Configure role permissions
Configure role permissions
What are role permissions?
Every role in Pave includes a set of permissions that control two things:
- What the user can do (their authority): view data, edit data, or have no access
- Who the user can see (their scope): all employees, their reporting tree, only themselves, or a custom group
You configure permissions per product area. Each product area has a toggle to enable or disable it for the role, and individual permission settings underneath that control specific capabilities within that product.
To configure permissions, go to Settings > Roles & Permissions, select a role, and open the Permissions tab. For details on creating roles, assigning users, or managing the role list, see [Create and manage roles].
Product sections
The Permissions tab displays an accordion with one section per Pave product. Each section has a toggle labeled Enabled or Disabled on the right side.
- Enabled gives users in this role access to that product. Expand the section to configure the specific permissions within it.
- Disabled blocks all access to that product for users in this role.
The product sections you see depend on which Pave products your company uses. Available sections include:
| Product section | What it controls |
|---|---|
| Benchmarking | Access to Market Data benchmarks, reports, peer groups, and inviting collaborators |
| Compensation Planning | Access to merit cycles, the planner worksheet, cycle dashboards, reward letters, and related configuration |
| Connections | Access to HRIS, ATS, and other integrations, data management, and the Pave API |
| Reward Letters | Access to view or manage reward letters outside of a compensation cycle |
| Settings | Access to company info, user management, authentication settings, notifications, and communication configuration |
| Team View | Access to the Team View dashboard, employee data, demographics, equity data, compensation bands, and analytics |
| Total Rewards | Access to Total Rewards statements, future equity modeling, promotion modeling, and the learning hub |
| Visual Offer Letter | Access to create and manage Visual Offer Letters for candidates |
| Bands | Access to the Market Pricing band viewer, band manager, and aggregated employee data |
Set what a role can do
Each permission within a product section is displayed as a readable sentence that you can edit inline:
"Can [authority] [feature] for [scope]"
For example: "Can view the Live band set for full roll-up"
The first dropdown in each sentence controls the authority, which determines what action the user can take:
| Authority | What it means |
|---|---|
| Not access | The user cannot see or use this feature at all |
| View | The user can see the data but cannot make changes |
| Edit | The user can see and modify the data (this includes everything that view provides) |
Some permissions use more specific labels that map to the same authority levels. For example, "export" and "not export" for data downloads, "invite" and "not invite" for collaborator invitations, or "override" and "not override" for compensation controls.
Set who a role can see
The second dropdown in each permission sentence controls the scope, which determines which employees or records the user can access. Not every permission has a scope dropdown. Permissions that are simple on/off toggles (like cycle configuration access) only have the authority dropdown.
When a scope dropdown appears, the available options depend on the permission. Common scope options include:
| Scope | What the user sees |
|---|---|
| All employees | Every employee at the company |
| Full roll-up | Everyone in the user's reporting tree (all levels below them). In Total Rewards, this also includes the user's own data. |
| Direct reports | Only people who report directly to the user. In Total Rewards, this also includes the user's own data. |
| Themselves | Only the user's own data |
| Custom | A specific group of employees defined by filters you configure (see below) |
Visual Offer Letter permissions use candidate-specific scopes: all candidates or their candidates (only candidates assigned to the user as recruiter or hiring manager).
Configure custom scopes
When you select Custom as the scope, a filter panel appears below the permission sentence. This is where you define exactly which employees or records the user can access.
Filters use two levels of logic:
- Within a filter group, all conditions are combined with AND. The user only sees records that match every condition.
- Between filter groups, groups are combined with OR. The user sees records that match any group.
For example, to give a role access to Engineering employees in the US, plus Product employees in Canada, you would create two filter groups:
- Group 1: Department is Engineering AND Country is US
- Group 2: Department is Product AND Country is Canada
To build a custom filter, choose a field (such as Department, City, Country, or Person), an operator (such as "is" or "is not"), and one or more values. The available fields depend on what the permission controls. Employee permissions offer fields like Department, City, Country, Person, All reports of, and Direct reports of. Band permissions offer fields like Function, Ladder, Ladder Rank, and pay zone.
