Managing Employee Permissions with Roles
Hero Schedule has moved from individual permission settings to a roles-based permissions system. This article explains how roles work, how to assign them to employees, and how to create and configure roles for your agency.
Overview
Instead of setting permissions directly on each employee, you now assign one or more roles to each employee. Each role carries a defined set of permissions. An employee can hold multiple roles simultaneously, and their combined access is reflected in their Effective Permissions.
Viewing an Employee's Current Permissions
To see what an employee currently has access to:
- Go to Menu > Setup > Employees and click on the employee's name.
- In the Edit Employee panel, scroll down to the Roles section to see which roles are assigned.
- Below that, expand Effective Permissions to see a full breakdown of every permission the employee currently has, organized by category (Scheduling, Time Off & Overtime, Notes & Communication, etc.).
If the effective permissions look correct, no changes are needed. If something appears to be missing or incorrect, you will need to add a role or edit an existing one.
Assigning Roles to an Employee
Adding a Role
- Open the employee's record and scroll to the Roles section.
- Click Add Role.
- Select the role you want to assign from the dropdown.
- Choose an Assignment Scope:
- All — the employee has those role permissions across the entire organization.
- Selected Group — the employee only has those permissions within a specific group. For example, you can scope a Lieutenant role to Day Squad A only.
- Click Save.
Assigning Multiple Roles
An employee can hold more than one role. For example, if a lieutenant needs to cover two squads, you can add the Lieutenant role twice — once scoped to Day Squad A and once scoped to Day Squad B. Repeat the steps above for each role assignment.
Removing a Role
In the Roles section of the employee's record, click the delete icon next to the role you want to remove, then save.
Managing Roles (Menu > Setup > Employee Roles)
To view, create, and configure roles for your entire organization, go to Menu > Setup > Employee Roles.
Each role has three tabs:
- Settings — rename the role.
- Permissions — configure exactly what this role can do.
- Assigned Employees — see which employees currently hold this role.
Understanding Auto-Generated Roles
After the transition, you may have many numbered roles (Role 1, Role 2, Role 3, etc.). To make sense of them:
- Click a role and go to the Assigned Employees tab to see who has it.
- Click the Permissions tab to review what that role allows.
- Once you understand the role, rename it in the Settings tab to something meaningful (e.g., rename "Role 5" to "Supervisor").
Creating a New Role
- On the Employee Roles page, click Add Role in the top right.
- Enter a name for the role and click Save / Create Role.
- Click the Permissions tab and enable the appropriate permissions for this role.
- Use the Show Permission Descriptions toggle at the bottom to see a plain-language explanation of each permission.
- When finished, click Save Permissions.
Permission Scopes Within a Role
Some permissions allow you to set a scope — for example, Edit Employees can be set to All (organization-wide) or restricted to a specific group. This is the same scoping concept as role assignment, but set at the permission level within the role itself. Use this to build roles that are inherently limited in reach.
Assigning Employees Directly from the Role
You can also add employees to a role from within the role editor:
- Go to Menu > Setup > Employee Roles and click the role.
- Click the Assigned Employees tab.
- Click Add Employee and select the employee(s) you want.
Key Permissions to Be Aware Of
- Close Pay Period — limit this carefully; only assign it to employees who are responsible for payroll processing.
- Use Time Clock — only enable this for employees who use the time clock feature; enabling it unnecessarily adds an item to the employee's navigation.
Benefits of the New Roles System
- Easily grant or revoke a complete set of permissions by adding or removing a role, rather than editing individual settings.
- Scope permissions precisely — give a supervisor access to approve time off and edit the schedule for their squad only, without giving them full admin access.
- Quickly audit who has what access using the Assigned Employees tab on any role.
- Cleaner, more scalable permission management as your agency grows.
Quick Reference
| Task | Where to Do It |
|---|---|
| See what an employee can do | Menu → Setup → Employees → [Employee] → Effective Permissions |
| Add or remove a role from an employee | Menu → Setup → Employees → [Employee] → Roles |
| Create a new role | Menu → Setup → Employee Roles → Add Role |
| Edit what a role can do | Menu → Setup → Employee Roles → [Role] → Permissions |
| See who has a specific role | Menu → Setup → Employee Roles → [Role] → Assigned Employees |
| Rename a role | Menu → Setup → Employee Roles → [Role] → Settings |
Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article