7.5 Employee Central Permissions for Administrators
Key Takeaways
- Employee Central permissions are split between effective-dated entities and non-effective-dated Employee Data.
- Block actions View Current, View History, Edit/Insert, Correct, and Delete control effective-dated cards and their History buttons.
- Create, correct, and delete actions in the History UI do not trigger workflows, even if workflow derivation rules exist.
- Employment Information is the only non-effective-dated entity that supports field-level permissions.
- Manage Foundation Object Types covers XML-based corporate data, and MDF Foundation Objects covers MDF-based corporate data.
7.5 Employee Central Permissions for Administrators
Quick Answer: EC permissions are split into Employee Central Effective Dated Entities (history-based blocks such as Job Information) and Employee Data (non-effective-dated items). Effective-dated cards use block actions: View Current, View History, Edit/Insert, Correct, and Delete. The Edit Link permission controls the pencil icon. Separate permission categories cover imports and foundation objects.
Permissions THR81 Covers
- Employee Central Effective Dated Entities
- Employee Data
- Employee Central Import Entities
- Manage Foundation Object Types
- Manage Foundation Objects
- MDF Foundation Objects
When granting permissions, consider category, card, and field levels. People Profile categories are also controlled in RBP. A user needs the category and at least one card in it (Section 4.1).
Employee Central Effective Dated Entities
This category covers elements and fields that track historical and future changes. It becomes available once the Succession Data Models are uploaded. Standard effective-dated entities include personalInfo, homeAddress, personRelationshipInfo (Dependents), jobInfo, compInfo, and jobRelationsInfo.
Block Actions
| Permission | Effect on the card |
|---|---|
| View Current | Makes the card visible in the profile category |
| View History | Shows the clock icon and opens the history window |
| Edit/Insert | Enables Create in the history window |
| Correct | Enables Correct in the history window |
| Delete | Enables Delete in the history window |
Important: the create, correct, and delete actions in History do not trigger workflows, even if workflow derivation rules are implemented. That is why History access is normally reserved for HR administrators (Section 9.4).
The Edit Link
The Edit Link permission controls whether the pencil icon is available on the card. Only its Edit/Insert level matters; the other levels are ignored. With it, users open and edit the card to start a transaction in People Profile, which can trigger event reason derivation and workflows. Edits can also be started from the People Profile Actions menu when the Update Employment Records permission is granted.
Field-Level Permissions
| Level | Meaning |
|---|---|
| View Current | See the field's current value |
| View History | See historical values in the block's History view |
| Edit/Insert | Change the value with Create in History |
| Correct | Change the value with Correct in History |
| Delete | Not applicable to single fields; whole records are deleted |
Newly enabled fields, whether standard, custom, or country-specific, appear in this category. Country-specific fields are prefixed with the country code, for example DEU-Travel Distance. THR81's exercises grant new fields all levels for the System Admin role.
Employee Data
Non-effective-dated entities are permissioned in the separate Employee Data category. For example, HR Information > Personal Contacts and National ID Card are granted here. Employment Information is the only non-effective-dated entity that supports field-level permissions.
Worked Example: IT Managers and Personal Contacts
ACE wants IT managers to edit their employees' contact information in the Personal Contacts card:
- Proxy as an IT manager (Tammy Aberts) and confirm the card is not visible for an employee.
- Manage Permission Groups: create Granted: IT Managers with people pool Job Code = IT-MGR, update membership, and confirm Tammy is included.
- Manage Permission Roles: create IT Manager Access with Employee Data > HR Information > Personal Contacts > Edit.
- Grant it to the IT Managers group, target Everyone, and exclude granted users from having the same access to themselves.
- Log out and in, proxy as Tammy, and confirm she can see and edit the Personal Contacts card.
Employee Central Import Entities
This category lets you perform or restrict imports of person and employment objects, and ensures imports stay within the importing user's target population. It works together with Employee Central Import Settings > Import Employee Data (Section 8.2).
Foundation Object Permissions
| Permission category | Covers |
|---|---|
| Manage Foundation Object Types | Admin actions for XML-based corporate data in Manage Organization, Pay and Job Structures. Available only after the Corporate Data Models are uploaded. |
| Manage Foundation Objects | Admin actions for importing foundation data, translations, and corporate data models |
| MDF Foundation Objects | Admin actions for MDF-based corporate data |
| Metadata Framework | Tools such as Configure Object Definitions and Manage Data |
Other EC Permissions to Remember
- Manage Hires: hire and rehire activities (Section 8.1).
- Employee Central Quick Actions: use rights for Quick Action templates (Section 10.1).
- Manage Workflows: workflow administration, the quick-approval option, and Professional Edition Manage Workflow Requests (Section 9.2).
- Manage System Properties > Employee Central Feature Settings: access to Manage Employee Central Settings, where features such as Position Management are switched on.
Testing with Proxy
Proxies are useful for verifying configuration and permissions in EC. When Private Data For Proxy Account Holder is deselected, the proxy does not see sensitive data such as home address or compensation (Section 2.3). THR81's default admin in the practice system can proxy as any user.
An HR administrator inserts a new Job Information record from the History window. A workflow derivation rule exists for Job Information. What happens?
Which permission controls whether the pencil icon appears on an effective-dated card, and which level matters?
Which non-effective-dated entity supports field-level permissions?