinary employee account and look at a colleague’s profile. What you see there is what the whole company sees — and it is usually a setting nobody chose.
Exceptions and how you keep them in check
Exceptions are inevitable: an assistant preparing reports, an external consultant for a period, a manager temporarily covering another team. The problem is not that they exist, but that they are not marked as exceptions — over time they become part of the normal configuration.
Three conditions for any exception
- The reason — written, in one sentence, at the moment it is granted — not reconstructed at review
- The expiry date — mandatory, even if it is a year out; a right with no date is never withdrawn
- Who approved — a name, so that at review there is somebody to ask whether it is still needed
The second condition is what makes the rest work. With expiry dates, the six-monthly review becomes a short list of decisions — renew or not — rather than an investigation into why somebody holds a right.
Temporary delegation
The most frequent case: the manager goes on leave and somebody has to approve in their place. The bad version, and the most widespread, is sharing the account. It destroys every trace: from that moment, nobody can say who approved what.
The correct version is a declared delegation, for a period, in which the stand-in approves under their own identity and it stays visible that they did so as a stand-in. It costs one setting and solves both the access problem and the accountability one.
What do I do about a director who asks for access to everything?
Ask what they want to be able to do, not what they want to see. In most cases the answer is an aggregated report, which can be provided without individual access to sensitive data.
Should a manager see reviews written by their predecessor?
Yes, the formal ones — they are professional history and help them avoid repeating conversations already held. The predecessor’s informal notes, no, because they were not written to be read by somebody else.
Predefined roles, with rights that are not copied from person to person
Each role comes with a considered set of rights, and exceptions stay visible as exceptions — so the six-monthly review takes an hour, not a day.
Free account, every module for 7 days, no card required.