RWE Read + Write + Edit (full) RW Read + Write (no destructive edit) R Read only Y Action allowed scoped Limited to own scope - No access

Visibility and Permissions role x resource

Who can see and do what across HR. Cells: RWE read/write/edit, RW read+write, R read only, tick action, dash none. Cells marked * mean scoped to own dept / team / self.

0 selected
Role Own profile Own team Own dept All employees Salary (any) Documents (any) Vacancies Candidates Convert candidate Approve vacancy Org structure Finance
C
CEO
Rahul Yadav
RWE RWE RWE RWE R RWE RWE RWE Y Y RWE RWE
D
Director
Veena Yadav
RWE RWE RWE RWE R RWE RWE RWE Y Y RWE R
C
CFO
Sonika
RWE RWE RWE R RWE R - - - - R RWE
H
HR Manager
Reena Sharma
RWE RWE RWE RWE RWE RWE RWE RWE Y Y RW -
H
HR Associate
Pooja
RWE RWE R R R* RWE RW RWE - - - -
D
Dept Manager
Akash Kumar
RWE RWE RWE R* R* R RW RW - - - -
T
Team Lead
(open)
RWE RWE R R* - - - - - - - -
S
Sr Associate
(85 employees)
RWE R R* - - - - - - - - -
A
Associate
(85 employees)
RWE R R* - - - - - - - - -
T
Trainee
(85 employees)
RWE R* - - - - - - - - - -
C
Candidate
(secure link)
R* - - - - (self) - (self) - - - -
Salary eye-reveal (HR-14)

Salary fields are masked by default on every screen. Eye-icon click triggers OTP / password re-auth. Audit-logged on every reveal. CFO and HR Manager are the only roles where reveal is one-click; everyone else gets re-auth.

Permission constants

Convention Dcrayons.Hr.<Aggregate>.<Action>. 14 permissions defined in Stage 4 contract. Pages gate destructive actions with abp-if-granted; lists filter rows server-side via the granted scope.