> ## Documentation Index
> Fetch the complete documentation index at: https://help-empuls.xoxoday.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Access control

> Define what each admin can see and do in Empuls. Use built-in roles or create custom access roles with menu-level permissions.

Empuls uses role-based access control to govern who can configure programs, manage employees, view reports, or take admin actions. Every user is assigned exactly one access role; the role determines which menus appear and which actions are allowed. Four roles ship with every account and you can create additional custom roles for specialized teams — finance, communications, regional admins — without granting full Super Admin privileges.

## Before you start

* You must be a **Super Admin** to view, create, or edit access roles.
* Changes to an access role take effect the next time an assigned user signs in or refreshes the page.
* Access role names are limited to 25 characters.

## Built-in roles

| Role              | What they can do                                                                                                                                                      |
| ----------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Super Admin**   | Full access — branding, org budgets, access roles, integrations, security settings, AI settings, and every menu under Admin Hub. Default group admin of the Townhall. |
| **General Admin** | Configurable access. By default, manages employees, programs, reports, and finance. A Super Admin can grant or revoke specific menus.                                 |
| **Manager**       | Team-scoped access — recognition and reports for direct reports, plus approval queues if configured. No platform-wide settings.                                       |
| **User**          | Standard employee access — recognition, surveys, rewards, social features, and personal profile. No admin menus.                                                      |

The four built-in roles cannot be deleted or renamed. Super Admin permissions cannot be reduced.

## How access control works

<Steps>
  <Step title="A role defines a permission matrix">
    Every menu in the Admin Hub maps to a permission. Each role has one of those permissions enabled or disabled.
  </Step>

  <Step title="A user is assigned one role">
    When you create or edit an employee, you pick their access role. The user inherits every permission of that role.
  </Step>

  <Step title="UI adapts to the role">
    Menus the role doesn't have access to are hidden. Direct URL access to a restricted page redirects to the home dashboard.
  </Step>

  <Step title="Changes propagate on next sign-in">
    If you change a role's permissions, assigned users see the new access the next time they reload or sign in.
  </Step>
</Steps>

## Review the permission matrix

<Steps>
  <Step title="Open Manage Access Roles">
    Click your profile icon in the top-right and select **Manage Access Roles**, or navigate to the Manage Access Roles page from Admin Hub.
  </Step>

  <Step title="Open Manage Access Roles">
    Click your profile icon in the top-right and select **Manage Access Roles**, or navigate to the Manage Access Roles page from Admin Hub.
  </Step>

  <Step title="View role columns">
    The page shows a matrix: rows are menus (Manage Employees, Budgets, Surveys, AI Settings, and so on); columns are access roles. A check in a cell means that role can access that menu.

    <Frame>
      <img src="https://mintcdn.com/empuls/_64PzH77Q1CYgFB7/images/Screenshot-2026-05-27-162841.png?fit=max&auto=format&n=_64PzH77Q1CYgFB7&q=85&s=534c449384e74f9770131175830e80b1" alt="Empuls access role permission matrix with menus as rows and roles as columns" width="1903" height="906" data-path="images/Screenshot-2026-05-27-162841.png" />
    </Frame>
  </Step>

  <Step title="View role columns">
    The page shows a matrix: rows are menus (Manage Employees, Budgets, Surveys, AI Settings, and so on); columns are access roles. A check in a cell means that role can access that menu.
  </Step>

  <Step title="Filter or search">
    For large permission lists, use the search to find a specific menu by name.
  </Step>
</Steps>

## Create a custom access role

<Steps>
  <Step title="Click Create Access Role">
    From the Manage Access Roles page, click **Create Access Role**.

