Concept: General Access Control Groups
This topic explains how general access control groups work. See Concept: Specialist Access Control Groups to learn about specialist access, and see Setup Considerations: Access Controls to learn about the access control functionality at a higher level.
Overview
General access groups account for the majority of access configuration.
All users that are in your Peakon instance are part of the standard
Employees
group. Any user that manages employees or segments is also part of the standard Managers
group. You can add and remove users manually on any other standard group, and you can create your own custom groups.General access groups enable you to configure user access to question sets (Example: Deactivate a question set you don't use). However, if you need to additionally configure user access to specific drivers (Example: The Facilities director needs access to the Environment driver only), we recommend using Concept: Specialist Access Control Groups.
Access controls work together with attributes, to form the full scope of activities a user can perform within their assigned segments.
Functionality | Description |
|---|---|
Attributes and segments | A segment dictates the employees, and therefore segments, the leader has access to. Example: direct reports, a business unit, or a country segment. |
Access control | Access Control dictates the settings that the leader can use within their segments. Example: view dashboard, manage employee records, or manage schedules. The exception is any All employees group, because they automatically grant their members full company level access. In this case, the Access Control group still dictates what settings the leader can use within this scope. |
Access Types
General access groups have 3 access levels:
All employees
, Managed employees
, and Individual
. The access level options relate to the extent of data that the group's members can access, not the permissions that they can use within their assigned area.The Administrators, External Administrators, Human Resources, and Senior Leaders groups provide access to all employees in the company. The Managers group provides access to managed employees, through a reporting line or a managed segment.
Users can be part of multiple groups at the same time. Example: managers and administrators are also survey participants, and are therefore part of the Employees group.
Access level | Example | Explanation | Adding users |
|---|---|---|---|
All employees | Administrators, External Administrators, Senior Leaders, Human Resources | All employees type groups provide company-level access, whether you've configured the group to only access survey results, manage employee data or otherwise. This group type is appropriate for administrator-like users. | You can manage users directly within the access group. |
Managed employees | Managers | Managed employees type groups provide segment-level access. Example: A manager's direct team, a business unit or an entity.This group type is appropriate for leaders of any level, who need access to a specific team. A member of this group can only use their settings within their own area. | Peakon automatically adds all people managers and segment managers to the standard Managers group.You can manage users directly within the access group, but you must first assign them a reporting line or a managed segment. |
Individual | Employees | Individual type groups provide users to their own survey results in personal dashboards. | Peakon adds all users automatically to the standard Employees group.For custom groups, you can manage users directly within the access group. |
Adding Users to Groups
When creating a custom access group, you must decide how Peakon adds new people to the group. Peakon uses the Choose manually
option for all standard groups.
Choose manually
| Enables you to manually manage users within the group. Because the access control area is only available to administrators, only they can add or remove employees in such groups. This is appropriate for groups that you want to manage centrally. |
Choose by segment
| You add users to the group by adding them to a segment, which populates the group indirectly. This option is useful for local administrators who have access to update employee records and segments. When using this option on a 'Managed employees' group, Peakon only adds leaders who manage employees or segments. This approach removes the need of having more administrators, and provides local administrators with autonomy in granting access. |
See Add External Administrator for instructions on how to grant access to external administrators, if applicable.