Roles & Permissions
How to create and edit administrative roles with granular permissions in WorkClock HQ.
Roles & Permissions
Use Roles & Permissions to control what administrators can view, create, update, delete, approve, or export across WorkClock HQ.
Open it from Company Settings > Roles & Permissions, or go to /company-settings?tab=roles.
What The Roles List Shows
The roles table shows:
- Role name.
- Number of active permissions.
- Date created.
- Edit action.
The default Admin role is labeled Default and may have restricted editing behavior.
Staff roles are filtered out of this list so the page focuses on administrative access.
How To Create A Role
- Open Company Settings > Roles & Permissions.
- Click + Add Role.
- Enter a Role Name, such as
HR ManagerorBranch Supervisor. - Search for permissions if needed.
- Select individual permissions, or use Select All within a permission category.
- Review the Role Summary panel.
- Click Add Role.
How To Edit A Role
- Open Company Settings > Roles & Permissions.
- Click a role row or the edit icon.
- Update the role name if editable.
- Add or remove permissions.
- Review the Role Summary panel.
- Click Update.
Permission Categories
Permissions are grouped by area, such as:
- Employees.
- Departments.
- Sub-departments.
- Department roles.
- Shifts.
- Clock-in.
- Attendance.
- Reports.
- Settings.
- Work schedules.
- Organization admins.
- Audit logs.
- Transactions.
Some permission categories may be marked coming soon and cannot be selected yet.
Role Builder Tools
The role builder includes:
- Search permissions: find a permission by label or key.
- Select All: select every permission inside a category.
- Deselect All: remove every selected permission inside a category.
- Role Summary: see the role name and selected permissions before saving.
- Selected Access: review the selected permission list.
Current Delete Behavior
Role deletion is not currently exposed from the roles list. The available role actions are create and edit.
If a role should no longer be used, remove it from users or replace it with a safer role. If role deletion becomes available later, use it carefully because it can affect administrator access.
Best Practices
- Give each role the minimum access required.
- Create roles around job responsibilities, not individual people.
- Avoid giving broad settings or role management access to users who do not manage security.
- Review permissions before assigning a user as an administrator.
- Keep a small number of high-trust users with role management rights.
Example Role Designs
| Role | Suggested access |
|---|---|
| HR Manager | Employees, attendance, reports, limited organization settings. |
| Branch Supervisor | View employees, view attendance, manage assigned department or branch operations. |
| Finance Admin | Billing, transactions, invoices, subscription-related access. |
| Operations Admin | Locations, schedules, shifts, attendance reports. |
FAQs
Why can I not create a role?
Your account may not have role management permission.
Why must I select at least one permission?
A role without permissions cannot perform useful admin work, so the form requires at least one permission.
Can I search permissions?
Yes. Use the search field in the role builder to find permissions by label or key.
Can I delete a role?
The current roles list does not expose a delete action. Create and edit are the supported actions in the visible UI.
Should every admin use the default Admin role?
No. Use custom roles for day-to-day administrators so each person has only the access they need.