Users, Roles & Permissions FAQ
Answers to common setup and operating questions about user management, roles, and permissions.
For what the system is and how to set it up from scratch, see the
Users, Roles & Permissions Overview.
Setup
What are the four system roles, and can I change them?
The four system roles are Super Admin (hierarchy level 1), Administrator (level 2), Manager (level 3), and Member (level 7). Super Admin and Administrator are immutable — their permissions cannot be edited and the roles cannot be deleted or deactivated. Manager and Member permissions can be customised through the permission matrix at Admin → Roles.
What happens if I create a user without selecting a role?
The user defaults to Member. Their legacy role is set to Member, and the system automatically assigns the matching organizational role immediately after the user is created.
Do I need to send an invitation separately after creating a user?
Yes. Creating a user puts them in Uninvited status — they exist in the system but cannot sign in. You must click Send Invite on their profile (or use the bulk invite action) to generate a temporary password and email it. A user is invitable only when they are active and have an email address on file.
Permissions and access
How do I create a custom role with specific permissions?
Go to Admin → Roles → New Role. Set a name, hierarchy level, and pick a source role to copy permissions from. If you select Super Admin as the source, Admin-level permissions are copied instead — Super Admin permissions are not copyable. If no source is selected or the source is not found, Member permissions are applied. After creation you are taken directly to the permission matrix to customise.
Which features are reserved for Super Admins only?
Two features are excluded from the permission matrix for every other role: System Health and Sample Data. Only Super Admins can access system checks and load or clear sample data. All other permissions can be granted to any custom role through the matrix.
What is the difference between an organizational role and the legacy role?
Every user has both. The organizational role is the modern, permission-granular assignment you manage at Admin → Roles. The legacy role (Super Admin, Admin, Manager, Member) is derived automatically from it and controls the platform-level access checks phrased as “Admin or above” and “Manager or above”. You never need to set the legacy role directly — it follows the organizational role assignment.
What is the hierarchy level and why is there a gap between Manager (3) and Member (7)?
The hierarchy level determines who is “above” or “below” whom for subordinate/superior checks. The gap between level 3 (Manager) and level 7 (Member) exists to accommodate custom roles. When default roles are created, the system also provisions Director (2), Regional Manager (3), People Operations Manager (4), District Manager (5), Location Manager (6), and Supervisor (7) to fill those levels.
Day-to-day
How do I import users in bulk?
Go to Admin → User Management → Import, download the CSV template, fill it in, and upload the file. Maximum file size is 10 MB. Two import modes are available: Add only (creates new users, skips matches on email or user ID) and Add and update (creates new and updates existing matches). The import runs as a background job.
What can I do with bulk actions, and when do they run in the background?
Select multiple users from the list, then choose an action: activate, deactivate, change role, change password, assign organizational role, change department, change location, change manager, assign skill, assign leave policy, update schedulable status, update on-call status, send invitations, or delete. When the action targets more than 100 users, it runs as a background job with a progress card. The “Select All Filtered” option requires at least one active filter — it is blocked without one.
How does deactivating a user differ from deleting one?
Deactivate keeps the user record but removes platform access and automatically unassigns their upcoming shifts. You can also record termination details (date, type, reason, last working day). Delete is a soft-delete: the record is hidden for 30 days and can be restored from Admin → User Management → More Actions → Deleted Users. After 30 days, records become eligible for permanent deletion.
What stops me from accidentally permanently deleting users?
Several guards. You must type the exact confirmation string “PERMANENT DELETE” (for selected users) or “DELETE ALL USERS” (for all soft-deleted users). You cannot delete yourself — the system removes the current user from any bulk deletion list. Only a Super Admin can delete another Super Admin. And the system prevents deleting the last Super Admin in the business.
When something looks wrong
“I created users but they say they can’t log in”
The most common cause: their invitation status is still Uninvited. Creating a user does not automatically send credentials. Go to their profile and click Send Invite, or select them in the user list and use the bulk Send Invitations action. Also verify the user is Active — an inactive user cannot sign in even if invited.
“A user has the Manager job title but can’t approve timesheets”
Job titles and job functions are informational labels — they do not grant platform permissions. Access is controlled entirely by the organizational role. The user needs a role that has the approve action enabled for the relevant feature (e.g. timesheets) in the permission matrix at Admin → Roles.
“We deleted someone last month — can we get them back?”
Deleted users can be restored for 30 days from Admin → User Management → More Actions → Deleted Users. After 30 days they are eligible for permanent deletion and cannot be recovered. If fewer than 30 days have passed, click Restore on the user’s entry.
Job families and job titles
What is the difference between a job family, a job title, and a job function?
A job family (e.g. “Sales”, “Engineering”) is a grouping container. A job title (e.g. “Sales Representative”) belongs to a job family and is assigned to users on their employment profile. A job function is a free-text classification on the user’s employment profile, entered in the Job Function field. All three are informational and for reporting — none of them grant platform permissions or control access.
Can I delete a job family or job title that has employees assigned?
No — the system deactivates them instead of deleting. For both job families and job titles, the system checks for assigned employees first. If employees are assigned, the record is marked inactive and preserved. If no employees are assigned, it is deleted outright.
Defaults and limits
Are new users schedulable by default?
Yes. Include in Shift Scheduling is on by default. A newly created user will appear in shift scheduling unless you explicitly turn that setting off on their employment profile. On-call is the opposite — Enable for On-Call Duty is off by default.
Is there a limit on how many users I can export at once?
Exports of more than 1,000 users run as a background job rather than as a synchronous download. There is no hard cap on the number of users you can export.
More help
- Users, Roles & Permissions Overview — what the system is and how to set it up.
- Security & Sign-On — password policies, SSO, session timeouts, and two-factor authentication.
- Ask AI — the assistant answers user management questions from these articles.