Skip to main content

Security Roles and Permissions

Updated yesterday

Note: This is a very powerful feature that enables Super Users within your company to change the configuration of your company instance - only make changes you fully understand the implication of. If you need help, please contact support.

If you make changes to your roles and permissions, users will need to logout and log back in for those permissions to be enabled on their session.

BrightMove uses a robust security model based on Role-Based Access Control (RBAC) to ensure data privacy and control. Access to the system is granted through a combination of user types, roles, and permissions.

  • Roles: A role defines a set of access privileges. Each user can be assigned multiple roles to allow for more granular control. Roles can have 0 to many permissions associated with them.

  • Permissions: These are specific actions or data access rights. Roles control which permissions a user has.

  • Admins: Typically granted permissions to manage high-level system settings, such as Company Settings and employee/user management. This allows them to oversee and adjust platform configurations on an organizational level.

  • Recruiters: Generally have access to functionalities focused on recruitment tasks but often are restricted from administrative controls.

By leveraging RBAC, BrightMove allows administrators to tailor access and permissions, ensuring each user has only the access they need. Role configurations may vary by organization and are often customized to meet specific operational needs, allowing for tailored permissions and access control.

Managing Roles

To manage security roles, go to Settings > Security

From the Security link you can manage roles.

From the Employees link, you can associate 0 to many roles to your users.

Granting Administrator Access

If a full user requires the Administrator role and does not currently have it, the following process can be followed:

  1. Approval by an Existing Admin: Only a current Admin can authorize the granting of Administrator permissions to another user.

  2. Request Submission: The request must be initiated and approved by an Admin via email to BrightMove support or through a designated organizational representative.

  3. Support Restrictions: BrightMove support will not process requests to grant Admin access unless explicitly approved by an existing Admin. This ensures compliance with organizational security policies.

From the Company Roles screen, you can add, edit, duplicate and delete security roles.

Managing Permissions

From within the selected role, you can pick and choose the permissions that should be enabled for your scenario.

For example, in the screen below, the role Recruiter does not have the Opportunity module permissions. You can tell this by the red X next to the permissions. If you wish for the users with the Recruiter role to have this permission, simply enable the permission by selecting it, and click save.

Any user with this role will now have access to the Opportunity module in this scenario.

Did this answer your question?