ChartHop for Administrators
...
Access
User access controls

Built-in Roles

a user’s access role within charthop determines what data they can see within the org and what actions they can take within charthop access roles are the broadest way to grant employees access to charthop for example, users with the owner role can create new surveys, while users with the employee role can only take surveys and cannot create them users in your organization with the recruiter editor role can create new jobs in charthop each role includes the permission of standard access, which means access to the non administrative features of charthop, including shared scenarios for review purposes administrative tasks, such as creating new surveys or importing employee data, are restricted to those with advanced access, such as an org editor, owner, or technical owner role assigning access roles to the members of your organization should be a thoughtful process and follow the principle of granting users only the permissions they need and no more than that for several roles within your organization, including members of hr, recruiting, finance, it, and more, additional access may be appropriate, depending on your organization's needs for roles with access to sensitive data such as personal information for employees, you can further filter what data those that role can see for example, you can assign the org editor role to multiple people in your organization but filter each person to have those permissions only in their department or division charthop basic provides two access roles to assign to employees in your organization owner and employee non employees cannot be allowed access the following table gives a general overview of each role select the role name to view more specific details on pages and data that the role can access role description employee docid\ fwpttlc790dmvlt3xk915 allowed to see their own personal information and the compensation data of anyone in their reporting line this is the default access level appropriate for most organization members cash compensation viewer the same access as an employee but can see cash compensation data, including cash compensation for individuals outside their reporting line compensation viewer same as an employee but can see all compensation data, including both cash and equity employee (no comp data) the same access as an employee but without permission to view compensation data for those in their reporting line equity compensation viewer the same access as an employee but can see all equity compensation data, including equity compensation for individuals outside their reporting line guest can view org public data recommended for users outside the organization users who are org members can also see their own personal data but not the sensitive data of individuals in their reporting line org editor access to all sensitive data, including compensation, with the ability to edit and make permanent changes to the primary environment does not have admin capabilities such as the ability to install applications or change organization wide settings owner allowed full, unrestricted access to everything , including inviting new users and assigning roles can configure integrations and manage organization wide settings because of the unrestricted nature of this role, this access role should be used very sparingly people ops admin docid\ o6czgwxjekfaefkwz1l6b access to all sensitive data including compensation, with the ability to edit and make permanent changes to the primary environment has the ability to configure and manage fields, forms, categories, profile tabs, and actions, among others does not have the ability to change user permissions, configure integrations, or alter organization wide settings for most organizations, this role should be the most commonly used administrator role people ops admin (no comp data) docid\ xxw0l5uxlyl qshsamtbm same as people ops admin, but without access to compensation data access to all sensitive data, except for compensation related data has the ability to edit and make permanent changes to the primary environment, and has the ability to configure and manage fields, forms, categories, profile tabs, and actions, among others does not have the ability to change user permissions, configure integrations, or alter organization wide settings people ops admin (no sensitive data) docid\ xozkhw57nzvossnsh wmt same as people ops admin, but without access to sensitive data access to manage configuration and workflows, without direct access to any sensitive data including compensation has the ability to configure and manage fields, forms, categories, profile tabs, and actions, among others does not have the ability to change user permissions, configure integrations, or alter organization wide settings recruiter same as an employee and can view open jobs and the sensitive data associated with those jobs, including target compensation cannot merge scenarios but can create view scenarios shared with them recruiting editor same as employee but can create open jobs in the primary timeline as well as in scenarios allowed to view and edit sensitive information about open jobs, including target compensation levels and other sensitive data sensitive data (limited comp) same as an employee but can also see all sensitive data except compensation for those outside their reporting line sensitive data viewer docid\ dhlprvo0eywcoaofqn2k2 same as an employee but can also see all sensitive data, including for those outside of their reporting line technical owner allowed to create and invite new users as well as assign user roles can configure apps and integrations, update custom fields, and alter organization wide settings however, they do not receive direct access to sensitive people data in the application because of the ability to configure data access and api keys, a technical owner could indirectly establish access to sensitive data (although such activity would be auditable) this role should be granted with care to the appropriate it staff the following roles are deprecated time off viewer personal contact viewer access remains unchanged for users who have already been assigned these roles you cannot assign new users these roles packages basic basic | | headcount planning headcount planning | compensation reviews compensation reviews | performance performance | engagement engagement | hris