Roles and Permissions in OpenHRApp

OpenHR uses role-based access control (RBAC) to ensure each user sees only what they need and can only perform actions appropriate to their role. This guide covers every role and its exact permissions.

This is a sub-guide of Welcome to OpenHR — read that first for a general overview.

Available Roles in OpenHR

RoleDescription
ADMINFull system access. Can configure everything in Organization Settings.
HRManage employeesleaves, and policies. Similar to Admin but focused on HR functions.
MANAGEROversee team attendance and approve leaves for direct reports.
TEAM_LEADLead a team. Can be configured as a leave approver.
EMPLOYEEStandard user. Can clock in/outapply for leave, and view personal data.

Complete Permission Matrix

FeatureAdminHRManagerTeam LeadEmployee
Dashboard (full stats)YesYesTeam onlyTeam onlyPersonal
Employee DirectoryFull CRUDFull CRUDView teamView teamView teammates
Organization SettingsFull accessFull accessNoNoNo
Attendance Clock In/OutYesYesYesYesYes
Attendance AuditYesYesTeam onlyNoOwn only
Leave ApplyYesYesYesYesYes
Leave Approve (Manager)OverrideOverrideDirect reportsIf configuredNo
Leave Approve (HR)YesYesNoNoNo
Leave Create/Edit/DeleteYesYesNoNoNo
ReportsAllAllTeam scopeNoNo
Profile/SettingsYes + Admin toolsYesYesYesYes

Key Access Rules to Understand

Related Guides