Skip to content

Roles & access

Every payIQ membership gives you exactly one role in a workspace. Your role decides what you can see and do there. A user can hold different roles in different workspaces — your role is shown in the header and in Settings.

payIQ has five roles:

  • Payroll Operator
  • Approver
  • Payment/Reconciliation Reviewer
  • Read-only Reporter
  • Administrator

The working payroll and operations role. A Payroll Operator can maintain employees, compensation, and payroll components; create, calculate, and finalize payroll runs; request, issue, repay, and plan advances; record attendance; create and submit leave requests; propose payroll consequences; prepare and process payment instructions; and see the full report catalogue.

A Payroll Operator cannot approve an advance, approve leave or a payroll consequence, confirm a payment, or reverse a confirmation. Keeping preparation and approval apart is deliberate.

The review and approval role for payroll operations. An Approver can approve advances, approve or reject leave, approve payroll consequences, finalize payroll runs, and submit and lock payment batches. An Approver can view payroll detail and the full report catalogue, including compensation columns.

The reconciliation role for payments. A Payment/Reconciliation Reviewer can confirm a payment as paid, record a failure, and complete a batch. They see payment instructions and batches, the payment amounts, and the reconciliation position — but not the payroll or advance source linkage behind an instruction. Their report set is limited to the employee directory, payment reports, the payments summary, and accounting handoffs.

A deliberately non-monetary read-only role. A Read-only Reporter can view the employee directory (without compensation), accounting handoffs, attendance, and leave, and can run eight non-monetary reports. The reporter role exists for people who need operational counts and statuses but should not see pay amounts.

Full access. In addition to everything above, an Administrator is the only role that can:

  • create, rename, archive and reactivate workspaces;
  • add existing users, create users with validated passwords, and administer memberships and roles;
  • record advance corrections and payment reversals;
  • record an accounting transmission and receive a LedgerIQ result;
  • manage leave types, working calendars, holidays, and leave entitlements;
  • delete an attendance record;
  • cancel a payment batch.
Area Payroll Operator Approver Payment Reviewer Reporter Administrator
Employee directory Yes Yes Yes Yes Yes
Compensation and payroll components Yes View No No Yes
Payroll runs, results, payslips Yes Yes No No Yes
Finalize payroll Yes Yes No No Yes
Advances: view Yes Yes No No Yes
Advances: request, issue, repay Yes No No No Yes
Advances: approve No Yes No No Yes
Advances: corrections No No No No Yes
Attendance and leave: view Yes Yes Yes Yes Yes
Attendance recording; leave request Yes No No No Yes
Leave approval; consequence approval No Yes No No Yes
Leave types, calendars, holidays, entitlements No No No No Yes
Payroll consequences: propose Yes No No No Yes
Payments: view Yes Yes Yes No Yes
Payments: prepare and process Yes No No No Yes
Payments: confirm paid and fail No No Yes No Yes
Payments: submit and lock a batch No Yes No No Yes
Payments: reversal and batch cancel No No No No Yes
Accounting handoffs: view Yes Yes Yes Yes Yes
Accounting handoffs: content and key Yes Yes No No Yes
Accounting handoffs: record transmission No No No No Yes
Reports All All Five Eight non-monetary All
Rename workspace No No No No Yes
  • One workspace at a time. You only ever see records in your current workspace.
  • Foreign records are hidden. A record belonging to another workspace behaves as if it does not exist.
  • Read is not write. Being able to see a screen does not grant the actions on it; the actions are gated separately by role and by the record’s state.
  • Role is per workspace. Your role in one company does not carry to another.

Contact your workspace Administrator. Administrators can change member roles in Settings → Users & access, with confirmation and recorded history. Their own role obeys the same rules: the last active Administrator cannot be demoted, deactivated or removed. An Administrator in one company cannot manage another company without an active Administrator membership there. No invitation email is sent; new users receive explicitly supplied passwords shared securely.