Skip to content
CheckBiz360by EncodeBiz

Document access permissions

The CheckBiz360 document module applies a role-based permission model that determines which actions each user can perform on documents. Understanding this structure is essential to configuring access correctly, protecting sensitive documentation and guaranteeing that each person in the organisation sees only what concerns them.

Article 37 of 923 min read

Roles and general permissions

CheckBiz360 defines four main roles with different levels of access to the document module:

ActionWorkerSupervisorManagerOwner
View own documentsYes (public)Yes (public)Yes (all)Yes (all)
View other employees' documentsNoTheir team only (if permitted)Yes (their organisation)Yes (whole organisation)
Upload documentsNoSubject to delegationYesYes
Edit documentsNoSubject to delegationYesYes
Delete documentsNoNoYesYes
Request a signatureNoNoYesYes
Acknowledge receiptYes (their own)Yes (their own)Not applicableNot applicable
View private documentsNoSubject to delegationYesYes
Export documentsNoNoYesYes

Visibility of payslips and contracts

Payslips and contracts are the most common document types and also the ones that most frequently raise questions about who can access them.

Payslips

  • Owner and Manager: can see the payslips of every employee in the organisation, regardless of whether they are marked as private or not.
  • Supervisor: can see the payslips of the employees on their team only if the manager has granted them explicit access to that team's documents. By default, the supervisor has no access to payslips.
  • Worker: can see their own payslips if they are not marked as private. They cannot see any other employee's payslips.

Contracts

The same rules apply to contracts. An employee can see their own contract if it is published and not private. They cannot see their colleagues' contracts.

Restrictions through the private field

When a document has the private field enabled, visibility restrictions apply as follows:

  • The document is invisible to the employee (Worker) regardless of whether it is published.
  • The supervisor can only see the document if they have delegated permissions to manage the affected team's documents and if the manager has expressly granted them access to private documents.
  • The Manager and the Owner can always see every document, including private ones.

This hierarchy guarantees that sensitive information —such as disciplinary notes, appraisals or reprimand letters— stays protected from unauthorised access.

Delegating permissions from Manager to Supervisor

The manager can extend a supervisor's permissions to include document management for their team. This lets the supervisor take on responsibility for uploading and organising documents without needing to be given full manager access.

Delegation can cover:

  • Uploading documents: the supervisor can create and publish documents for the employees on their team.
  • Editing documents: the supervisor can modify the metadata of existing documents for their team.
  • Visibility of private documents: the supervisor can see documents marked as private for the employees on their team.

To configure permission delegation:

  1. Sign in to the back office as Manager or Owner.
  2. Navigate to the Employee management or Team configuration section.
  3. Select the supervisor you want to delegate permissions to.
  4. In the supervisor's permissions section, enable the corresponding document options.
  5. Save the changes.

Deletion permissions

Deleting documents is an irreversible action that only users with the Manager or Owner role can perform. Before deleting a document, check:

  • If the document has a registered signature, deletion will also erase the signature traceability record.
  • If the document forms part of a file that has to be retained by legal obligation, do not delete it even if its immediate operational usefulness has ended.

Marking obsolete documents as private rather than deleting them is recommended, especially for documents with a signature or with employment relevance, so as to preserve the history without exposing the document to the employee.

Was this article useful?

Cookie settings

Choose what you want to allow. You can change your mind at any time from “Cookie settings”, at the bottom of the page. Read the cookie policy

NecessaryAlways on

They make the site work and remember this very choice, so we don’t have to ask you again. They identify no one and never leave this site, so they don’t depend on your permission.

They tell us which of our ads bring visitors and which don’t, so we stop spending on the ones that fail. That’s the Meta pixel (Facebook and Instagram) and Google Tag Manager (Google Analytics and Google Ads): they set first-party cookies and send data to Meta Platforms Ireland and Google Ireland.