EN

United States (EN)

Australia (EN)

Canada (EN)

Canada (FR)

France (FR)

Germany (DE)

Ireland (EN)

United Kingdom (EN)

EN

United States (EN)

Australia (EN)

Canada (EN)

Canada (FR)

France (FR)

Germany (DE)

Ireland (EN)

United Kingdom (EN)

Blog

Introducing role-based permissions: Get complete control over the data and apps that your team can manage

Author

Published

January 12, 2022

Updated

May 30, 2024

Read time

4 MIN

seo_image_fa17d26f_aBAMAKUq0

Ensuring you have the right permissions governing data and systems access for your employees is critical to building a secure and high-performing organization. 

But, maintaining those permissions is a hard, and manual, task in most software systems.

You promote each user to admin status, in each system, one at a time. And when someone leaves, or their role changes in a way that requires that their permissions change, you have to make those updates manually as well. 

This gets harder to manage when admin permissions aren’t binary, and require you to specify the scope of someone’s authority. For example, you might be an admin, but only for a certain part of the organization. Or you can make changes, but others need to sign off on them to take effect. 

In systems where “approval” is required—whether it’s for a raise, an expense reimbursement, a new computer, or access to a system—that approval is always implicitly about “role” and each employee’s organizational “relationship” to others in the company. For example, you might need approval from your manager, your HR Business Partner, the VP of your department—but who each of these people are will change and evolve as your role within the company changes.

As your team grows, so does the effort required to maintain these permissions, and it’s inevitable that people won’t have the permissions they’re supposed to have.

That’s why we’re excited to introduce our latest feature: role-based permissions—a new, better way to manage permissions across your company, built on top of Rippling’s game-changing employee graph.

Role-based permissions: a better way to control employee access  

Role-based permissions let you ‘set and forget’ your policies for admin access, approvals, and change management—all from one place. 

You select the criteria that govern:

  • which employees get admin access to your systems based on high-level employee attributes (e.g. their department, level, team memberships, location, etc.)

  • the subset of the organization their permissions apply to (e.g. only their department or direct reports)

  • the types of data they can access and actions they can take (both in Rippling and your integrated business systems)

  • when additional approval is required for attempted changes, and from whom (e.g. ‘their HR Business Partner’ or ‘their department’s VP').

For example, you could create a ‘Support Managers’ permission profile that applies only to Support managers Level 6 and above, and lets them access information only for their direct reports. 

From there, Rippling identifies which employees match your criteria, and automatically grants them the right permissions.

Permissions_inline-detail-1_v1
Permissions_inline-detail-2_v1
Permissions_inline-detail-3_v1-1

Because every manager's LMS results are housed in the Employee Graph, Rippling is able to identify which managers satisfy those conditions, and Rippling assigns those advanced permissions automatically.

And unlike other platforms, Rippling’s role-based permissions extend across the entire Rippling suite (e.g. Payroll and Time & Attendance) as well your third-party integrations (e.g. Jira and Zoom). 

For example, you can allow Sales Managers to manage access to key apps like Gong and Zoom for their direct reports, view their sensitive employment-related information (e.g. compensation), and terminate their employment—all within a single permission profile.  

Take the pain out of permissions management

Setting up admin profiles for new hires, and updating those permissions when responsibilities change, is manual work that takes time away from your more pressing responsibilities. 

But as we mentioned above, with role-based permissions, you only need to set up your permissions profile once, and Rippling takes on the busywork of assigning and removing permissions based on the parameters you set. 

Permissions_inline-detail-4_v1
Permissions_inline-detail-5_v1
Permissions_inline-detail-6_v1

When setting up the approvals process in your permissions profile, you’ll be able to define: 

  • who the approval requests should be routed to

  • whether approval is needed from just one or multiple approvers

  • whether a single or multi-step approval process is needed (e.g. the decision needs to be approved by both the employee’s manager, and the manager’s manager as well)

And because you can assign approvers based on the title they hold rather than their individual name (e.g. 'VP of Employee’s Department' vs. ‘Daniel Cornfield’) you don’t have to worry about updating your permissions if the person holding that role later changes.

It also means that your permissions profile can apply equally to someone in Sales or Marketing without issue—in the former situation, the approval request will go to the VP of Sales, while in the latter, it would go to your VP of Marketing instead. Which means you have the flexibility to assign permission profiles across teams and departments as well. 

Permissions_inline-detail-7_v2

Disclaimer

Rippling and its affiliates do not provide tax, accounting, or legal advice. This material has been prepared for informational purposes only, and is not intended to provide or be relied on for tax, accounting, or legal advice. You should consult your own tax, accounting, and legal advisors before engaging in any related activities or transactions.

Author

Steven Cipolla

Software Engineer, Permissions

Explore more

seo_image_ef118b91_aBAMAKUq0
Aug 21, 2025
|
11 MIN

Role-based access control (RBAC): What it is, benefits, and examples

Discover what role-based access control (RBAC) is and its benefits for your company's security. Learn examples and best practices for implementation.

seo_image_10a4a6d1_aBAMAKUq0
Aug 21, 2025
|
6 MIN

Introducing IT Management: Complete visibility and control over all things IT

Finally, a purpose-built view just for IT to manage onboarding, offboarding, and other IT services. Get visibility and control over IT tasks and HR collaboration.

seo_image_31a18f3f_aBAMAKUq0
Aug 21, 2025
|
3 MIN

Introducing configurable profiles: Customize Rippling to meet your business needs

Rippling’s newest feature, configurable profiles, lets you customize Rippling so you can empower your employees with the data they need

seo_image_d3eb124c_aBAMAKUq0
Aug 21, 2025
|
10 MIN

A guide to attribute-based access control (ABAC)

Attribute-based access control (ABAC) offers a robust solution for controlling data access. Learn what it is, how it works, and its benefits.

seo_image_e3f3341d_aBAMAKUq0
Aug 21, 2025
|
2 MIN

Introducing Rippling + Employee Navigator: More flexibility and control over benefits administration

Employee Navigator and Rippling are partnering to give you even more flexibility over your benefits administration.

seo_image_6272dd9d_aBAMAKUq0
Aug 21, 2025
|
3 MIN

Introducing Rippling Business Partners

Introducing Rippling Business Partners: Discover how we’re empowering businesses with tailored solutions and expert support.

seo_image_54f7dc3c_aBAMAKUq0
Aug 21, 2025
|
7 MIN

Introducing Rippling Bill Pay

Discover how Rippling Bill Pay lets you consolidate, automate, and control your business spend from one platform. Simplify your bill payment process today.

Graphic illustration of a ripple pattern formed with converging lines
Aug 21, 2025
|
6 MIN

How a PEO can help you manage a remote team

Learn what a PEO is and how a professional employer organization will help you manage remote employees.

See Rippling in action

Increase savings, automate busy work, and make better decisions by managing HR, IT, and Finance in one place.