Talent Systems — Employer Help
Team & Permissions

Roles & Permissions

Understanding the four employer roles and how permissions work.

Four Roles

RoleDescription
OwnerFull access to everything. One per workspace. Can configure permissions and transfer ownership.
AdminFull access by default. Permissions configurable by owner.
MemberRead access by default. Can view but not modify most things.
AssociateMinimal access by default. Designed for external reviewers or limited collaborators.

Permission Areas

Permissions are organized into 9 areas, each with three access levels:

AreaWhat It Controls
PostingsCreate, edit, delete job postings
CandidatesInvite, revoke, reset candidates
ScorecardsView candidate scores and evaluations
TranscriptsView interview transcripts
ComparisonAccess side-by-side candidate comparison
AnalyticsView scoring analytics and charts
ExportsDownload CSV and PDF reports
TeamInvite, remove, change roles
Talent PoolSearch and import from talent pool

Access Levels

LevelMeaning
FullRead and write access — can view and modify
ReadView only — can see data but not change it
HiddenCompletely invisible — not in sidebar, not in API responses

Default Permissions

AreaOwnerAdminMemberAssociate
PostingsFullFullReadRead
CandidatesFullFullReadRead
ScorecardsFullFullReadRead
TranscriptsFullFullHiddenHidden
ComparisonFullFullReadRead
AnalyticsFullFullReadHidden
ExportsFullFullHiddenHidden
TeamFullHiddenHiddenHidden
Talent PoolFullFullReadHidden

How Enforcement Works

Permissions are enforced at three layers:

  1. UI — sidebar items and buttons are hidden or disabled based on your permissions
  2. API — every request checks your role's permissions, returning 403 if insufficient
  3. Data stripping — even if you access a candidate page, fields you lack permission for are stripped from the response

On this page