Complete access control for every user and team
The Permissions module in Office-X lets you control who can access and do what in the system. You can manage permissions for individual employees or teams, ensuring that access to each feature and action is secure and properly controlled.
You can manage permissions in two powerful ways:
- Employee Permissions – assign feature-level access to individual users.
- Team Permissions – assign feature-level access to entire teams for easier management.
Employee Permissions #
Assign feature-wise and action-level permissions to specific employees.
Here’s how it works:

- Search Employee: Enter the employee’s name or email to find the person whose permissions you want to manage.
- Feature List: After selecting an employee, you’ll see the features available to them based on your subscription plan. Payroll, Asset Tracking, Incident Report, Internal Support, and CRM only appear if your plan includes them.
- Expand a Feature: Click a feature to see its sub-features and available actions.
- Action Controls: Each action shows Create, View, Update, and Delete toggles. Only the permissions that apply to that action can be enabled; unsupported options are greyed out. You can use Mark All to enable all applicable permissions within a feature, or the select-all option on an individual action to enable all permissions supported by that action. Greyed-out permissions cannot be enabled.

- Save Permissions: The first time you set someone up, click Save in the Assign Permission window. After that, every toggle you switch on that employee’s permission card saves on its own, straight away — there is no separate Save button to press.
- Edit Anytime: You can revisit and modify these permissions anytime as the organization grows or roles change.

Good to know: Permission changes take effect immediately when you save them. If the employee already has Office-X open, they may need to refresh or load a new page before the updated access appears on screen. The permission itself is active as soon as you save it.
Good to know: If you later upgrade your subscription plan, any newly available features automatically appear in the Permissions list. You only need to come back and enable the permissions you want to grant.

Delete Employee Permissions #
You can delete an employee’s direct permission configuration whenever that employee no longer needs individually assigned access.
Click Delete Permission from the employee permission card and confirm the deletion.

Once deleted, the employee will be removed from the Employee Permission list, and every directly assigned permission for that employee — across all features, not just one — is revoked at once. This doesn’t touch any access they still have through a Team Permission they’re a member of.
Search Assigned Employee Permissions

You can search assigned employee permissions by employee name or email. This helps you quickly find an employee who already has permission access configured.
Team Permissions #
Assign access to an entire team in one go.
This section works almost the same as Employee Permissions, but instead of searching for an individual employee, you’ll search by team name.
(Teams are created from Admin → Teams.)
Here’s the process:

- Search Team: Enter the team’s name (e.g., HR Team, Sales Team, IT Department, etc.).
- Select Features: Just like employee permissions, expand the features and enable or disable actions (Create, View, Update, Delete) using toggles or “Mark All.”
- Save: Once saved, every member of that team will automatically inherit the same permissions.


- Dynamic Access Control:
- When a new employee joins and is assigned to that team, they instantly receive the same permissions.
- If someone is removed from the team, their access is revoked automatically.
Good to know: team permission changes work exactly like employee ones — they are active the moment you save, but anyone with Office-X already open sees the change on their next page load or refresh.
Delete Team Permissions #
You can remove all permissions assigned to a team at once. Doing so revokes access for all team members, while keeping individual employee permissions intact if separately configured.

Search Assigned Team Permissions

You can search assigned team permissions by team name. This makes it easier to find and manage team-level access when many teams are available.
This saves time, ensures consistency, and prevents access gaps especially in large organizations.
Permission Action Reference #
This section lists every permission you can hand out, grouped by module, so you know exactly what you are giving away before you switch it on.
Read the tables like this: “you” is you, the Subscriber Admin doing the granting, and “they” is the employee or team you are granting it to. So “They can add new employees to the system” means that once this permission is on, that person is able to add employees.
