Skip to main content

Access roles: Default access role permissions in Sense HR

Check the out-of-the-box permissions for Standard users, Managers, Manager with Indirect reports, and Administrators.

Who it’s for: Administrators

Platform: Sense HR

Available on: Access roles available on all plans. Access Role Management (ARM) available on Professional, Elite, and Enterprise plans only.


Overview

Sense HR includes four default access roles:

  • Standard users

  • Managers

  • Manager with Indirect reports

  • Administrators

This article shows the permissions and behaviour of these roles in an out-of-the-box Sense HR organisation, before any Access Role Management customisation or additional screens, workflows, or custom actions have been added.

🖊️ Note:

For a simpler overview of what each default access role can see and do across Sense HR, see Access roles: What Standard users, Managers and Administrators can do.

Use this reference:

  • on Team plans, where the default roles apply and Access Role Management (ARM) is not available

  • to understand the starting permissions on Professional, Elite, and Enterprise plans

  • to compare a customised role with its original settings

  • when restoring permissions that have previously been changed through ARM

🖊️ Note:

Some permissions shown in this reference relate to features that may not be available on your current plan. If your plan does not include a feature, its access role permission has no effect while that feature is unavailable. If you later upgrade to a plan that includes the feature, the existing permission setting will take effect.

On Professional, Elite, and Enterprise plans, your live permissions may differ from this reference if roles have been customised using ARM. On Elite and Enterprise plans, additional screens, report types, or custom actions may also be present if your organisation uses Screen Designer or Automate.


Default roles at a glance

Access role

Default people access

Dashboard

Purpose

Standard users

Own profile only

Employee Dashboard

Employee self-service and standard company-wide features

Managers

Own profile + direct reports

Manager Dashboard

Provides manager access to their direct-reporting team

Manager with Indirect reports

Own profile + direct and indirect reports

Manager Dashboard

Extends manager access through the downward reporting hierarchy

Administrators

Everyone

Administrator Dashboard

Full system access

🖊️ Note:

These descriptions reflect the default configuration. On plans with ARM, the people scope of manager-type roles can be changed through People groups.


New users and automatic role changes

New users are assigned the Standard users role by default.

Because of this, administrators using ARM should make sure the permissions for Standard users remain suitable as a safe starting point for any newly added user.

Some role changes also happen automatically based on reporting lines:

  • When a user is assigned as a Line Manager in another employee’s Job details screen, they automatically move from Standard users to Managers.

  • If that user is later removed as Line Manager for their last or only direct report, they automatically move back from Managers to Standard users.

🖊️ Note:

Automatic role changes only apply between Standard users ↔ Managers. You can still manually assign another access role where required.


Understand what access roles control — and what is controlled elsewhere

Access roles provide the baseline for what users can see and do in Sense HR, but not every permission or behaviour is controlled through ARM.

The following are configured separately:

  • Event booking and approval rules — configured under Settings > Calendar & Planner > Event manager. For example, an event rule determines whether a booking requires approval and generates an approval To Do.

  • Personal document access — configured when a document is added to an employee’s profile. Document-level access can be given to the employee, their manager, or additional users.

  • Company document visibility — configured when a company document is uploaded by defining who it is assigned to and who is excluded.

  • Sense Mobile access — activated using a verification code sent by an administrator or another user with the relevant permission. Verification codes can be sent individually from a profile or in bulk from the People list.

  • Dashboard sickness widget — enabled or disabled under Settings > Calendar & Planner > General.

🖊️ Important note:

Having access to a screen does not always mean the user can access every record or perform every action within it. Document permissions, event rules, To Do behaviour, profile templates, and other configuration can further control the final user experience.


How to read the permission tables

Each row in the tables below is a screen or permission in Sense HR, and each column is an action the role can perform on it.

  • ✅ On — the permission is enabled by default.

  • ╳ Off — the permission is disabled by default.

  • Own profile — what the role can do on their own record.

