Skip to content
CheckBiz360by EncodeBiz

Permission matrix by role

CheckBiz360 applies a role-based access control model that determines precisely what each user can do within the platform. This matrix is the definitive reference for understanding which actions are available at each level and under what conditions.

Article 8 of 923 min read

Consult this table when configuring new profiles, resolving questions about access to features or reviewing your organisation's permission policy.

Permission table

ActionWorkerSupervisorManagerOwner
Create own clock recordYesYesYesYes
View own historyYesYesYesYes
View team historyNoYes (branch)YesYes
Request a manual workdayYesYesYesYes
Approve and correct clock recordsNoYes (branch)YesYes
Create tasksNoConfigurableYesYes
Validate tasksNoConfigurableYesYes
Rate workersNoConfigurableYesYes
Upload documentsNoNoYesYes
View own documentsYesYesYesYes
View team documentsNoYes (by role)YesYes
View payslips and contractsOwn onlyOwn onlyTeamAll
Create incidentsYesYesYesYes
Configure a branchNoNoYesYes
Manage employeesNoNoYesYes
View operational intelligenceNoPartialYesYes
Generate reportsNoNoYesYes
Configure the organisationNoNoNoYes

Notes on the table

Configurable supervisor permissions

Some supervisor permissions are marked as "Configurable" in the table. This means that the default behaviour can be enabled or disabled by the manager or the owner according to the company's operational needs. Specifically:

  • Create tasks — By default, supervisors cannot create tasks. The manager can enable this capability for specific supervisors.
  • Validate tasks — The same as creation: disabled by default, activatable by the manager.
  • Rate workers — Allows the supervisor to record performance ratings for the workers on their team. Disabled by default.

To modify these permissions, go to the profile of the supervisor in question and adjust the advanced permission settings.

Branch scope in the supervisor role

Where the table says "Yes (branch)", it means that the supervisor can only carry out that action on employees or data belonging to the branch where they have been assigned supervisor responsibility. They have no visibility over, or ability to act on, other branches.

Viewing team documents as a supervisor

The supervisor column says "Yes (by role)" for viewing team documents. This means the supervisor can see documents belonging to the staff assigned under their responsibility, provided those documents have been marked as accessible to their role level by the manager who uploaded them.

Viewing payslips and contracts

This permission behaves differently depending on the role:

  • Worker and Supervisor — Can only view their own payslip and contract documents.
  • Manager — Can view the payslip and contract documents of every employee on their team or at their assigned branches.
  • Owner — Has access to every payslip and contract document in the organisation, with no branch or team restriction.

Operational intelligence for supervisors

The supervisor's "Partial" access to operational intelligence means they can consult basic metrics and statistics for their branch's team (such as hours worked or attendance rates), but they have no access to the strategic analysis dashboards, branch comparisons or aggregate financial indicators that are available to the manager and the owner.

Configure the organisation

This action is reserved exclusively for the owner role. It includes configuring the company's global parameters such as the organisation name, the time zone, integrations with external systems and subscription management.

Considerations on access security

Role assignment should be reviewed regularly, especially at the following moments:

  • When an employee changes position or responsibilities.
  • When a supervisor moves to managing a different branch.
  • When an employee leaves the company.
  • After organisational restructuring or the opening of new branches.

Who can consult this configuration

Viewing and modifying role permissions is available to the manager (level 3) and owner (level 4) roles.

Was this article useful?

Cookie settings

Choose what you want to allow. You can change your mind at any time from “Cookie settings”, at the bottom of the page. Read the cookie policy

NecessaryAlways on

They make the site work and remember this very choice, so we don’t have to ask you again. They identify no one and never leave this site, so they don’t depend on your permission.

They tell us which of our ads bring visitors and which don’t, so we stop spending on the ones that fail. That’s the Meta pixel (Facebook and Instagram) and Google Tag Manager (Google Analytics and Google Ads): they set first-party cookies and send data to Meta Platforms Ireland and Google Ireland.