Permission Scope Meaning #
| Scope | What it means |
|---|---|
| For Own | Their own records only. Nobody else’s. |
| For All | Everyone in the company. |
| For Others | Anyone except themselves. This is used where acting on your own record would not make sense — for example, approving your own overtime. |
| For On Behalf | Records they submitted for somebody else. |
| For Subordinate(s) | Their own reporting chain: the people who report to them directly, plus the people who report to those reports. |
| As Approver | They can approve or reject a request only if both conditions are met: 1. They have this permission. 2. They are assigned as the approver for the request’s current approval step. Having just one of these is not enough. |
| Route Access | They can open a particular page. |
Employee Management #
| Action Name | Action Type | Description |
|---|---|---|
| Create Employee | Create | They can add new employees to the system. |
| View Profile & Account (For Own) | View | They can see their own profile and account details. |
| View Employee Profiles (For All) | View | They can see every employee’s profile. |
| View Employee Profiles (For Subordinates) | View | They can see profiles only for people in their own reporting chain — those who report to them directly, plus the people who report to those reports. |
| Manage Bank Deposit Forms (For All) | View | They can open and manage the bank deposit form of any employee. |
| Edit Employee (For All) | Update | They can edit any employee’s profile. |
| Manage Employee Documents (For All) | Update | They can upload, rename and delete PDF documents (contracts, certificates and similar files) on any employee’s profile. |
| Reset Employee Password (For All) | Update | They can reset the password of any employee account. |
| Manage Work Hours (For All) | Create | They can set up and assign work hour schedules for any employee. |
| Manage Payroll Config (For All) | Create | They can set up any employee’s payroll details — salary, deductions and bonuses. |
| Assign/Unassign Seats (For All) | Create | They can give a license seat to any employee, or take it back. |
| Change Employee Status (For All) | Update | They can activate or deactivate any employee, and change their employment status. |
| Manage Opening Balance (For All) | Update | They can set or update the opening balance of any employee. |
| Assign Work Days (For All) | View, Create, Update, Delete | They can view, create, edit and delete work day assignments for any employee. |
| Assign Work Days (For Subordinate) | View, Create, Update, Delete | They can view, create, edit and delete work day assignments, but only for people who report to them and only where they are the Reporting Manager. |
| Bulk RM Change (For All) | Update | They can change the Reporting Manager for many employees at once. |
Work Shift Management #
| Action Name | Action Type | Description |
|---|---|---|
| Create Bulk Work Shift (For Subordinate) | Create | They can create many work shifts at once for the people who report to them. |
| Create Work Shift (For Subordinate) | Create | They can create a work shift for someone who reports to them. |
| Edit Work Shift (For Subordinate) | Update | They can change existing work shifts for people who report to them. |
| Delete Work Shift (For Subordinate) | Delete | They can delete work shifts for people who report to them. |
| View All Work Shift | View | They can see every work shift record. |
| Export Work Shift (Excel & PDF) | View | They can export work shift data to Excel or PDF. |
Holiday Management #
| Action Name | Action Type | Description |
|---|---|---|
| Manage Holidays | View, Create, Update, Delete | They can add, edit and delete company holidays on the calendar. |
Attendance Management #
Attendance uses two different scope patterns, so it is worth a quick word before the table.
- The two Attendance Summary pages come as For All (the whole company) or For Subordinates (their reporting chain — direct reports, and the people under those reports too).
- Every other action comes as For Others (anyone except themselves) or For Subordinates (their reporting chain, again never themselves). Either way, nobody can approve, hand-add or reclassify hours on their own record through these permissions.
