Pick from 7 baseline roles
Day-1 setup uses the seven defaults. Most companies need zero customisation to start, just assign each user one of super_admin, hr_manager, manager, employee, etc.
A seven-role baseline with 70+ granular permissions, a custom role builder scoped to department or position, and a tamper-evident audit log recording every Create / Update / Delete / Login / Export action. Read-only by design, defensible in DOLE and SOC 2 audits.
Most local HR tools either give every admin god-mode or hide the audit log behind a six-figure enterprise tier. WORKSPHR ships RBAC and the audit viewer on every plan, because “who deleted that employee record” should not be a question with no answer.
Most Filipino HR tools were built around “HR can do everything, employees can do nothing”. That breaks the moment you have a payroll specialist who shouldn't see promotions, or a manager who needs leave approval but not salary visibility. The fixes get hacked into Excel, with predictable consequences.
Roles, editable Owner/Admin permissions, custom builder, audit viewer, compliance export. Built into the platform from day one, available on every plan, no enterprise upsell.
Seven roles ship pre-configured: super_admin, org_admin, hr_manager, hr_staff, manager, employee, contractor. Each has a sensible default permission set you can clone and customize. Most clients never need to build a role from scratch.
Day-1 setup uses the seven defaults. Most companies need zero customisation to start, just assign each user one of super_admin, hr_manager, manager, employee, etc.
When you need "Payroll Specialist (no delete)" or "Branch Manager Cebu" (dept-scoped), the role builder ships them in minutes. The four-tier guard chain enforces them on every endpoint.
Any org_admin or hr_manager can pull "who deleted that 201 file" or "who exported the alphalist" in seconds. Pipe the same stream to Datadog or hand a CSV to your auditor.
super_admin, org_admin, hr_manager, hr_staff, manager, employee, contractor. Each ships with a sensible default permission set you can clone, scope to a department, and customize. Most clients never need to build a role from scratch.org_admin and hr_manager roles. There is no UI or API to mutate them. The append-only behavior is enforced at the database layer to keep the trail defensible in a DOLE or SOC 2 audit.Book a 30-minute demo. We'll walk you through role provisioning, the permission matrix, and the audit log viewer, live.