Roles & access
Every payIQ membership gives you exactly one role in a workspace. Your role decides what you can see and do there. A user can hold different roles in different workspaces — your role is shown in the header and in Settings.
payIQ has five roles:
- Payroll Operator
- Approver
- Payment/Reconciliation Reviewer
- Read-only Reporter
- Administrator
What the roles are for
Section titled “What the roles are for”Payroll Operator
Section titled “Payroll Operator”The working payroll and operations role. A Payroll Operator can maintain employees, compensation, and payroll components; create, calculate, and finalize payroll runs; request, issue, repay, and plan advances; record attendance; create and submit leave requests; propose payroll consequences; prepare and process payment instructions; and see the full report catalogue.
A Payroll Operator cannot approve an advance, approve leave or a payroll consequence, confirm a payment, or reverse a confirmation. Keeping preparation and approval apart is deliberate.
Approver
Section titled “Approver”The review and approval role for payroll operations. An Approver can approve advances, approve or reject leave, approve payroll consequences, finalize payroll runs, and submit and lock payment batches. An Approver can view payroll detail and the full report catalogue, including compensation columns.
Payment/Reconciliation Reviewer
Section titled “Payment/Reconciliation Reviewer”The reconciliation role for payments. A Payment/Reconciliation Reviewer can confirm a payment as paid, record a failure, and complete a batch. They see payment instructions and batches, the payment amounts, and the reconciliation position — but not the payroll or advance source linkage behind an instruction. Their report set is limited to the employee directory, payment reports, the payments summary, and accounting handoffs.
Read-only Reporter
Section titled “Read-only Reporter”A deliberately non-monetary read-only role. A Read-only Reporter can view the employee directory (without compensation), accounting handoffs, attendance, and leave, and can run eight non-monetary reports. The reporter role exists for people who need operational counts and statuses but should not see pay amounts.
Administrator
Section titled “Administrator”Full access. In addition to everything above, an Administrator is the only role that can:
- create, rename, archive and reactivate workspaces;
- add existing users, create users with validated passwords, and administer memberships and roles;
- record advance corrections and payment reversals;
- record an accounting transmission and receive a LedgerIQ result;
- manage leave types, working calendars, holidays, and leave entitlements;
- delete an attendance record;
- cancel a payment batch.
Role summary
Section titled “Role summary”| Area | Payroll Operator | Approver | Payment Reviewer | Reporter | Administrator |
|---|---|---|---|---|---|
| Employee directory | Yes | Yes | Yes | Yes | Yes |
| Compensation and payroll components | Yes | View | No | No | Yes |
| Payroll runs, results, payslips | Yes | Yes | No | No | Yes |
| Finalize payroll | Yes | Yes | No | No | Yes |
| Advances: view | Yes | Yes | No | No | Yes |
| Advances: request, issue, repay | Yes | No | No | No | Yes |
| Advances: approve | No | Yes | No | No | Yes |
| Advances: corrections | No | No | No | No | Yes |
| Attendance and leave: view | Yes | Yes | Yes | Yes | Yes |
| Attendance recording; leave request | Yes | No | No | No | Yes |
| Leave approval; consequence approval | No | Yes | No | No | Yes |
| Leave types, calendars, holidays, entitlements | No | No | No | No | Yes |
| Payroll consequences: propose | Yes | No | No | No | Yes |
| Payments: view | Yes | Yes | Yes | No | Yes |
| Payments: prepare and process | Yes | No | No | No | Yes |
| Payments: confirm paid and fail | No | No | Yes | No | Yes |
| Payments: submit and lock a batch | No | Yes | No | No | Yes |
| Payments: reversal and batch cancel | No | No | No | No | Yes |
| Accounting handoffs: view | Yes | Yes | Yes | Yes | Yes |
| Accounting handoffs: content and key | Yes | Yes | No | No | Yes |
| Accounting handoffs: record transmission | No | No | No | No | Yes |
| Reports | All | All | Five | Eight non-monetary | All |
| Rename workspace | No | No | No | No | Yes |
Access rules that apply to everyone
Section titled “Access rules that apply to everyone”- One workspace at a time. You only ever see records in your current workspace.
- Foreign records are hidden. A record belonging to another workspace behaves as if it does not exist.
- Read is not write. Being able to see a screen does not grant the actions on it; the actions are gated separately by role and by the record’s state.
- Role is per workspace. Your role in one company does not carry to another.
If you think you need a different role
Section titled “If you think you need a different role”Contact your workspace Administrator. Administrators can change member roles in Settings → Users & access, with confirmation and recorded history. Their own role obeys the same rules: the last active Administrator cannot be demoted, deactivated or removed. An Administrator in one company cannot manage another company without an active Administrator membership there. No invitation email is sent; new users receive explicitly supplied passwords shared securely.