Configure module-level permissions

Beyond the four standard roles (Employee, Manager, Org Admin, Kairos Admin), the platform lets you toggle module-level permissions per role. Useful when your organisation needs a non-standard combination, for example a “Finance Manager” who needs access to Reports and Award Compliance but doesn’t need to see the full HR Hub.

Open module permissions

  1. On the left hand sidebar, click Settings.
  2. Open the module permissions area.

You’ll see a matrix: roles down one axis, modules across the other, with toggles at each intersection.

What you can toggle

The matrix lets you adjust access to modules including:

  • Payroll fields visibility
  • Leave management
  • Recruitment
  • Reporting
  • Document generation
  • Workflow management

Each module has its own toggle per role. Default values follow the platform’s standard setup; you only need to change toggles where your organisation deviates.

How changes take effect

  • Toggle a module on for a role: people in that role gain access to it on their next page load.
  • Toggle a module off for a role: they lose access immediately.

Changes apply to all users in the role. There’s no per-user override at this level (that’s what custom roles would handle, not yet supported).

When to deviate from defaults

The default role behaviour is sensible for most organisations. Common reasons to adjust:

  • Restricting Payroll fields from managers. Default lets managers see their team’s pay rates. Some orgs prefer this stays admin-only. Toggle Payroll off for Manager.
  • Giving employees access to the org chart. Already on by default, but worth verifying.
  • Hiding Recruitment from managers if hiring is centralised through HR.

What this DOESN’T cover

Module permissions toggle access to whole modules. They don’t:

  • Hide individual employees from a manager
  • Redact specific fields within a record
  • Apply per-user custom rules

For those finer-grained controls, you’d need to think about restructuring your data (e.g. separate departments, separate managers) rather than tweaking module permissions.

Permissions to change permissions

Only org admins (and Kairos admins) can change module permissions. You can’t accidentally give a manager the ability to escalate their own role this way; the matrix itself is gated.