Abilities

What each ability allows, how the Team page assigns them, and how Admin relates to the others.

For: Administrators (the admin ability) · Last updated

Access in Workforce Intelligence is controlled by abilities. A person can hold any combination. You assign them on Settings → Administration → Team, when you invite someone or when you change their role. Everyone also holds an implicit member ability, which needs no assignment.

The abilities you can assign#

The Abilities checkboxes on the Team page are:

Checkbox Ability What it allows
Admin admin Manage the deployment: the Team page, Single sign-on, company-wide API keys and the other administration screens. Passes every other ability check, and can see every SSH key registered in the company.
Hire Coworkers hire_coworkers Hire a Coworker and be named as its Supervisor. Also allows editing a Work Center.
Manage Knowledge Bases manage_knowledge_bases Create Knowledge Bases, and manage the ones the person owns or can edit. It does not allow managing every Knowledge Base in the company.
Manage Apps manage_apps Register Apps, and manage any App (not only ones the person built), including creating and revoking that App's API keys.
People Manager people_manager View company-wide usage and cost.

An App's own Builder can manage that App without manage_apps, and a Coworker's Supervisor can manage that Coworker without any extra ability.

How Admin interacts with the others#

Ticking Admin also ticks Hire Coworkers, Manage Knowledge Bases and Manage Apps and greys them out, because admin already includes each of them. People Manager stays independent: you can tick or clear it whether or not Admin is ticked.

If you clear Admin afterwards, the three other boxes stay ticked and become editable again, so clear the ones the person should no longer have.

Abilities that are not on the Team page#

  • manage_financial_inputs allows editing the company's output and workforce-cost inputs to the WI Score and launching a survey campaign. The Team page does not offer it as a checkbox. An administrator can perform those actions without it.
  • WI Score access does not come from an ability you assign. The WI Score is open to administrators and to anyone who is the Supervisor of at least one Coworker.

Team scope is separate#

Abilities decide what a person may do. Teams decide which full-time Coworkers, Apps and Knowledge Bases a group of people can reach. An administrator passes team scope checks without being a member.

When changes apply#

Abilities are read from the person's record on every request, so a change you save on the Team page applies to their existing session without a new sign-in. Revoking someone is different: it ends their sessions immediately (see Managing people).