If someone holds neither version of an action, they cannot do it at all.
| Action Name | Action Type | Description |
|---|---|---|
| Overall Attendance Summary (For All) | View | They can open the overall attendance summary for everyone in the company. |
| Overall Attendance Summary (For Subordinates) | View | They can open the overall attendance summary, but it only shows the people who report to them. |
| Individual Attendance Summary (For All) | View | They can open the detailed attendance page of any employee. |
| Individual Attendance Summary (For Subordinates) | View | They can open the detailed attendance page, but only for people who report to them. |
| Create Manual Attendance (For Others) | Update | They can add or correct attendance entries by hand for anyone except themselves. |
| Approve Check-in / Check-out (For Others) | Update | They can approve or reject check-in and check-out correction requests for anyone except themselves. |
| Approve OT/Lieu Hours (For Others) | Update | They can approve or reject overtime and time-in-lieu requests for anyone except themselves. |
| Bulk Approve Check-in / Check-out (For Others) | Update | They can approve many check-in and check-out requests together in one go, for anyone except themselves. |
| View Attendance (For All) | View | They can see the attendance records of every employee. |
| View Attendance (For Subordinates) | View | They can see attendance records only for people who report to them. |
| Create Manual Attendance (For Subordinates) | Update | They can add or correct attendance entries by hand, but only for people who report to them — never for themselves. |
| Approve Check-in / Check-out (For Subordinates) | Update | They can approve or reject check-in and check-out correction requests, but only for people who report to them — never for themselves. |
| Approve OT/Lieu Hours (For Subordinates) | Update | They can approve or reject overtime and time-in-lieu requests, but only for people who report to them — never for themselves. |
| Bulk Approve Check-in / Check-out (For Subordinates) | Update | They can approve many check-in and check-out requests together in one go, but only for people who report to them — never for themselves. |
Leave Management #
| Action Name | Action Type | Description |
|---|---|---|
| Create Leave Request (For Own) | Create | They can submit their own leave request. |
| Create Leave Request (For Others) | Create | They can submit a leave request on behalf of someone else. |
| View Leave Request Details | View | They can open a leave request and see its full details. |
| View All Leave Requests (Route Access) | View | They can open the page that lists every employee’s leave requests. |
| Edit Leave Request (For Own) | Update | They can edit their own leave requests while these are still pending. |
| Edit Leave Request (For On Behalf) | Update | They can edit leave requests they submitted on behalf of someone else. |
| Approve Leave Request (As Approver) | Update | They can approve the current step of a leave request — but only if they are the approver assigned to that step. This permission on its own is not enough, and being the assigned approver on its own is not enough either. They need both. |
| Reject Leave Request (As Approver) | Update | They can reject the current step of a leave request — but only if they are the approver assigned to that step. This permission on its own is not enough, and being the assigned approver on its own is not enough either. They need both. |
| Delete Leave Request (For Own) | Delete | They can delete their own leave requests while these are still pending. |
| Delete Leave Request (For On Behalf) | Delete | They can delete leave requests they submitted on behalf of someone else. |
Bill Management #
| Action Name | Action Type | Description |
|---|---|---|
| Create Bill Request (For Own) | Create | They can submit their own bill or expense reimbursement request. |
| Create Bill Request (For Others) | Create | They can submit a bill request on behalf of someone else. |
| View Bill Request Details | View | They can open a bill request and see its full details. |
| View All Bill Requests (Route Access) | View | They can open the page that lists every employee’s bill requests. |
| Edit Bill Request (For Own) | Update | They can edit their own bill requests while these are still pending. |
| Edit Bill Request (For On Behalf) | Update | They can edit bill requests they submitted on behalf of someone else. |
| Approve Bill Request (As Approver) | Update | They can approve the current step of a bill request — but only if they are the approver assigned to that step. This permission on its own is not enough, and being the assigned approver on its own is not enough either. They need both. |
