Security Groups provide a framework to manage permissions for an organization. Security groups allow you to configure and assign permissions based on users or roles. In this article, we dive into what Security Groups are and what permissions are.
In this article:
What are Security Groups
Security Groups Definitions
How do Security Groups work
Security Groups F.A.Q.
Additional Resources
What are Security Groups
Permissions are managed through Security Groups. These Groups can have individual users or roles associated and automatically confer the associated permissions to all Roles and Employees.
Benefits
- Create a structured but customizable permission framework that scales with your organization.
- Maintain control over permission distribution through the definition of security groups with the appropriate permissions for your organization.
- Simplify permissions management with automatic permission provisioning.
- Provide greater control over who can see defined segments of employee and candidate profiles.
- Align your data access rights with your organization’s structure. This is particularly valuable for orgs that need to restrict access by region, business unit, or division.
Option Definitions
- User Admin: This permission grants the individual access to add/edit User Profiles and reset passwords. This user will also have access to several pages within the Setup area.
- Roles Admin: This permission primarily grants the ability to create and manage company Roles (when combined with the User Admin permission). This user can also modify the Company Mission & Vision and modify the details of Roles by creating role-based Requisition Templates and managing the associated role Competencies, Goals, and Hiring Workflow.
- Workforce Planning Module: This permission type will grant access to our Workforce Planning module.
- HR Admin: This permission grants visibility into employees' compensation information, hiring files, and employment history.
- IT Admin: This permission grants the ability to set up connected apps in World of Work, enable Celebrations, Two-Factor Authentication, Bulk Calendar Connect, and access Devices and Equipment.
- Security Group Admin: This permission grants management and actions within the Security Groups tool.
- Employee: The general access user permission that is assigned by default to all newly created users (unless it is a 3rd-party Vendor recruiter user) is Employee. Employees cannot access the Tools menu for backend settings but will be able to view existing Roles and their corresponding Competencies.
- Task Assignee: This permission is considered the tasks-only Onboarding user. This user has access to the My Tasks tab and can be assigned to approve tasks or complete internally assigned tasks. A Task Assignee does not have access to view in-progress or completed onboarding packets.
- Goal Alignment: This permission grants an individual the ability to create and manage Goals for themselves and provides access to the Org Chart, Company Vision, and search for Colleagues based on the company directory. If a user with this permission has direct reports, this user can edit the direct report's goals and provide goal feedback or private notes.
- Performance Management: This permission grants an individual access to participate in reviews to which they have been assigned. This user will not be able to view or manage the overall review cycles or performance-related settings. This is the permission that should be granted to all employees of organizations utilizing the Performance Module.
- Recruiter: This permission is considered the all-access Recruiting user, granting an individual access to view all Candidates* across all Requisitions created (*unless your organization utilizes Data Walls). They can also create/post requisitions without an approval process, and approve new requisition requests from hiring managers. This user will have the additional ability to edit Applications, Scorecards, Email Templates, and other recruiting setup items, as well as gain access to the Reporting & Analytics platform.
- Hiring Manager: This permission is considered the "restricted access" Recruiting user. This user will only be able to view candidates in requisitions they have access to and require approval from a Recruiter when creating a requisition. Requisitions they have access to include: requisitions they are assigned to as the Primary Hiring Manager, requisitions they have been assigned to as part of the Hiring Team, or requisitions their subordinates have created.
- Offer Letter Admin: This permission grants an individual the ability to manage Offer Letter Templates and view all historically sent candidate offer letters* (*when combined with a Recruiter or Hiring Manager permission).
- Offer Letter Sender: This permission grants an individual the ability to send and view Offer Letters to Candidates they have access to* (*when combined with a Recruiter or Hiring Manager permission). This user will not have access to the setup or management of offer letter templates.
- Background Check: This permission grants an individual access to initiate and view the results of a candidate's Background Check. This permission requires a ClearCompany Background Check Partner to be integrated with your account. Please contact your ClearCompany Representative to learn about available partners and pricing/enablement details. Don't have a background check provider, check out Background Checks by ClearCompany.
- Assessment Tests: This permission grants an individual access to initiate and view the results for a candidate's Assessment Test. This permission requires a ClearCompany Assessment Test Partner to be integrated with your account. Please contact your ClearCompany Representative to learn about available partners and pricing/enablement details.
