Detected country: US
logo
‌
‌
‌
logo

Powered by

  • Home
  • Account & Permissions
  • Roles and permissions
  • Create and manage roles

Create and manage roles

5min read

Share

Create and manage roles

What are roles?

Roles control what each person in your Pave account can see and do. Every role includes a set of permissions that determine which products a user can access, what actions they can take, and which employees they can view data for.

Pave includes default roles for common use cases, and you can create custom roles tailored to your organization. You can assign multiple roles to a single user, duplicate roles to build on existing permission sets, and delete roles you no longer need.

Default roles

Every Pave account includes the following roles. The exact set may vary depending on which Pave products your organization uses.

RoleDefault access
AdminFull access to all Pave products, settings, and administration features, including role management and impersonation
EmployeeCan view their own compensation, total rewards, and profile data
ManagerCan view and manage data for their direct reports and reporting tree
RecruiterCan view and manage their own candidates
Recruiting ManagerCan view and manage all candidates
IntegratorCan manage HRIS, ATS, and other data source connections
BenchmarkerCan view Market Data benchmarks and reports, and invite collaborators
ExecutiveCan view and edit compensation data for their reporting tree, with visibility into equity and total rewards
HR Business PartnerMinimal default access, designed to be customized with scopes tailored to specific employee groups

The Admin and Employee roles cannot be deleted. All other default roles can be deleted if your organization does not need them.

Who can manage roles

To create, edit, duplicate, or delete roles, your role must include edit access to Role Management under Settings. The default Admin role includes this permission.

Create a custom role

  1. Go to Settings > Roles & Permissions.
  2. Click Create role.
  3. Enter a name for the role. Names must be unique within your account and can be up to 255 characters.
  4. Enter a description explaining what the role is for and who should have it (up to 510 characters).
  5. Configure the role's permissions for each product area.
  6. Click Save.

Your organization can have up to 100 roles total, including both default and custom roles.

Duplicate a role

Duplicating a role copies its permission settings into a new role, so you can adjust access without starting from scratch.

  1. Go to Settings > Roles & Permissions.
  2. Find the role you want to duplicate.
  3. Click Duplicate.

The new role is created with the name "[original name] Copy" and the same permissions as the original. Rename the role, adjust permissions as needed, and click Save.

Duplicating copies permissions only. Users assigned to the original role are not added to the duplicate.

Delete a role

  1. Go to Settings > Roles & Permissions.
  2. Find the role you want to delete.
  3. Click Delete and confirm.

Deleting a role is permanent and cannot be undone. You cannot delete the Admin or Employee roles.

Users assigned to the deleted role lose the permissions it provided. If those users have other roles, those roles still apply. Every user retains the Employee role regardless.

Assign users to roles

From the Roles & Permissions page

  1. Go to Settings > Roles & Permissions and select a role.
  2. Click the Assigned users tab.
  3. Click Add users.
  4. Search by name or paste a comma-separated list of email addresses.
  5. Click Save.

When you add users to a role that grants broad access (such as viewing all employees or equity data), Pave displays a warning so you can review the change before saving.

From the Users page

  1. Go to Settings > Users.
  2. Click on a user to open their profile.
  3. Click the + icon next to their current roles.
  4. Select a role. The permission summary below updates to preview what the user's access will look like with the new role.
  5. Click Save.

Bulk assignment

  1. Go to Settings > Users.
  2. Use the column filters to narrow the list (by department, title, level, or location).
  3. Select the checkboxes next to the users you want to update, or use the select-all checkbox for the filtered view.
  4. Click Assign role or Remove role in the top right.
  5. Choose the role and confirm.

Automatic manager assignment

Instead of manually assigning users to a manager role, you can have Pave automatically assign the role to everyone who is a direct manager in your HRIS. When enabled, Pave syncs role membership with your HRIS management hierarchy each time your data updates, adding new managers and removing users who are no longer managers.

To enable automatic assignment:

  1. Go to Settings > Roles & Permissions and select the role.
  2. Click the Assigned users tab.
  3. Switch from Add users manually to Assign managers automatically.
  4. Review the preview showing how many managers will be assigned, then confirm.

When you switch a role to automatic assignment, any users who were manually added are removed and replaced by the HRIS manager list. Pave sends you an email once the assignment is complete.

If you switch back to manual assignment, all currently assigned users stay on the role. You can then add or remove users individually.

You cannot edit individual user assignments while a role is set to automatic. To make manual changes, switch the role back to manual assignment first.

Multiple roles

A user can have more than one role at a time. When a user has multiple roles, permissions are additive: the user receives the highest level of access granted by any of their roles for each product area.

For example, if one role grants view access to Compensation Planning for direct reports, and another role grants edit access for all employees, the user has edit access to all employees in Compensation Planning.

You can preview the combined permissions for any user from their profile on the Users page before saving changes.

Add a guest user

Guest users are people outside your company who need access to Pave, such as external consultants or advisors.

  1. Go to Settings > Users.
  2. Click Add guest in the top right.
  3. Follow the prompts to enter the guest's information and assign a role.

Guest users are not connected to your HRIS. Unlike employees, who are automatically removed from Pave when they leave your company per HRIS sync, guest users must be manually removed when their access is no longer needed.

Things to know

  • The Employee role is assigned to every user by default and cannot be removed.
  • Roles are shared across all Pave products. A change to a role's permissions affects every user with that role, in every product.
  • Role names must be unique within your account.
  • Your organization can have up to 100 roles total.
  • To verify what a role looks like in practice, you can impersonate a user with that role. See [Impersonate a user] for details.

Share