| Reject Bill Request (As Approver) | Update | They can reject the current step of a bill request — but only if they are the approver assigned to that step. This permission on its own is not enough, and being the assigned approver on its own is not enough either. They need both. |
| Delete Bill Request (For Own) | Delete | They can delete their own bill requests while these are still pending. |
| Delete Bill Request (For On Behalf) | Delete | They can delete bill requests they submitted on behalf of someone else. |
Travel Request Management #
| Action Name | Action Type | Description |
|---|---|---|
| Create Travel Request (For Own) | Create | They can submit their own travel request. |
| Create Travel Request (For Others) | Create | They can submit a travel request on behalf of someone else. |
| View Travel Request Details | View | They can open a travel request and see its full details. |
| View All Travel Requests (Route Access) | View | They can open the page that lists every employee’s travel requests. |
| Edit Travel Request (For Own) | Update | They can edit their own travel requests while these are still pending. |
| Edit Travel Request (For On Behalf) | Update | They can edit travel requests they submitted on behalf of someone else. |
| Approve Travel Request (As Approver) | Update | They can approve the current step of a travel request — but only if they are the approver assigned to that step. This permission on its own is not enough, and being the assigned approver on its own is not enough either. They need both. |
| Reject Travel Request (As Approver) | Update | They can reject the current step of a travel request — but only if they are the approver assigned to that step. This permission on its own is not enough, and being the assigned approver on its own is not enough either. They need both. |
| Delete Travel Request (For Own) | Delete | They can delete their own travel requests while these are still pending. |
| Delete Travel Request (For On Behalf) | Delete | They can delete travel requests they submitted on behalf of someone else. |
Purchase Management #
| Action Name | Action Type | Description |
|---|---|---|
| Create Purchase Request (For Own) | Create | They can submit their own purchase request. |
| Create Purchase Request (For Others) | Create | They can submit a purchase request on behalf of someone else. |
| View Purchase Request Details | View | They can open a purchase request and see its full details. |
| View All Purchase Requests (Route Access) | View | They can open the page that lists every employee’s purchase requests. |
| Edit Purchase Request (For Own) | Update | They can edit their own purchase requests while these are still pending. |
| Edit Purchase Request (For On Behalf) | Update | They can edit purchase requests they submitted on behalf of someone else. |
| Approve Purchase Request (As Approver) | Update | They can approve the current step of any pending purchase request. This one works differently from Leave, Bill and Travel: the permission alone is enough, so they do not also have to be the assigned approver. |
| Reject Purchase Request (As Approver) | Update | They can reject the current step of any pending purchase request. This one works differently from Leave, Bill and Travel: the permission alone is enough, so they do not also have to be the assigned approver. |
| Delete Purchase Request (For Own) | Delete | They can delete their own purchase requests while these are still pending. |
| Delete Purchase Request (For On Behalf) | Delete | They can delete purchase requests they submitted on behalf of someone else. |
Payroll Management #
| Action Name | Action Type | Description |
|---|---|---|
| Run Payroll (For All) | Create | They can run and process payroll for all employees. |
| View Payroll (For All) | View | They can see payroll records and pay slips for all employees. |
Report Management / Incident Report #
| Action Name | Action Type | Description |
|---|---|---|
| Create Incident Report (For Own) | Create | They can file an incident report about themselves. |
| Create Incident Report (For All) | Create | They can file an incident report about any employee. |
| View Incident Report (For All) | View | They can see the incident reports of all employees. |
| Edit Incident Report (For Own) | Update | They can edit the incident reports they created themselves. |
| Edit & Discard Incident Report (For All) | Update | They can edit or discard any incident report. |
Tracking / Asset Tracking #
| Action Name | Action Type | Description |
|---|---|---|
| Create Asset | Create | They can add new assets to Asset Tracking. |
| View Asset (For Own) | View | They can see only the assets assigned to them. |
| View Asset (For All) | View | They can see every asset in the company. |