  • People — what the role can do on other people’s records, within the people covered by their People group.

Every value shown is the out-of-the-box default. On Professional, Elite, and Enterprise plans these can be changed using ARM, so your live settings may differ.


Default permissions: Standard users

Standard users can access their own profile. They have no People access to other employee profiles.

Own profile

Screen

View

Update

Add

Delete

Overview

✅ On

✅ On

╳ Off

╳ Off

To do

✅ On

✅ On

✅ On

✅ On

Planner

✅ On

✅ On

✅ On

✅ On

Documents

✅ On

╳ Off

╳ Off

╳ Off

Additional notes

╳ Off

╳ Off

╳ Off

╳ Off

Bank details

✅ On

✅ On

✅ On

✅ On

Benefits

✅ On

╳ Off

╳ Off

╳ Off

Company equipment

✅ On

╳ Off

╳ Off

╳ Off

Contact details

✅ On

✅ On

╳ Off

╳ Off

Disciplinary & Grievances

╳ Off

╳ Off

╳ Off

╳ Off

Employment checks

╳ Off

╳ Off

╳ Off

╳ Off

Employment details (includes Employee ID)

╳ Off

╳ Off

╳ Off

╳ Off

Job details (includes Line manager)

╳ Off

╳ Off

╳ Off

╳ Off

Other contact details

✅ On

✅ On

✅ On

✅ On

Pay details

✅ On

╳ Off

╳ Off

╳ Off

Personal details (includes National insurance number)

✅ On

✅ On

╳ Off

╳ Off

PPE

╳ Off

╳ Off

╳ Off

╳ Off

Training

✅ On

✅ On

╳ Off

╳ Off

Vehicle

╳ Off

╳ Off

╳ Off

╳ Off

Leaver details

╳ Off

╳ Off

╳ Off

╳ Off

No field-level permissions are set by default for the Standard users role.

🖊️ Note:

On Elite and Enterprise plans, a profile template can determine which of these screens actually appears in a person’s profile. If a screen is not included in their profile template, access role permission does not make it appear.


People

Standard users have no People permissions tab and no access to other employee profiles through the People module.


Features

Users & Data

Permission

Default

Add new employee

╳ Off

Process leaver

╳ Off

Undo Leaver

╳ Off

View organisation explorer

✅ On

View gateway data

╳ Off

🖊️ Note: View organisation explorer gives access to Organisation Explorer only. It does not grant access to other employee profiles — profile access still follows the user’s access role.


Settings

Permission

Default

Manage dropdown lists

╳ Off

Calendar & Planner - General

╳ Off

Calendar & Planner - Working hours

╳ Off

Calendar & Planner - Event manager

╳ Off

Time & Attendance configuration

╳ Off

Document categories

╳ Off

Document templates

╳ Off

Company documents

╳ Off

Screen designer

╳ Off

Access roles

╳ Off

Basic AMI

╳ Off

Auto Pilot

╳ Off

Calendar with AMI

╳ Off

Payslip Upload with AMI

╳ Off

Expenses with AMI

╳ Off

Reports with AMI

╳ Off


Planner actions

Permission

Default

Manage planner settings

╳ Off

Edit past events

╳ Off

Delete past events

╳ Off

Add own sickness

╳ Off

Add attendance

╳ Off

Edit attendance

╳ Off

🖊️ Note:

Add own sickness is not the same as the Dashboard sickness widget. Add own sickness lets a user record sickness directly in their own Planner. The Dashboard sickness widget is controlled separately under Settings > Calendar & Planner > General.


Company Calendar

View calendar is On by default. The two settings below control whose events a user sees, and what detail is shown.

Who can they see?

Setting

Default

Everyone

╳ Off

Their team

✅ On

Their department

╳ Off

Their location

╳ Off

Their subcompany

╳ Off

Additional people filter

None

Exclude people

None

🖊️ Note:

Their team means the people who share the same line manager. Anyone in a reporting line has a team — including Standard users, who have one through their colleagues even though no one reports to them. A user with no line manager and no direct reports has no team, so this setting shows them no one.

