Before creating a single role, you need Illizeo’s grammar. Four concepts are enough: the role, the permission code, the tier and the scope.
The four concepts #
| Concept | What it decides |
|---|---|
| The role | What carries the rights. An employee can hold several; rights add up. |
| The permission code | The capability itself. The catalogue holds close to 700, across 23 menus, plus the field-level rights derived from your profile sections. |
| The tier | How far the right goes. Two cumulative scales: for a feature, Access < Execute < Admin; for a field, View < Edit < Insert < Delete < History. |
| The scope | Over whom. Yourself, your team, everyone, or a custom population — with exclusions available. |
An authorisation therefore always reads as a combination: actor × target × section × action. Which is why “may edit an absence” means nothing until you say whose absence.
Standard roles shipped #
-
Start from the roles you are given #
Eleven roles are provisioned when your workspace is created: All employees, Manager, Additional manager, Custom Manager, Second Manager, Matrix Manager, HR Manager, Payroll Manager, Accounting, Auditor, Administrator. Only Administrator carries the admin flag.
-
Understand the default scopes #
“All employees” covers each person over their own data. Manager resolves to the people they manage, HR Manager to the HR population. These defaults are a starting point; you change them.
-
Adjust in the matrix #
Roles & permissions shows the catalogue menu by menu. You tick a code and its tier for each role. Your decisions are never overwritten by an Illizeo update: provisioning does not touch rights already set.
-
Use a temporary role when it is time-boxed #
A role can carry a start date and an end date. It stops having effect on its own after the end date — no scheduled job, no manual deactivation — and takes effect again if you extend the date. The time box belongs to the role, not to the assignment: to cover one person, create a dedicated temporary role rather than dating the assignment.
FAQ #
Can an employee hold several roles?
Yes, and rights are unioned: one role granting a capability is enough for them to have it.
What happens if a temporary role has no end date?
It has no effect. The rule is fail-closed: without an end date, a role marked temporary takes part in no authorisation decision.
Can an admin-only capability be given to a specific role?
Often yes: many of those powers have their own code in the catalogue. For example, approving an absence directly without going through the approval flow is a named right you can tick for a role — and even with it, nobody can self-approve their own request.
Are field rights set in the same place?
They appear in the same matrix, but they do not come from the catalogue: they are derived from your employee profile sections. Their maximum tier depends on the section type — only a history-tracked section opens the History tier.
How do we avoid over-granting?
Review the matrix role by role rather than employee by employee, and prefer a narrow scope over a high tier: Admin over your team is less exposed than Access over everyone.
What does not exist #
There is no “rights per user” report: reading is done by role, in the matrix. There is no inheritance between roles either — a role does not derive from another, each carries its own ticks.
