Skip to main content

See what each role and permission gives access to in Workstream

Roles & permissions reference — see exactly which default role has access to each feature and setting in Workstream.

Every team member in Workstream is assigned a role, and that role determines what they can see and do — from managing job postings to processing payroll. This article breaks down exactly which permissions each default role includes, organized by feature area, so you can quickly check who has access to what.

📌 Access needed: To view or change role permissions, you need the Create and manage users permission. If you don't have access, contact your Super Admin.

💡 Looking to add a custom role or edit an existing one? See Add and edit roles and permissions. This article is a reference for what's included by default — not a how-to for making changes.


Account management

Permission

What it does

Included by default

Create and manage users

Add, edit, disable, and reactivate user accounts

Super Admin, District Manager

View sensitive applicant information (partial — last 4 of SSN)

See the last 4 digits of an applicant's SSN

Super Admin, District Manager, General Manager

View sensitive applicant information (full — background check, full SSN)

See an applicant's full SSN and background check details

Super Admin only

View, create, and edit all HR calendars

Manage interview and availability calendars company-wide

Super Admin, District Manager

Edit company info

Update career page branding, intro, industry, and FAQ; toggle Spanish hiring

Super Admin only

Edit evaluation plan

Turn the Evaluation Plan on or off and edit its criteria

Super Admin, District Manager

Create and edit integrations

Connect and configure third-party integrations

Super Admin only

Manage API

Create and manage API access tokens

Super Admin only

Manage locations

Add and edit locations and their tax entities

Super Admin only

Manage departments

Add and edit departments

Super Admin only

Customize notifications

Set up notifications for specific job postings

Super Admin, District Manager

Create and edit custom reports

Build and manage custom reports

Super Admin only

Create and edit custom fields

Add and delete custom fields

Super Admin only


Job posting management

Permission

What it does

Included by default

Create and edit job postings

Add or edit job posting details

Super Admin only

Delete job postings

Remove a job posting entirely

Super Admin only

Publish and unpublish job postings

Control whether a posting is live

Super Admin only

Access sponsored job boards

Sponsor a job posting on paid boards

Super Admin, District Manager, General Manager

Create and edit templates

Build reusable position and hiring-process templates

Super Admin only

⚠️ Sponsored job boards require the Publish and unpublish job postings permission as well — a role can't sponsor a posting it can't publish.


Applicant management

Permission

What it does

Included by default

Create and edit applicant feedback

Add and edit applicant scores

All users

Create and edit applicant notes

Add internal notes on an applicant's profile

All users

Send texts and emails to applicants

Message applicants directly

All users


Team management

Permission

What it does

Included by default

Onboard new hires / edit onboarding processes and documents / manually mark modules complete

Start onboarding for new hires, edit onboarding processes and documents, and mark modules complete manually

Super Admin, District Manager, General Manager

View sensitive worker information (partial — last 4 of SSN, direct deposit)

See a team member's last 4 of SSN and direct deposit info

Super Admin, District Manager, General Manager

View sensitive worker information (full — SSN, DOB, direct deposit)

See a team member's full SSN, date of birth, and direct deposit info

Super Admin, District Manager, General Manager

Import and delete workers

Bulk import team members or delete a team member record

Super Admin, District Manager, General Manager

Edit worker records

Edit a team member's profile information

Super Admin, District Manager, General Manager

Add and configure company documents

Upload and set up document templates

Super Admin, District Manager, General Manager

Assign company documents to active team members

Assign uploaded documents to active team members for completion

Super Admin only

📌 Location and department visibility: Super Admins always see every team member. Every other role defaults to Limited Visibility — team members outside their own location and department are hidden from the Team tab. Turning on Full Visibility for a role lets that role see everyone, though for unassigned locations/departments they'll only see basic details (name, date of birth, contact info).


Payroll management

Permission

What it does

Included by default

Configure Payroll

Set up tax entities and enroll the company for payroll

Super Admin only

Manage Payroll Operations

Access the payroll portal — run payroll, view payroll documents, download reports

Super Admin only

Access to Payroll entities

Assign specific users to specific payroll entities, so different people can manage payroll for different entities

Super Admin only

💡 For the full walkthrough on assigning these, see Assign Payroll setup and management permissions. For giving a manager scoped access to just their direct reports' pay, see Assign managerial permissions to users.


Surveys

Permission

What it does

Included by default

Create and send surveys

Build and assign surveys to the team

Super Admin only

View and download survey results

Access and export survey results

Super Admin, District Manager, General Manager


Data export

Permission

What it does

Included by default

Manage data export templates

Create export templates

Super Admin only

Manage data export files

Access exported data files

Super Admin only


FAQ

Can I change what a role has access to?

Yes. These are the defaults for Workstream's built-in roles. A Super Admin can edit any role's permissions, or create a fully custom role. See Add and edit roles and permissions for steps.

Why can't I see the "Assign company documents" option even though I'm a General Manager?

That permission isn't included in the General Manager default — only Super Admin has it out of the box. A Super Admin can add it to your role if needed.

Does the Assistant Manager role have any Team management or Payroll access?

Not by default. Assistant Manager is scoped to applicant management only (feedback, notes, and messaging applicants).

Did this answer your question?