RBAC GuideUser Roles

PayMax User Roles Explained

Understand all 7 PayMax user roles, their specific permissions, limitations, and best use cases. Learn how to assign the right role for maximum security and efficiency.

Complete Role Breakdown

Company Administrator

Complete system access with administrative privileges

COMPANY ADMIN

Permissions & Access

  • Full access to all features and data
  • User management and role assignment
  • Company settings and configuration
  • Billing and subscription management
  • Integration setup and management
  • Complete payroll processing control
  • All employee data access
  • System audit and compliance oversight

Key Limitations

  • Cannot access employee self-service portal
  • Some features limited by subscription tier

Typical Users

  • Business owners
  • Managing directors
  • Senior executives
  • System administrators

Access Level Summary

Complete administrative control

HR Manager

Comprehensive HR management with employee focus

HR MANAGER

Permissions & Access

  • Employee data management
  • Leave administration and approval
  • Performance review management
  • Workforce analytics access
  • Change request processing
  • Organizational structure management
  • Employee lifecycle management
  • Compliance monitoring

Key Limitations

  • No payroll processing access
  • No billing or subscription control
  • Cannot modify company financial settings
  • Limited system configuration access

Typical Users

  • HR managers
  • People operations leads
  • Talent managers
  • HR business partners

Access Level Summary

Full HR and employee management

Payroll Administrator

Specialized payroll processing and compliance

PAYROLL ADMIN

Permissions & Access

  • Complete payroll processing
  • Tax calculations and submissions
  • Payslip generation and distribution
  • Statutory compliance reporting
  • Financial integrations management
  • Compensation policy configuration
  • Payroll history and audit access
  • SARS and regulatory submissions

Key Limitations

  • No HR management features
  • No user management capabilities
  • Cannot access performance reviews
  • Limited employee data editing

Typical Users

  • Payroll specialists
  • Finance managers
  • Accounting professionals
  • Compliance officers

Access Level Summary

Complete payroll and financial control

Employee

Self-service access for personal information

EMPLOYEE

Permissions & Access

  • Personal profile management
  • Leave requests and balance viewing
  • Payslip access and download
  • Performance review participation
  • Personal document upload
  • Contact information updates
  • Tax certificate access
  • Time and attendance logging

Key Limitations

  • No access to other employee data
  • Cannot approve leave requests
  • No payroll processing access
  • Limited to personal information only

Typical Users

  • Full-time employees
  • Part-time staff
  • Permanent workers
  • Regular contractors

Access Level Summary

Personal data and self-service only

Contractor

Limited access for contract workers

CONTRACTOR

Permissions & Access

  • Basic profile information
  • Contract-specific leave requests
  • Payment history and slips
  • Document submission
  • Contact details updates
  • Work schedule viewing
  • Basic self-service features
  • Contract terms access

Key Limitations

  • No performance review access
  • Limited leave entitlements
  • Cannot access company directory
  • No workforce analytics access

Typical Users

  • Independent contractors
  • Freelancers
  • Temporary workers
  • Project-based staff

Access Level Summary

Basic self-service for contractors

External Accountant

Financial and compliance data access

EXTERNAL ACCOUNTANT

Permissions & Access

  • Payroll reports and summaries
  • Tax calculation verification
  • Financial integrations access
  • Compliance report generation
  • Audit trail viewing
  • SARS submission verification
  • Historical payroll data
  • Statutory reporting access

Key Limitations

  • No employee personal data access
  • Cannot process payroll
  • No user management capabilities
  • Read-only access to most features

Typical Users

  • External accounting firms
  • Tax consultants
  • Compliance auditors
  • Financial advisors

Access Level Summary

Financial and compliance data only

Read-Only User

View-only access for observers

READ ONLY

Permissions & Access

  • Dashboard viewing
  • Report generation
  • Data export capabilities
  • Workforce analytics viewing
  • Compliance status monitoring
  • Historical data access
  • System usage analytics
  • Basic company information

Key Limitations

  • Cannot modify any data
  • No processing capabilities
  • Cannot access personal employee data
  • No administrative functions

Typical Users

  • Board members
  • Investors
  • Consultants
  • Auditors

Access Level Summary

View-only access to aggregated data

Quick Access Comparison

FeatureAdminHR MgrPayrollEmployeeContractorAccountantRead-Only
Employee ManagementFull ControlFull ControlLimitedSelf OnlySelf OnlyNoneView Only
Payroll ProcessingFull ControlNoneFull ControlView OwnView OwnView ReportsView Reports
Leave ManagementFull ControlFull ControlNoneSelf ServiceLimitedNoneView Only
User ManagementFull ControlNoneNoneNoneNoneNoneNone
Financial DataFull AccessNoneFull AccessPersonal OnlyPersonal OnlyFull AccessSummary Only

Role Management Best Practices

Principle of Least Privilege

Grant users the minimum access required for their role

HR managers don't need payroll processing access
Employees only access their own data
Read-only users for reporting and analytics only

Regular Access Reviews

Periodically review and update user access permissions

Quarterly user access audits
Remove access when roles change
Update permissions for promotions

Segregation of Duties

Separate conflicting responsibilities between different roles

HR processes employee changes, Payroll processes payments
External accountants verify but don't process
Read-only access for oversight roles

Documentation and Training

Maintain clear role documentation and provide proper training

Document role responsibilities clearly
Train users on their specific access levels
Regular security awareness sessions

Related Topics

Implement Proper User Roles

Secure your PayMax system with proper role-based access control. Start with the principle of least privilege and regularly review access levels.