Roles

Who may see and decide what in MetronHR?

Four roles form the basic grid: CEO, HR, Accounting and Employee. They decide access to the pages of the application. Alongside them sit five cases that take effect independently of the role: supervisors, department managers, project owners and the specifically set approvers for shift requests and for overtime payouts.

As at:September 2026

The four roles

Everyone in the business carries exactly one of the four roles. The role decides which pages they may open, and where a page is open to several roles it additionally decides the scope of the data: the same page, but their own row instead of all rows.

That is stored in a matrix with 41 entries that records page by page who may enter. It is the first check, not the only one: what somebody gets to see in terms of people, clients and services is then decided by a second level.

The four roles and what they stand for in the business.

  • CEO

    Who that usually is
    The owner or management.
    What it is intended for
    The business settings, the plan, deletion and everything concerning the tenant as a whole.
  • HR

    Who that usually is
    HR, the office, practice management.
    What it is intended for
    People, contracts, absences, public holidays and employee protection.
  • Accounting

    Who that usually is
    Accounting.
    What it is intended for
    The reports for payroll and the billing status.
  • Employee

    Who that usually is
    All other employees.
    What it is intended for
    Their own times, their own requests, their own time account.

A role overview with only these four rows would be incomplete. Five further cases grant access without being one of these roles.

Five cases alongside the roles

The four roles do not cover what actually happens in a business: a shift leader approves her team's requests without being HR. For such cases there are five routes that take effect alongside the role and are set independently of it.

Five routes of access that do not depend on one of the four roles.

  • Supervisors

    What it depends on
    On the „reports to“ field of the person reporting to them.
    What it opens
    Approvals, change requests, clients and services, the day plan.
  • Department manager

    What it depends on
    On the management of a department.
    What it opens
    Client, service and project views.
  • Project ownership

    What it depends on
    On responsibility for a project.
    What it opens
    The project reports for exactly that project.
  • Approvers for shift requests

    What it depends on
    On a setting of its own in the shift module.
    What it opens
    Swap requests, applications for open shifts and block handovers.
  • Approvers for overtime payouts

    What it depends on
    On a business setting, either by named people or by role.
    What it opens
    The decision on payout requests.

The group for shift requests belongs to the shift module and therefore to the Professional plan. The other four cases depend on no plan.

What a supervisor may and may not do

The relationship „is supervisor of“ is a field on the member and not a role. It is set on the person reporting, and only active reports count towards it.

It is enabled expressly per page, not across the board. Today there are four pages: the central approvals page, the change requests in the time tracking, the client list and the day plan. Where that switch is missing the relationship has no effect, even if the person has ten people under them.

And it grants access, not data ownership. Deciding and viewing within the scope of the respective page, yes. Changing master data or contracts, no. Anyone needing that needs the HR role.

  • If the „reports to“ field points to the person themselves, the request counts as approved by them. That special case is expressly handled in the product and is not a side effect.
  • Inactive reports do not count. Anyone who has left the business makes nobody a supervisor.

The steps here describe a running system. Anyone who does not have one yet sets it up during the trial and keeps everything created along the way.

The central approvals page

One page bundles the open requests the signed-in person is responsible for. Anyone opening it does not see everything open in the business but what is waiting for their own decision.

It is open to management, HR and accounting as well as to supervisors with direct reports. The individual request types themselves, that is absence, time change, overtime payout, shift swap and block handover, have rules of their own and are described under their respective topic.

  1. Open the approvals page. It shows the requests you are responsible for.
  2. Check the request and decide. The rules of the individual request type are described under their topic, not on this page.
  3. For requests that do not appear here, open the relevant area: shift requests and payouts have their own groups of approvers.

Recording on behalf of others

Time entries can be created for others where the permission exists. That is checked on the server, and twice over: whether somebody may record for others at all and for which people specifically.

The difference matters more than it sounds. The list of selectable people is not filtered in the browser but determined on the server. A choice that does not appear there is not a hidden possibility but a refused one.

The same pattern applies to absences. Who may make a request for whom is described in the guide to holiday.

Who sees which people, clients and services

The role matrix answers the question „may this person open this page“. It does not answer the question „which rows appear on it“. For that there is a second level with two checking modules: one for people, one for the assignment of clients and services.

In practice that means two people with the same role can open the same page and see different things on it, depending on the department, their reports and the clients assigned. That is deliberate and not the consequence of a forgotten setting.

Follow-up questions

Can somebody hold two roles at once?
No. Everyone carries exactly one of the four roles. What looks like a second role in practice is the five cases alongside: supervisor, department manager, project ownership and the two groups of approvers. They are set separately and take effect in addition to the role.
Do I have to make somebody HR so that they can approve holiday?
No. For that it is enough to enter them as supervisor of the people concerned. That gets them to the approvals page and lets them decide their team's requests, without gaining access to master data and contracts.
Why does my department manager see the client list but not the personnel file?
Because the two routes of access open different things. Managing a department reaches client, service and project views. The personnel file depends on the HR role, and department manager is not a role.
Who decides on paying out overtime?
A group the business sets itself, either by named people or by role. It is independent of the role matrix, and it is not the same as the group for shift requests.
Can two people with the same role see different things?
Yes. The role decides access to the page, and a second level decides the rows on it. The department, the reports and the clients and services assigned all feed into that.

Describes the state of the application onSeptember 2026. What changes in the product is in the product updates.

wissen.ugur_aydogan_produktentwicklung_bei

Published by: AMNAU GmbH

Editorial responsibility: Ugur Aydogan, Product development.

Last reviewed: September 2026

Reading up is one thing. Setting it up yourself takes an afternoon.

MetronHR records working time at the terminal, in the app and in the browser, keeps holiday and overtime up to date and files the month ready to go. Try it free for 14 days.

No credit card, cancel at any time