| Edit Asset (For All) | Update | They can edit any asset. |
| Duplicate Asset (For All) | Update | They can copy an existing asset to create a similar one, with the details already filled in. |
Setting Management #
| Action Name | Action Type | Description |
|---|---|---|
| Employee Forgot & Change Password (For Own) | View, Update | They can recover or change their own password, and turn Two-Factor Authentication on or off on their own account. |
| SMTP Settings | View, Create, Update, Delete | They can set up and manage the company’s email (SMTP) server settings. |
Admin Configuration #
| Action Name | Action Type | Description |
|---|---|---|
| Department | View, Create, Update, Delete | They can add, edit and delete company departments. |
| Pay Type | View, Create, Update, Delete | They can add, edit and delete pay types such as hourly or salary. |
| Designation | View, Create, Update, Delete | They can add, edit and delete job titles (designations). |
| Employment Status | View, Create, Update, Delete | They can add, edit and delete employment statuses such as full-time, part-time or contract. |
| Leave Type | View, Create, Update, Delete | They can add, edit and delete leave types such as sick, annual or casual leave. |
| Benefits | View, Create, Update, Delete | They can add, edit and delete employee benefit plans. |
| Expense Category | View, Create, Update, Delete | They can add, edit and delete the expense categories used in bill and purchase requests. |
| Teams | View, Create, Update, Delete | They can add, edit and delete teams. |
| Forms | View, Create, Update, Delete | They can add, edit and delete the custom forms used across the system. |
| Announcements | View, Create, Update, Delete | They can add, edit and delete company-wide announcements and broadcasts. |
| Incident Config | View, Create, Update, Delete | They can set up incident report types, severities and statuses. |
| IP Logs | View, Create, Update, Delete | They can manage the list of allowed IP addresses that controls where staff may check in and out. |
| Currency | View, Create, Update, Delete | They can add, edit and delete the currencies the system supports. |
| Support Category | View, Create, Update, Delete | They can add, edit and delete internal support categories, and choose who resolves each one. |
Support Management #
This is the internal support ticket system your staff use to raise issues with each other. It is not Business Support, which is how your company raises tickets with Office-X — that one is under Business Management below.
| Action Name | Action Type | Description |
|---|---|---|
| View All Supports | View | They can see every internal support ticket, not just the ones they raised. |
| Create Support Request (For On Behalf) | Create | They can raise an internal support ticket on behalf of someone else. |
| Edit Support Request (For On Behalf) | Update | They can edit an internal support ticket that was raised on behalf of someone else. |
Business Management #
| Action Name | Action Type | Description |
|---|---|---|
| Edit Company Profile | Update | They can edit the company profile — name, address, logo and other details. |
| Business Support | Create, View, Update | They can raise your company’s Business Support tickets to Office-X, and view, edit, resolve or close the ones they raised. See the Business Support guide for more. |
| Manage Billing & Payment | Update | They can manage the subscription billing details and payment method. |
| Manage Business Payroll Configuration | Update | They can set the company-wide payroll rules — overtime rules, deduction basis and bonus types. |
Performance Management #
| Action Name | Action Type | Description |
|---|---|---|
| View Assessment Detail (For All) | View | They can see the full performance assessment results of any employee. |
| View All Assessments | View | They can open the list of performance assessments. |
| Performance Period & Criteria Setup | View, Create, Update, Delete | They can open the performance setup page and fully manage review periods and evaluation criteria. This is full setup access, not just permission to look at the page. |
| Take Assessment (For Subordinate) | Create | They can start and submit performance assessments for people who report to them. |
| Edit & Mark as Completed Assessment (For Subordinate) | Update | They can edit an assessment and mark it as completed, for people who report to them. |
| Delete Assessment (For Subordinate) | Delete | They can delete performance assessments for people who report to them. |
CRM – Clients #
| Action Name | Action Type | Description |
|---|---|---|
| Create Client | Create | They can add new clients to the CRM. |
| View All Clients | View | They can see the full list of clients. |
| Edit Client (For All) | Update | They can edit any client’s details. |
