Supported Actions
- Setting permissions for roles
- Assigning role(s) to a user
- Assigning users to a role
- Bulk updating users in Roles
- Adding guest user access
- Impersonating users
Setting permissions for roles
All user permissions are managed from Settings in the Pave app. You can look up all users & their assigned roles on the Users page, and look up role information on the Roles & Permissions page.
Setting product access for a role
On the Roles page, each role contains toggles for each Product area in Pave. The enablement of any product toggle gives users in that role access to that product in Pave. The permission settings underneath the product toggle define how the user can interact with that product:
Setting product permissions for a role
A user’s permissions are comprised of their role’s authority and scope settings within each Pave product. You can change the authority & scope permission settings for any role based on your organization’s needs.
Authorities
Define what a user can do using a given feature. Some authorities are product specific.
- “View” authority: Users can view this information in Pave
- “Edit” authority: Users can edit this information in Pave
- "Export" authority: Users can export this information in Pave
- "Invite" authority: Users can invite others to use this product in Pave
- "Override" authority: User can override preset hard stops in Pave
Scopes
Define who a user can see within a given product or feature.
The following scopes are organized in descending order of priority. Users with multiple roles receive the highest (most permissive) access rank out of all the roles assigned to them:
- All: The user sees every employee at the company. Generally this permission scope should be reserved for roles that have access to all employee compensation in your HRIS or other systems.
- Full Rollup: The user sees everyone beneath them in their reporting tree. In the Total Rewards product, this also includes the ability to view themselves.
- Direct reports only: The user sees anyone who reports directly to them. In the Total Rewards product, this also includes the ability to view themselves.
- Themselves: The user sees themselves
Custom Scopes
Custom scopes can be configured to provide access to a department, the direct reports or full rollup of an individual, particular employees, or location.
- adding And Logic to custom scopes
To add multiple dimensions to a custom scope’s filter, select +Add to add a second set of criteria to the role’s custom scope. By adding multiple criteria to the same filter, users in this role can only see employees at the company who meet every filter criteria.
- adding Or Logic to custom scopes
To add an alternate filter to a custom scope, select Add filter group below the current filter to add a separate filter to the role’s custom scope. By adding this, users in this role can see employees at your company who meet at least one filter’s criteria.
Assigning role(s) to a user
There are three ways to assign users to roles in Pave. None of these methods of adding a role to a user automatically removes the user from their previously role— in fact, multiple roles can be given to a user to given them more nuanced access in Pave:
When multiple roles are assigned to a single user, all role permissions are combined for that user, and they receive the highest permission level for each Pave area between all of their roles.
If a user has both edit all and view reports only permissions from different roles, but for the same product, they will have edit all access to that product area, since that is the highest permission level afforded to them between their assigned roles.
Ways to assign users to roles
1. Assign roles to a user from the Users page
2. Add new users to a role’s user list from the Roles page
3. Bulk add/ remove users to a role
You can preview the final permission settings for a user before saving changes. From the Users page, click on the employee you wish to update, and click the + icon next to their roles to add a new role. The permission settings below will update to preview the user’s new permissions for your review prior to saving the new role addition.
Assigning Users to a Role
-
Navigate to the Roles & Permissions page in Settings and choose a role
-
On the role’s Permissions tab, review all Pave products & permissions that are enabled for this role to confirm this is an appropriate role for the employee(s) you wish to add
-
From the Roles & Permissions page, click on the Assigned Users tab, then Add Users
- Add users by email in this module. You can search for individuals or paste a list of emails to add multiple users at a time.
Important permission changes are always flagged anytime you’re adding users to a role that gives them especially permissive access, like the ability to view equity or all employees:
- Save your changes on the Users page to add the new users to this role (unsaved users will be highlighted in green or red, depending on whether they’re being added to the role or removed).
Bulk updating users in roles
From the Users page in Settings, use the left-side bulk select checkbox to select all users in the filtered view to add or remove them all from a single role at once, using the Remove role or Assign role options in the top right corner:
Using Filters with bulk role assignments:
Use any of the columns on the Users table to filter employees by a department, title, level and/or city to bulk add a specific group of users into a role. For example, you can add all managers to the Manager role by filtering for all manager levels, and bulk selecting that population to add them to Manager.
Adding guest user access
Non-employees can be added to your Pave account using the Guest flow. Select “+ Add guest” in the top right corner of the Users page and follow the instructions provided.
Note: Employees are automatically removed from Pave if terminated, but Guest users need to be manually removed from Pave when you wish to terminate their access. Contact Pave to do this.
Impersonating users
Admins on your Pave account can impersonate other users to check their permissions, and take action on behalf of others to unblock merit cycles. To impersonate another employee, click the eye icon to the right of the employee’s name on the Users page, and Pave will reload to display the employee’s view:
Note that while impersonating another user, any actions taken in Pave will be acting as the user themselves. Check out our Impersonation docs to learn more about this function.
Have questions about this doc? Get in touch with our Support Team!