    <Frame>
      <img src="https://mintcdn.com/empuls/_64PzH77Q1CYgFB7/images/Screenshot-2026-05-27-163404.png?fit=max&auto=format&n=_64PzH77Q1CYgFB7&q=85&s=ec22ce193eb905cb586642711f86a160" alt="Create Access Role button on the Manage Access Roles page" width="1872" height="903" data-path="images/Screenshot-2026-05-27-163404.png" />
    </Frame>
  </Step>

  <Step title="Click Create Access Role">
    From the Manage Access Roles page, click **Create Access Role**.
  </Step>

  <Step title="Name the role">
    Enter a **Role Name** (up to 25 characters). Use a descriptive name like "Finance Admin", "Regional HR", or "Communications Admin" so the matrix and employee profiles stay readable.
  </Step>

  <Step title="Click Submit">
    The role is created with no menu permissions enabled by default. It now appears as a new column in the matrix.\\

    <Frame>
      <img src="https://mintcdn.com/empuls/kZKA4_hUeWO-aNOX/images/Screenshot-2026-05-27-163523.png?fit=max&auto=format&n=kZKA4_hUeWO-aNOX&q=85&s=2e9938b402354030b4d32f6480e35aa0" alt="Newly created custom access role added as a column in the permission matrix" width="1857" height="902" data-path="images/Screenshot-2026-05-27-163523.png" />
    </Frame>
  </Step>

  <Step title="Click Submit">
    The role is created with no menu permissions enabled by default. It now appears as a new column in the matrix.
  </Step>

  <Step title="Enable menu permissions">
    In the new role's column, check each menu the role should access. Save when complete.
  </Step>
</Steps>

<Note>
  Some menu permissions are "system" permissions that cannot be removed from Super Admin — for example, access role management itself. These cells appear locked in the matrix.
</Note>

## Edit an existing role

<Steps>
  <Step title="Find the role">
    On the Manage Access Roles page, locate the role in the matrix.
  </Step>

  <Step title="Edit permissions">
    Click the **pencil icon** next to the role. Toggle menu permissions on or off.
  </Step>

  <Step title="Submit">
    Click **Submit** to save. Users assigned to this role see the updated access on next sign-in.
  </Step>
</Steps>

## Assign a role to a user

Role assignment happens on the employee record, not on the access role page.

<Steps>
  <Step title="Open the employee">
    Navigate to **Admin Hub → Employees → Manage Employees** and click the **pencil icon** next to the user.
  </Step>

  <Step title="Update the User Access Role">
    Pick the new role from the dropdown — built-in or custom.
  </Step>

  <Step title="Save">
    The user's access updates on their next sign-in.
  </Step>
</Steps>

You can also assign roles in bulk during CSV import. See [Manage employees](/admin/user-management/manage-employees) for the import flow.

## When to use custom roles vs delegation

| Use a custom role when…                                                | Use delegation when…                                                        |
| ---------------------------------------------------------------------- | --------------------------------------------------------------------------- |
| Several people need the same elevated scope (e.g., a regional HR team) | One person needs temporary cover for another (e.g., approvals during leave) |
| Access should persist over time                                        | Access is short-term, often days or weeks                                   |
| You want clear ownership and reporting per role                        | You want full account access without changing the user's permanent role     |

See [User delegation](/admin/user-management/user-delegation) for short-term account access.

## Limits and gotchas

* A user can have only one access role at a time. To grant additional menus, edit the role itself or use delegation.
* Deleting a custom role requires first reassigning every user holding that role to a different role.
* Permission changes don't kick out active sessions; users see new access only after their next sign-in or page reload.
* The Super Admin role cannot be assigned to a brand-new user who hasn't accepted their invite — they must activate their account first.

## Related

<CardGroup cols={2}>
  <Card title="Manage employees" href="/admin/user-management/manage-employees">
    Add users and assign access roles.
  </Card>

  <Card title="User delegation" href="/admin/user-management/user-delegation">
    Grant temporary access to another user's account.
  </Card>

  <Card title="SSO overview" href="/admin/user-authentication/sso-overview">
    Combine access control with single sign-on for centralized identity.
  </Card>
</CardGroup>