| Delete Client (For All) | Delete | They can delete any client. |
| Activate / Inactivate Client (For All) | Update | They can turn any client on or off. |
CRM – Items #
| Action Name | Action Type | Description |
|---|---|---|
| Create Item | Create | They can add new items to the CRM catalog. |
| View All Items | View | They can see the full list of catalog items. |
| Edit Item (For All) | Update | They can edit any catalog item. |
| Delete Item (For All) | Delete | They can delete any catalog item. |
| Activate / Inactivate Item (For All) | Update | They can turn any catalog item on or off. |
CRM – Docs #
| Action Name | Action Type | Description |
|---|---|---|
| Create Doc | Create | They can create new document templates. |
| View All Docs | View | They can see the full list of document templates. |
| Edit / Clone / Open Builder Doc (For All) | Update | They can edit any document template, copy one, or open Builder — the full designer for the template’s fields, signer roles and settings. |
| Delete Doc (For All) | Delete | They can delete a document template that has never been used. Once a template has been used, it can only be turned off, not deleted. |
| Activate / Inactivate Doc (For All) | Update | They can turn any document template on or off. |
CRM – Estimates #
| Action Name | Action Type | Description |
|---|---|---|
| Create / Duplicate Estimate | Create | They can create a new client estimate, or copy an existing one to save time. |
| View All Estimates | View | They can see the full list of estimates. |
| Edit Estimate (For All) | Update | They can edit any estimate. |
| Delete Estimate (For All) | Delete | They can delete any estimate. |
| Send / Resend / Void Estimate (For All) | Update | They can send an estimate to a client, send it again, or void it. |
CRM – Agreements #
| Action Name | Action Type | Description |
|---|---|---|
| Create Agreement | Create | They can create new client agreements. |
| View All Agreements | View | They can see the full list of agreements. |
| Edit Agreement (For All) | Update | They can edit any agreement. |
| Delete Agreement (For All) | Delete | They can delete any agreement. |
| Send / Resend Agreement (For All) | Update | They can send an agreement out for e-signature, or send it again to a signer. |
| Terminate Agreement (For All) | Update | They can terminate an agreement that is already active. |
CRM – Bookings #
Like Attendance above, most Booking actions come in two versions. The For Own version only covers the services and bookings where that person is the assigned staff member. The For All version drops that limit and covers every staff member’s services and bookings.
| Action Name | Action Type | Description |
|---|---|---|
| Create Booking Service (For Own) | Create | They can create a bookable service, but only one assigned to themselves. |
| Create Booking Service (For All) | Create | They can create a bookable service for any staff member. |
| Edit / Activate-Deactivate Booking Service (For Own) | Update | They can edit, and turn on or off, only the booking services assigned to them. |
| Edit / Activate-Deactivate Booking Service (For All) | Update | They can edit any booking service and turn it on or off, no matter which staff member it belongs to. |
| Delete Booking Service (For Own) | Delete | They can delete only the booking services assigned to them. |
| Delete Booking Service (For All) | Delete | They can delete any booking service, no matter which staff member it belongs to. |
| View Bookings (For Own / Assigned) | View | They can see only the bookings where they are the assigned staff member. |
| View All Bookings | View | They can see every booking in the company. |
| Manage Booking Response (For Own) | Update | They can cancel, reschedule or mark as no-show only the bookings assigned to them. |
| Manage Booking Response (For All) | Update | They can cancel, reschedule or mark as no-show any booking, no matter which staff member it belongs to. |
| Manage AI Booking Integrations (ElevenLabs) | Update | They can open Admin → Integrations and set up the AI phone-booking agent: connect an account and API key, run the setup, assign the phone number, set the post-call webhook, and disconnect it again. |
Activity Log #
| Action Name | Action Type | Description |
|---|---|---|
| View Activity Logs (For All) | View | They can see the activity log for all employees. |
| View Activity Logs (For Own) | View | They can see their own activity log history. |
Summary #
The Permissions Module gives you centralized control over access and security across the entire platform.
Whether you’re granting individual privileges or team-wide permissions, Office-X ensures every operation is handled safely, flexibly, and transparently.