- Talent Sourcing: This permission grants an individual access to the External Sourcing feature to passively search potential candidates across professional social media sites.
- Onboarding Coordinator: This permission is considered the all-access Onboarding user. This individual can send, edit, and have access to all in-progress and completed Onboarding Packets and Completed Documents. This user can also manage items within Onboarding Setup*, including New Hire Packet Templates, Onboarding Email Templates, and the Document Library (*when combined with the User Admin permission). Depending on how your organization utilizes Onboarding Data Walls.
- Performance Admin: This permission grants an individual access to launch and manage performance review cycles, workflows, and performance-related setup and settings. This user can also view all reviews at any stage of completion. Depending on how your organization utilizes Onboarding Data Walls.
- Survey Admin: This permission gives the ability to launch, and manage survey cycles and provides access to the survey setup resources.
- Goals Admin: This permission grants an individual the ability to oversee and manage all Goals in the system (including private and otherwise restricted Goals) and modify Goal Settings.
- Performance Reporting: This permission grants an individual access to the Performance tab within the Reporting & Analytics center. This user will not be able to view or manage Review Cycles or performance-related setup items.
Other Permissions
-
CEO: The CEO "permission" will live on the Edit User page as a designation for an employee. To change the CEO designation, a User Admin will have to select a new CEO (can't be removed from an employee). Preventing the removal of the CEO helps protect against issues with the hierarchy.
-
Vendor: The Vendor "permission" will live on the Edit User page as a designation on an employee If added to an employee, they will immediately lose all membership in any Security Group and can't be added to any Security Group until the Vendor designation has been removed.
How do Security Groups work
- A default set of Security Groups will exist in a newly provisioned organization. They can be edited or deleted. The default groups are below.
- Employees or Roles can be assigned and unassigned as members of a security group:
- Employees with an associated role in the Security Group will receive all permissions associated with the Security Group.
- Changes to permissions in the Security Group will automatically be applied to all Employees and Employees with an associated role in the Security Group.
- Employees can be added in bulk to a security group by applying filters based upon Department, Role, or Office (Logic works as an "OR" between multiple select values within the same attribute and as an "AND" between different attributes (e.g. "(Sales Department OR Marketing Department) Employees AND in San Francisco").
- A Security Group can be defined for the "Company" and that will confirm the selected permissions to all employees of the company (except those that are members of a "Vendor" designated Security Group.
- Management/Actions within the Security Group Dashboard can be done by a user with the Security Group Admin permission.
- Roles can be added in bulk to a Security Group through multiple checkboxes (or search).
- Role membership in a Security Group can be managed from the Role Management Dashboard (as well as the Security Group Dashboard).
- This can be done by a user with the Role Admin permission.
- A "Permission Check" can be performed on a role so a user can see what permissions the role currently has, will receive, and will lose following changes to associated Security Groups.
Default Security Groups
Below are the default security groups that are in the system.
- Employee
- Goal Alignment
- Performance Management
- Recruiter
- User Admin
- Offer Letter Admin
- Offer Letter Sender
- Background Check
- Assessment Tests
- Onboard Coordinator
- Performance Admin
- Survey Admin
- Goals Admin
- IT Admin
- Task Assignee
- HR Admin
- User Admin
- Roles Admin
- Security Group Admin
- Hiring Manager
Security Groups F.A.Q.
When a new hire is assigned a role with an assigned Security Group during the onboarding process, the new hire will automatically receive the permissions listed under that security group.
In addition, a security group can be assigned to the Company role, which will give each user the assigned permissions from that security group.
Yes! A "Permission Check" can be performed on a role so a user can see what permissions the role currently has, will receive, and will lose following changes to associated Security Groups.
Security groups are used to assign a set of permissions, the permissions are a set of actions that a user can take. For example, a security group of "Recruiter" can have permissions to create and post requisitions. If you are interested in limiting the data that a user has access to, you will want to implement Data Walls.
We recommend the below:
- Assign security groups to roles, so any new user or existing users with the role will get the permissions aligned with that role.
- Assign a security group to the Company role, when doing so, any new users created in the system will get the permissions assigned to this role. To assign a security group to a company role, navigate to Tools> Setup> Roles/Departments/Roles and select the Company role at the top-left-hand side.
Comments
Please sign in to leave a comment.