Article Contents
- Introduction
- Global Administrator
- Individual Access Privileges
- Address Book
- Asset Register
- Email Archive
- Financial
- Human Resources
- IMS
- Plan Register
- Projects
- Templates
- Timesheets
- Users
- Who's In?
Introduction
Hiro's user privileges system ensures controlled access throughout your organisation to your sensitive data and workflows. Users can either be Global Administrators with full access to all parts of Hiro or be granted specific permissions for particular tasks.
Global Administrator
The first person to set up Hiro in your organisation automatically becomes a Global Administrator. This role grants complete access to all parts of Hiro and the ability to manage user privileges.
As a Global Administrator, you do not need additional access permissions. You have full access to everything in Hiro.
Your organisation must always have at least one Global Administrator. If you need to step down, assign another Global Administrator via the User Privileges & Notifications page before removing yourself.
Individual Access Privileges
New users created in Hiro's User Accounts page start with no access privileges. They can perform basic tasks but cannot access sensitive functions like approving invoices or viewing financial reports until granted specific privileges.
Only Global Administrators can assign these privileges on the User Privileges & Notifications page. Each individual privilege type is outlined below, together with the actions it allows.
For information about configuring notifications, view this article.
Address Book
| Privilege Type | Description |
| Change financial accounts |
|
| Merge contacts | Can merge different contacts together on the Merge Contacts page. |
| Generate ABN checking override codes |
Can generate ABN checking override codes on the Override Codes page. Learn more about what ABN checking override codes are used for in this article. |
Asset Register
| Privilege Type | Description |
| Access to Asset Register | By default, only Global Administrators can access the Asset Register. To allow someone else to access it, grant them this privilege. Once granted, they will be able to add and edit assets in Hiro. |
Email Archive
| Privilege Type | Description |
| Search for and download any email |
By default, users are only able to view and download emails in the Email Archive if they are part of the project team for the project that email is tagged to. Grant someone this privilege to enable them to retrieve any archived email, regardless of project. |
Financial
| Privilege Type | Description |
| Approve and process invoices |
Applies to the central Invoices workflow. Allows users to:
Does not grant access to:
Project visibility is controlled separately. |
| Perform invoice credit/reissues | Access to the Credit/Reissue Invoice page is restricted to users who hold this privilege. |
| Access financial reports and analyses |
By default, users can only access financial reporting data that is relevant to them. For example:
Grant this privilege to allow someone to:
This privilege does not allow someone to approve or send invoices, or apply payments. |
Human Resources
| Privilege Type | Description |
| Access Licences and Training Register |
Access to the Licences and Training Register is entirely blocked unless granted this privilege. Note that the ability to view/modify individual licence and training items assigned to staff is thereafter configured within that item's individual access permissions in the Register. |
| Modify Positions Register |
Access to the Positions Register is limited for non-privileged users, where they can view basic position information including position descriptions. The ability to add/modify positions and their associated position descriptions in the Positions Register is granted with this privilege. |
| Access and modify payroll (incl. Payroll Spreadsheet) |
Granting someone this privilege enables the ability to:
|
| Prepare Productivity Reports | Ability to access and generate Productivity Reports |
| Prepare Employee Performance Reports | Ability to access and generate Employee Performance Reports |
IMS
| Privilege Type | Description |
| IMS Coordinator/s | Lists the selected users as IMS Coordinators on the Management System page and gives them access to manage incidents. |
| Manage IMS documents | Allows users to view all controlled-document versions and formats, edit documents, publish new versions and access IMS document reporting. |
| Generate IMS field books | Allows users to generate IMS field books. |
| Manage Legal and Compliance Register | Allows users to manage items in the Legal and Compliance Register. |
| Manage Hazardous Chemicals | Allows users to manage items in the Hazardous Chemicals Register. |
Plan Register
| Privilege Type | Description |
| Provision plans |
Grants the ability to provision new plan numbers into provisioning pools in the Plan Register. |
| Allocate plans |
Grants the ability to allocate plan numbers onto projects in the Plan Register. |
| Upload plans |
Grants the ability to upload plan documents onto already allocated plan numbers within the Plan Register. |
Projects
| Privilege Type | Description |
| Edit all projects |
Allows users to:
Does not grant:
View Project access remains separately controlled by project team membership, View full details across all projects, and Project invoice information access. |
| View full details across all projects |
Accessing project information, such as timesheets, invoices and to-dos, is ordinarily restricted to members of that project's team. This privilege overrides Project invoice information access, including when it is set to No-one. By itself, this privilege does not allow users to edit projects or create, edit, approve, send or process invoices. Regardless of project team membership, granting this privilege enables the ability to:
|
| Project invoice information access |
Controls who can see the following within View Project:
The setting can allow:
Global Administrators and users with View full details across all projects override the selected level. Edit all projects and Approve and process invoices do not. |
Templates
Each individual template configured on the Templates page can be assigned who is allowed to access and modify that template.
Assigning the view / modify privileges enables someone to override the per-template permissions. For example, if someone has not been granted modify permissions on a particular template, they can still change it if they have been granted the "Edit all" template privilege.
Timesheets
| Privilege Type | Description |
| Bulk Move WIP |
By default, you can only use the Bulk Move Timesheets tool to move WIP timesheets onto a project that you are captain of. Grant someone this privilege to enable moving timesheets:
Learn more about the Bulk Move Timesheets tool in this article. |
| Backdate rates onto timesheets allocated to invoices |
Existing timesheets can have their charge rates recalculated to match updated rates in:
By default, backdating only applies to timesheets that are unallocated to an invoice (that is, those still in WIP status). Granting this privilege enables a user to also backdate and recalculate rates for timesheets already allocated to an invoice. |
| View or modify other people's timesheets | Who can view or modify each person’s timesheets is configured per person on the User Accounts page. |
Users
| Privilege Type | Description |
| Confidential staff info |
Granting this privilege enables the ability to:
This privilege does not grant user-account management, curriculum vitae editing, Licences & Training access or general access to other people’s timesheets. Organisation-wide Service milestone email reminders are configured separately under notifications. |
| Modify staff curricula vitae | Enables modifying anyone's curricula vitae on the Staff page. |
| Add/modify/delete users | Enables creating, modifying and removing user accounts via the User Accounts page in Settings. |
| Change user profile pictures | Enables changing a user profile picture for a user account via the User Accounts page in Settings, without the ability to otherwise modify the details of that person's user account. |
Who's In?
| Privilege Type | Description |
| Edit day properties |
This enables someone to modify two types of special properties on a day in Who's In?:
You can learn more about configuring public holidays and close-down periods in this article. |
| View full transaction details |
By default, non-privileged users only see the name of someone who’s been marked as away in the Who’s In? calendar. When you grant this privilege to someone, they can see the full details about someone being away – e.g., what type of leave they’re on, who approved the request, what date the request was approved, etc. |
| Edit/delete transactions | This enables someone to modify an existing leave entry in the Who’s In? calendar – e.g., being able to change the type of leave, or delete it from the calendar. |
| View other managers’ pending approvals |
By default, leave requests are sent to the person assigned as the employee’s Manager on the User Accounts page. The Manager can approve or deny the request. You can also configure Other leave approvers for an individual employee. These people can action the employee’s leave requests alongside their Manager. Learn more about configuring additional leave approval access. Granting someone the View other managers’ pending approvals privilege gives them broader access. They can view, approve or deny pending leave requests for anyone in the organisation, regardless of whether they are the employee’s Manager or an Other leave approver. This organisation-wide privilege is best suited to people who centrally administer leave requests. |