What can they see?

Setting

Default

Sickness

✅ On

Sickness display

Hide sick reason

Attendance data

✅ On

Events

Holiday, Paternity, Maternity

🖊️ Notes:

  • Sickness and Attendance data are On/Off toggles. Sickness display and Events are set by choosing a value, so their defaults are shown as that default value rather than as On or Off.

  • Hide sick reason applies to the Company Calendar only. Users can always see the reason for their own sickness events in their personal Planner. By default, Managers can also see sickness reasons in the personal Planner for their direct reports, and Manager with Indirect reports can see them for their direct and indirect reports.

  • Company Calendar visibility is separate from profile access. Seeing that another person has an event does not give access to that person’s profile.


Reports

Permission

Default

View reports

╳ Off

Create report

╳ Off

Individual report categories

╳ Off


Custom actions

Permission

Default

Send verification code

╳ Off

Send login invite

╳ Off


Default permissions: Managers

Managers have the same default Own profile, Features, and Custom actions settings as Standard users.

Their additional access is determined by their People permissions which covers their direct-reporting team.


Own profile

The same as Standard users — see Own profile above.


People — Their Team

Managers have one default People group, Their Team, which covers their direct reports. The table below shows the profile permissions managers have for people in this group.

Screen

View

Update

Add

Delete

Field-level permissions

Overview

✅ On

╳ Off

╳ Off

╳ Off

╳ Off

To do

✅ On

✅ On

✅ On

✅ On

╳ Off

Planner

✅ On

✅ On

✅ On

✅ On

╳ Off

Documents

✅ On

╳ Off

╳ Off

╳ Off

╳ Off

Additional notes

╳ Off

╳ Off

╳ Off

╳ Off

╳ Off

Bank details

╳ Off

╳ Off

╳ Off

╳ Off

╳ Off

Benefits

╳ Off

╳ Off

╳ Off

╳ Off

╳ Off

Company equipment

╳ Off

╳ Off

╳ Off

╳ Off

╳ Off

Contact details

✅ On

╳ Off

╳ Off

╳ Off

✅ On

Disciplinary & Grievances

╳ Off

╳ Off

╳ Off

╳ Off

╳ Off

Employment checks

╳ Off

╳ Off

╳ Off

╳ Off

╳ Off

Employment details

╳ Off

╳ Off

╳ Off

╳ Off

╳ Off

Job details

╳ Off

╳ Off

╳ Off

╳ Off

╳ Off

Other contact details

╳ Off

╳ Off

╳ Off

╳ Off

╳ Off

Pay details

╳ Off

╳ Off

╳ Off

╳ Off

╳ Off

Personal details

✅ On

╳ Off

╳ Off

╳ Off

✅ On

PPE

╳ Off

╳ Off

╳ Off

╳ Off

╳ Off

Training

✅ On

✅ On

✅ On

✅ On

╳ Off

Vehicle

╳ Off

╳ Off

╳ Off

╳ Off

╳ Off

Leaver details

╳ Off

╳ Off

╳ Off

╳ Off

╳ Off

🖊️ Note:

In the Field-level permissions column, '✅ On' means extra restrictions apply to individual fields on that screen. The affected fields are listed under Default field-level permissions below.

Default field-level permissions

Contact details and Personal details carry field-level restrictions in the default Their Team group. Managers can open these screens, but only see the fields shown below.

Screen

Fields visible by default

Fields hidden by default

Contact details

Work phone

Personal phone, Personal email, Address details, Line 1, Line 2, Town, County, Country, Postcode, Notes

Personal details

Title, First name, Last name, Known as, Email address, Gender, Nationality

Date of birth, National insurance number

Edit is Off for all of these fields by default, including the fields that are visible.


Documents

The default Managers role has View access to the Documents screen for people in Their Team. This does not automatically give access to every personal document stored against those profiles — access to each personal document is also set when that document is added.


