A role controls both what someone can do and whose records they can see. Give people the access their work needs, then check that boundary from their profile.
Only someone with permission to manage permissions can change roles in Settings → Permissions.
Administrator has this access by default.
Choose a starting role
To change someone’s role, open their profile, choose Edit, select Role and save. Existing roles may have been customised, so check the actual settings before relying on the defaults above.
Adjust a role
Open Settings → Permissions. Use Add role to copy an existing role, then change its permission toggles. Search the grid to find a permission. Changes apply to everyone holding that role. Administrator permissions are read-only; Manager and Employee can be changed. Use the role’s menu to Rename or Archive it. Move everyone off a role before archiving it; an archived role can no longer be given to anyone. Pay and private details have separate read and edit controls: View pay data, Edit pay data, View private details and Edit private details. Permission to edit people does not grant permission to see their salary or banking information, and Deactivate & reactivate is its own toggle. Every role also has Edit own personal information, Edit own contact information and Edit own banking information, on by default, which decide what people can change on their own My profile page. A custom role also inherits invitation permission from the role you copy. Invitations have no separate toggle in this grid, so choose the source role with that access in mind.

Limit whose records they see
Use Who can they see? to restrict a role to direct reports, people below them in the reporting tree (up to five levels), their locations or departments, or selected locations and departments. Rules add together: matching any rule includes the person. This boundary applies across people data, pay, timesheets, schedules, approval requests, reports and search. It does not change chat access. When you pick their locations or their departments, the boundary follows that person’s own assignments. So they cannot add a location or department to themselves that the role does not already reach: doing so would widen what they see. An administrator makes that change instead. Anything the role already covers, including a site or department named by a fixed rule beside it, they can still assign themselves, and they can always remove one of their own. Open a person’s Overview → Who they can see to inspect the result. This preview is available to people who manage permissions.Transfer ownership separately
The workspace owner can use Transfer ownership from the target person’s menu. The recipient must hold a role that administers the workspace. Assigning the Administrator role by itself does not transfer ownership.You cannot deactivate or delete the workspace owner. Transfer ownership first if that person is
leaving.
Next
Member profiles
Check the details available to your role.
Deactivating and removing people
Take access away when someone leaves.
Still need help?
Contact support
Email the Begin team and we’ll get back to you.
Ask Begin AI
Open the AI assistant and get instant answers based on these docs.