The filter panel displays a count of how many employees match your current configuration, so you can verify the scope before saving.
Reusable filters
If you find yourself configuring the same filters across multiple roles or permissions, you can save them as a reusable filter. Changes to a reusable filter automatically apply everywhere it is used.
To create a reusable filter, click Manage reusable filters at the top of the Roles & Permissions page, then click Create new reusable filter. You can also convert an existing inline filter into a reusable one by clicking Save as a reusable filter at the bottom of the filter panel.
To attach a reusable filter, set a permission's scope to Custom, then select the filter from the search dropdown. The filter rules appear as a summary card showing the filter name and a description of its rules.
If you need to customize a reusable filter for one specific permission without affecting others, click the Detach icon on the filter card. This copies the rules into a standalone filter you can edit independently.
The management drawer shows all reusable filters, their rules, and how many roles and permissions use each one.
Relative permissions for bands
When configuring band viewer or advanced band permissions in Compensation Planning, custom scopes support relative filter values that adjust automatically based on each user's position in your organization:
| Relative value | What the user sees |
|---|---|
| Values of Direct Reports | Bands matching the jobs of the user's direct reports |
| Own Value | Bands matching the user's own job |
| All Reports | Bands matching the jobs of everyone in the user's reporting tree |
These let you set a single permission configuration that automatically shows the right bands for each person, without creating a separate custom filter for every manager.
For example, a common configuration gives managers access to bands for their direct reports' roles and their own role, so they can discuss career progression without seeing the entire band set.
How multiple roles combine
When a user has more than one role, permissions from all roles are combined. The user receives the most permissive access granted by any of their roles.
Authority: For each permission, the highest authority across all roles wins. If one role grants view access to Team View employees and another grants edit access, the user has edit access.
Scope: Scopes from each role are evaluated independently and the results are combined. If one role grants access to direct reports and another grants access to a custom-filtered group, the user sees employees from both. Each role's custom filters are applied on their own, then the results are merged. They do not combine into a single filter set.
Product toggles: If any role enables a product, the user has access to that product, even if another role has it disabled.
Because permissions are additive, you cannot use a second role to restrict access granted by a first role. To narrow someone's access, adjust the permissions on the role that grants the broader access.
Examples
HR Business Partner with a regional scope: An HRBP supports the Engineering team in the US. They have the HRBP role with Team View scoped to a custom filter (Department is Engineering AND Country is US) and Compensation Planning scoped to the same group. They also have the default Employee role, which gives them view access to their own Total Rewards data. The result: they can see and manage compensation for US Engineering employees, and view their own Total Rewards statement.
Manager who is also a recruiter: A hiring manager has both the Manager role (Team View and Compensation Planning scoped to their full roll-up) and the Recruiter role (Visual Offer Letter scoped to their candidates). The result: they see their reporting tree in Team View and Compensation Planning, plus their own candidates in Visual Offer Letter.
Two roles with different custom scopes: A user has one role scoped to the Sales department and another scoped to the Marketing department. The result: they see employees in both Sales and Marketing. The filters do not merge. Each role's scope is applied separately and the results are combined.
You can preview the combined effect of a user's roles from the Users page in Settings. Click on a user to see their resolved permissions across all assigned roles.
Things to know
- The Admin role cannot be edited. Users with the Admin role have full access to all Pave products and settings.
- The Employee role is assigned to every user by default and cannot be removed.
- Some permissions are only visible when your company has the corresponding product or feature enabled. If you do not see a permission listed in a product section, your company may not have access to that feature.
- To verify what a role looks like in practice, impersonate a user who has that role. See [Impersonate a user] for details.
- Some Pave products have additional permission controls beyond what you configure here. Compensation Planning has column-level permissions within each merit cycle, and Team View has its own visibility settings. Those are configured within each product, not from the Roles & Permissions page.
- Changes to a role's permissions affect every user assigned to that role, across all Pave products.