To Dos and event approvals

Managers have access to the To do screen for their team. What they can do with an individual To Do also depends on the type of task, who it is assigned to, and any underlying workflow, document, or event rule.

For example, when someone in their team books an event covered by an Event manager rule that has Request approval enabled, the manager receives an approval To Do. Where the rule does not require approval, no approval To Do is created.


Features

The same as Standard users — see Features above.


Custom actions

The same as Standard users — both custom actions are Off by default. See Custom actions above.


Default permissions: Manager with Indirect reports

Manager with Indirect reports has the same default Own profile, Features, and Custom actions settings as Standard users and Managers. The only default difference is the People scope.

This role is always assigned manually — no one is moved into it automatically.


Own profile

The same as Standard users and Managers — see Own profile above.


People — Their team including indirect reportee

The default People group is Their team including indirect reportee. It applies the manager’s People permissions to their direct and indirect reports, all the way down the reporting hierarchy.

The screen-level and field-level permissions are identical to Managers > Their Team, including the Contact details and Personal details field restrictions. The difference between the two roles is therefore who the permissions apply to, not what the permissions are. See People — Their team above

🖊️ Note:

These are the default People scopes. On plans with ARM, People groups and their filters can be changed, so a advanced-type role may end up covering a different set of people, with different permissions for each group.


Features and Custom actions

The same as Standard Users and Managers — see Features above.


Custom actions

The same as Standard users and Managers — both custom actions are Off by default. See Custom actions above.


Default permissions for Administrators

Administrators have full access throughout Sense HR.

This includes:

  • all employee profiles and profile data

  • personal and company documents

  • employee planners

  • Company Calendar

  • To Dos

  • Reports and reportable data

  • Settings

  • adding new employees

  • processing and undoing leavers

  • system configuration and permissions

  • Access Role Management where available

The Administrators role is fixed and cannot be edited, copied, or deleted.

Because it always provides full access, there is no configurable default permission set to restore.


Other default role behaviours

Some behaviour follows the user’s access role but is not represented by a permissions toggle in ARM.


Dashboard

The dashboard a user sees is determined automatically by their access role type, rather than the individual access role name.

Default access role

Access role type

Dashboard

Standard users

Standard

Employee Dashboard

Managers

Advanced

Manager Dashboard

Manager with Indirect reports

Advanced

Manager Dashboard

Administrators

Admin

Administrator Dashboard

🖊️ Note:

Custom access roles use the dashboard associated with their access role type. For example, a custom role with the Advanced type uses the Manager Dashboard.


Profile photos

  • Users can add or change their own profile photo.

  • Administrators can also add or change another user’s profile photo.

  • Manager-type access to another person’s profile does not give permission to change that person’s profile photo.


Restore or check default permissions using ARM

On Professional, Elite, and Enterprise plans, use this article as a reference when comparing a customised default role with its original configuration.

Go to:

HR Dashboard > Settings > Access roles > [Select role] > Permissions

Depending on the role, check:

  • Own profile

  • People

  • Features

  • Custom actions

  • any active field-level permissions for Own profile and People

⚠️ Important:

Changes to an access role apply to everyone assigned to that role. Check the full effect of a change before saving it.

💡 Tip:

Keep a test profile that you can assign to different access roles while checking or restoring permissions. This lets you confirm what the role can actually see and do before applying the configuration to real users.


FAQs

Click for answers to frequently asked questions

Q: Why can’t I view or change access role permissions on a Team plan?

A: The reason you can’t view or change access role permissions on a Team plan is that Access Role Management (ARM) is not included. The four default access roles still apply, and administrators can assign them to users, but their underlying permissions cannot be customised.


Q: Can I change someone’s access role on a Team plan?

A: Yes. Administrators can change someone’s access role on a Team plan by going to HR Dashboard > People > [Select profile] > More actions (…) > Assign access role, even though ARM itself is not available.


