Skip to main content

Role Permissions

Payroll → Administration → Role Permissions (/role-permissions) — decide what each role can do in Payroll. Requires payroll:admin.

Payroll Role Permissions pagePayroll Role Permissions page
Payroll Role Permissions — matrix

The permission matrix​

  1. Pick a role with the Change selector (roles come from Zitadel / your IdP — e.g. PAYROLL_ADMIN, PAYROLL_VIEWER, FINANCE).
  2. Toggle individual permissions on/off. Permissions are grouped (Masters, Employees, Pay Runs, Statutory, Payslips, Loans) with a coverage bar per group; each carries a READ or MANAGE / PII / MASTER / APPROVE / ADMIN scope badge (payroll:read, payroll:master, payroll:manage, payroll:pii, payroll:approve, payroll:admin).
  3. Use All / Granted / Restricted filter or search to find a permission.
  4. Click Save Permissions. Changes apply on next page load (useMyPermissions cache).

Reset discards unsaved edits; Clear all removes every grant from the role (before saving).

Payroll permissions at a glance​

PermissionUnlocks
payroll:readAll read views (dashboard, masters, employees, runs, statutory, payslips, loans)
payroll:masterCreate/edit Pay Components, Salary Structures, Pay Groups, GL Mappings, Statutory configs
payroll:manageCreate runs, revisions, adjustments, loans; send payslips
payroll:piiView/edit tax declarations (amounts + regime drive TDS)
payroll:approveApprove/reject reimbursements
payroll:adminThis page + Configuration

Guidelines​

  • Follow least privilege: grant payroll:read before payroll:master/manage, treat payroll:pii and payroll:admin as sensitive.
  • The full list and what each unlocks is summarized in the Payroll Overview.
  • Permission changes are recorded in the Activity Logs.