What this does
Access in WorkRight is decided by two things working together: your role (what kind of user you are) and your plan (which modules your company has). A payroll admin sees payroll; a regular employee sees their own leave and payslips and not much else. Sensitive accounts are protected by two-factor authentication (2FA). This guide explains each piece so you can give people exactly the access they need.
The built-in roles
Every member has one base role from a fixed list. From least to most access:
- Employee (
employee) — the default. Sees their own profile, leave, payslips, expenses and any training assigned to them. - ICC member (
icc_member) — an Internal Committee member for POSH. Can view and act on the complaints assigned to the committee, on top of their employee access. - Manager (
manager) — approves their team's leave and expenses and sees their direct reports. - HR manager (
hr_manager) — runs the HR side of the company: people, payroll, leave policy, documents and most settings. - Company admin (
company_admin) — the top role inside a company, with full administrative access including billing.
We refer to company_admin and hr_manager together as HR admins — most setup and administrative screens are theirs. For safety, you can never invent a higher role for someone than the system allows; roles always come from this fixed list.
How your plan decides what appears
On top of roles, what shows up in the sidebar depends on your plan's features. If a module — say Expenses or Performance — isn't on your plan, it's simply hiddenfrom the sidebar; nothing is broken, the menu item just isn't there. During your free trial every module is unlocked, so the sidebar is at its fullest while you explore. To change which modules you have, visit pricing or your Settings → Billing page.
Custom roles — when the built-in ones aren't enough
Need something narrower, like a “Payroll Operator” who can run payroll but not touch hiring? HR admins can build custom roles under Settings → Roles & permissions. A key rule: custom roles only addcapabilities on top of a member's base role — they never take access away. You can only grant capabilities you hold yourself, and a few high-risk capabilities require you to enter a 2FA code when you assign them.
Two-factor authentication (2FA)
WorkRight uses app-based TOTP two-factor — the six-digit codes from an authenticator app like Google Authenticator, Authy or 1Password. Whether 2FA is optional or required depends on the role:
- Mandatory for
super_adminandhr_manager— these accounts can reach the most sensitive data, so 2FA is required, not optional. - Optional but recommended for everyone else (employees, managers, ICC members and company admins). You can — and should — turn it on.
If your role makes 2FA mandatory and you haven't set it up yet, WorkRight blocks youuntil you enrol — you're sent to the 2FA setup screen and can't use the rest of the app first. This is by design: it's what keeps payroll, POSH complaints and other sensitive records safe.
Some especially sensitive actions ask for a fresh step-up2FA code even after you're signed in — for example locking a payroll run, granting a high-risk capability, or acting on an ICC complaint.
Steps — turning on 2FA
- Open your account / security settings and choose to set up two-factor authentication. (If your role requires it, WorkRight takes you here automatically on sign-in.)
- Scan the displayed QR code with your authenticator app, or type the secret in manually.
- Enter the six-digit code your app shows to confirm and finish enrolment.
- Save your recovery details somewhere safe so you don't lose access if you change phones.
Tips
- Give people the lowestrole that lets them do their job, then add a custom role if they need a little extra — it's safer than over-promoting someone to HR manager.
- Encourage everyemployee to turn on 2FA, even when it isn't mandatory for their role.
- Custom roles add capabilities; they never remove access a base role already grants — keep that in mind when designing them.
- Security is always re-checked on the server, so a person can't get around their role just by poking at the interface.
Related
- Set up your WorkRight workspace — the first-run setup steps.
- Add or onboard an employee — invite people and assign their role.
- Plans & pricing — which plan unlocks which modules.
- HR software for India — how access control fits the bigger picture.