Q: Why does this article show permissions for features my organisation doesn’t have?

A: The reason this article may show permissions for features your organisation doesn’t have is that access role permissions and plan availability are separate. A permission has no effect while the corresponding feature is unavailable. If your organisation later upgrades to a plan that includes the feature, the existing permission setting will take effect.


Q: Why are my access role permissions different from the defaults shown in this article?

A: The reason your access role permissions may differ from the defaults shown here is that your organisation may have customised them using ARM. On Elite and Enterprise plans, you may also see additional screens, report types, or custom actions added through Screen Designer or Automate.


Q: What access role is assigned to a new user by default?

A: The access role assigned to a new user by default is Standard users. If your organisation uses ARM, make sure the permissions configured for Standard users provide a safe baseline for any newly added user.


Q: Why did someone automatically change from Standard users to Managers?

A: The reason someone may automatically change from Standard users to Managers is that they have been assigned as a Line Manager for another employee. If they are later removed as Line Manager for their last or only direct report, they automatically move back to Standard users.

🖊️ Note: Automatic role changes only apply between Standard users ↔ Managers.


Q: What is the difference between Managers and Manager with Indirect reports?

A: The default difference between Managers and Manager with Indirect reports is their people scope. Managers have access to their direct reports, while Manager with Indirect reports extends that access to direct and indirect reports in the downward reporting hierarchy. Their default screen and field-level permissions for those people are otherwise the same.

🖊️ Note: On plans with ARM, People groups can be customised, so the people a manager-type role can access may differ from these defaults.


Q: Why can a manager see the Documents screen but not every personal document in it?

A: The reason a manager can see the Documents screen but not every personal document is that screen access and document-level access work together. The default Managers role has View access to the Documents screen for their team, but access to individual personal documents is also determined by the permissions set when each document is added.


Q: Why can a manager see a screen but not every field on it?

A: The reason a manager may see a screen but not every field is that some screens have additional field-level permissions. For example, the default manager permissions allow access to the Contact details and Personal details screens for their team, while specific fields within those screens remain hidden.


Q: Why can someone see a Company Calendar event but not open that person’s profile?

A: The reason someone can see a Company Calendar event but not open that person’s profile is that Company Calendar visibility and profile access are separate permissions. Calendar visibility does not grant access to another employee’s profile.


Q: Why can a manager approve some event requests but not others?

A: The reason a manager may be able to approve some event requests but not others is that event approval is also controlled by the applicable rule in Settings > Calendar & Planner > Event manager. Where Request approval is enabled, an approval To Do is generated for the manager.


Q: Why doesn’t a user see a screen even though their access role has View permission?

A: The reason a user may not see a screen even though their access role has View permission is that, on Elite and Enterprise plans using Screen Designer, the screen must also be included in that person’s profile template. If it is not included, the screen will not appear.


Q: What determines which dashboard a user sees?

A: The dashboard a user sees is determined automatically by their access role type, rather than the individual role name. Standard roles use the Employee Dashboard, Advanced roles use the Manager Dashboard, and Admin roles use the Administrator Dashboard. This also applies to custom roles of those types.


Q: Does a manager’s access to another person’s profile allow them to change that person’s profile photo?

A: No. A manager’s access to another person’s profile does not allow them to change that person’s profile photo. Users can change their own profile photo, while administrators can also change profile photos for other users.


Q: Does an access role determine whether someone can use Sense Mobile?

A: No. An access role does not activate Sense Mobile access. Mobile access requires a verification code sent by an administrator or another user with the relevant permission. The functionality available after login also depends on the organisation’s setup and the user’s permissions.


Q: Does the Add own sickness permission control the Dashboard sickness widget?

A: No. Add own sickness does not control the Dashboard sickness widget. Add own sickness allows a user to record sickness directly in their own Planner. The Dashboard sickness widget is enabled separately under Settings > Calendar & Planner > General.

Did this answer your question?