Skip to content

Settings: Permissions & Roles ​

This guide covers the concrete screens behind GoldServe's access control — creating roles, assigning them, granting individual exceptions, and restricting specific features. For the underlying concepts (what a role is, how manager access works), see User Roles & Access.

All three screens sit under Settings → General.


Purpose ​

This answers: "How do I actually set up who can do what?"


The Three Controls ​

ScreenWhat it grantsWhen to use it
User GroupA named bundle of permissions, held by any number of employees.The normal way to give access.
Employee PermissionOne permission, granted directly to one person.A one-off exception that does not justify a role.
Accessibility RestrictionNothing — it takes away, limiting a feature to a chosen set of people.Narrowing a feature that is otherwise open to everyone.

The first two add up: someone's access is whatever their roles grant, plus whatever they hold individually. The third is separate, and can override both.


User Group (Roles) ​

Settings → General → User Group has three tabs:

  • Group Permissions (create) — name the group and tick its permissions.
  • Group Permissions (list) — every group, with how many permissions each holds.
  • Group Assign — put employees into a group.

The permission matrix ​

Permissions are laid out by module, then by record type within it, with the four standard actions for each:

ActionWhat it allows
ViewOpen and read those records.
AddCreate new ones.
ChangeEdit existing ones.
DeleteRemove them.

Only the record types that make sense to administer are listed. Internal and historical record types — change-history rows, attachments, link tables, and similar — are deliberately left out of the matrix, so the list stays close to what an administrator actually recognizes.

Editing an existing group ​

From the list, a group can be expanded to reveal its permissions, edited, renamed, or deleted. Individual permissions can also be removed one at a time without reopening the full matrix. A rename needs at least four characters.

Assigning employees ​

On the Group Assign tab, choose a group and then choose the employees who should hold it. The form opens pre-filled with the group's current members.

Saving replaces the membership. The list you save becomes the group's complete membership — anyone previously in the group but left off the new list is removed from it. Treat each save as the full, current roster rather than as an addition to it.


Employee Permission (Individual Grants) ​

Settings → General → Employee Permission lists everyone who holds at least one directly granted permission, and lets you assign more. The same matrix as above is used, applied to one person instead of to a group.

The same information also appears on an employee's own profile, so an individual's direct grants can be reviewed from their record rather than from Settings.

Use this sparingly. A permission granted here is invisible from the role list, which makes an access review harder — a role is easier to audit and to reuse.


Accessibility Restriction ​

Settings → General → Accessibility Restriction limits selected features to selected employees. It works independently of permissions: it is a second gate, not a permission of its own.

The features that can be restricted ​

FeatureWhat it controls
Default Employee ViewBrowsing the company-wide employee list.
Default Employee Detailed ViewOpening an individual employee's full record.
Profile Edit AccessEditing one's own profile. Only appears once Restrict Profile Edit is switched on in General Settings.
Gender Chart, Department Chart, Employees Chart, BirthdaysThe corresponding cards on the dashboard.

How a restriction is defined ​

For each feature you build a filter describing who keeps access — by department, job position, job role, work type, employee type, company, shift, tags, user group, or held permissions, or by naming individual employees. Employees can also be explicitly excluded.

Three states are possible:

  1. No filter saved — the feature is open to everyone. This is the starting state for every feature.
  2. A filter saved — only employees matching it keep the feature.
  3. Restrict All switched on — nobody has the feature, whatever the filter says.

Clear Filter returns a feature to state 1, open to everyone.


What Each User Sees ​

ActionEmployeeReporting ManagerHR Administrator
Create or edit a role——✅
Assign employees to a role——✅
Grant an individual permission——✅
Restrict a feature to specific employees——✅
See their own direct permissions on their profile✅✅✅

How Visibility Is Decided ​

  1. Permissions. Viewing groups, assigning permissions, and changing accessibility each need their own administrative permission. Nothing here falls back to reporting-manager access.
  2. Roles are system-wide. A user group is not scoped to a company: the same role exists across every company in the system, and assigning it is not limited by the company switcher.

Good to Know ​

  • Group assignment is a full replacement, not an addition. Check the complete list of intended members each time, rather than assuming existing members stay if they are left off.
  • A restriction and a permission are independent. Someone can hold every relevant permission and still be blocked from a feature that is restricted to a different group of people. The reverse is also true: a feature with no restriction saved is open to everyone regardless of permissions.
  • A restriction with nothing selected is not a restriction. Saving an empty filter leaves the feature open to everyone. To close a feature to all, use Restrict All.
  • Reporting managers get access that no screen here grants. Much of GoldServe lets a manager see their own team's records without any permission at all. That path is not configured on these screens — see User Roles & Access.
  • Feature restrictions are cached for the duration of a session. A restriction saved while someone is signed in may not take effect for them until their session refreshes.