> ## Documentation Index
> Fetch the complete documentation index at: https://help.gowindmill.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Permissions and Access

> Understand Windmill roles, manager scope, delegated access, and the visibility rules that control what each member can see and manage.

Windmill uses several controls together to determine access. A member's **role** controls workspace administration. The org chart defines manager scope. Each feature and connected system can also apply its own visibility rules.

## Roles and capabilities

Windmill has five roles: **Admin**, **HR Admin**, **Integration Manager**, **Data Analyst**, and **Team Member**.

Managers do not have a separate role. A Team Member can be a manager when the org chart gives them direct or indirect reports.

| Capability                                 | Admin | HR Admin | Integration Manager | Data Analyst | Team Member |
| ------------------------------------------ | ----- | -------- | ------------------- | ------------ | ----------- |
| Invite members across the company          | Yes   | Yes      | Yes                 | No           | No          |
| Change member roles                        | Yes   | Yes      | Yes                 | No           | No          |
| Manage billing                             | Yes   | Yes      | Yes                 | No           | No          |
| Manage SSO settings                        | Yes   | Yes      | Yes                 | No           | No          |
| Connect and configure company integrations | Yes   | Yes      | Yes                 | No           | No          |
| Manage the org chart                       | Yes   | Yes      | No                  | No           | No          |
| Manage groups                              | Yes   | Yes      | No                  | No           | No          |
| Manage access delegation                   | Yes   | Yes      | No                  | No           | No          |
| Manage performance review cycles           | Yes   | Yes      | No                  | No           | No          |
| Send a Pulse to the whole company          | Yes   | Yes      | No                  | No           | No          |
| View analytics for all employees           | Yes   | No       | No                  | Yes          | No          |

<Note>
  When **Allow managers to invite reports** is enabled in **Settings > Security**, managers can invite direct and indirect reports as Team Members. This permission does not let a manager invite people outside their reporting subtree or assign an administrative role.
</Note>

### Admin

Admins have all workspace capabilities. They can manage company settings, integrations, members, roles, billing, the org chart, groups, and company features.

Admin status does not by itself provide unrestricted access to all employee content. Source permissions and feature-specific privacy rules still apply.

### HR Admin

HR Admins can manage people operations and many company settings. This includes members, roles, billing, single sign-on (SSO), integrations, the org chart, groups, access delegation, performance review cycles, company-wide 1:1 templates, and supported company features.

HR Admin status does not provide the company-wide analytics permission. It also does not provide unrestricted access to employee content.

### Integration Manager

Integration Managers can manage company integrations, members, roles, billing, and SSO settings. They cannot manage the org chart, groups, access delegation, or performance review cycles. They do not get company-wide employee visibility from this role.

### Data Analyst

Data Analysts can view analytics for all employees. They cannot manage members, billing, integrations, the org chart, or other company settings.

### Team Member

Team Members use the standard Windmill features that their company enables. They can view their own information. Managers can also view supported information for people in their reporting subtree.

## Changing a member's role

Admins, HR Admins, and Integration Managers can change roles.

<Steps>
  <Step title="Go to Settings > Members">
    Open [Members](https://app.gowindmill.com/COMPANY/config/members).
  </Step>

  <Step title="Open the member actions menu">
    Find the member and select **Change role** from the row actions menu.
  </Step>

  <Step title="Select the new role">
    Review the role description, then select the role that the member needs.
  </Step>

  <Step title="Update the role">
    Select **Update role** to save the change.
  </Step>
</Steps>

<Warning>
  An Admin has all workspace capabilities. Only assign this role to a trusted member who needs full workspace administration.
</Warning>

## Org chart scope

The org chart defines each manager's reporting subtree. This scope includes direct and indirect reports.

The reporting subtree is one input to access. It does not override feature privacy or source-system permissions. For example, a manager relationship does not provide access to a private Google document, a private Slack channel, or private 1:1 content.

If an employee has no manager, no upstream manager receives access through the org chart. This is normal for a top-level leader. Other role and feature permissions can still apply.

### Manager changes

A manual manager change updates the old and new reporting scopes.

## Content visibility

Windmill combines these rules when it checks content access:

* **Workspace role:** Controls administrative actions and specific broad permissions, such as company-wide analytics.
* **Org chart:** Defines manager and reporting-subtree scope.
* **Feature rules:** Reviews, Pulses, 1:1s, Recaps, and other features can have their own sharing and privacy settings.
* **Source permissions:** Connected content can keep the access rules from its source system.
* **Delegation:** Adds supported manager-like visibility for a selected reporting scope.

An administrative role does not replace the other controls.

## 1:1 auditability

1:1 content is private by default. Admin or HR Admin status alone does not provide access to all 1:1 notes.

When 1:1 auditability is enabled, Windmill can provide read-only access to shared manager-and-report 1:1 history:

* Managers can audit 1:1s in their reporting subtree when manager audit access is enabled.
* HR Admins can audit all manager-and-report 1:1s when HR Admin audit access is enabled.

Audit access does not include Private Notes, participant-specific prep topics, Catch Me Up reports, or recording access.

## Access delegation

Access delegation gives one member supported manager-like visibility into another person's reporting subtree. The delegated member can see that person and everyone who reports up to them, directly or indirectly — the same downward scope a manager has. It does not extend upward: the delegated member does not gain visibility into anyone above that person in the org chart. It is useful for an interim manager, an assistant, or a People team member who needs a specific reporting scope without an org-chart change.

### Delegation limits

Delegation can provide access to supported team data, Recaps, and reports. It does not:

* Provide access to 1:1 notes or agendas
* Change Google document or meeting permissions
* Change Slack channel membership
* Let the delegated member impersonate another member
* Add permission to edit Pulses or company settings
* Override feature-specific privacy rules

### Adding delegation

Admins and HR Admins can add delegation. The manager and the member who receives access must each have an employee record.

<Steps>
  <Step title="Go to Settings > Access Delegation">
    Open [Access Delegation](https://app.gowindmill.com/COMPANY/config/access-delegation).
  </Step>

  <Step title="Select Add delegation">
    Start a new delegation rule.
  </Step>

  <Step title="Select the manager scope">
    Choose the manager whose reporting scope you want to share.
  </Step>

  <Step title="Select the member who gets access">
    Choose the member who needs the delegated scope, then select **Delegate access**.
  </Step>
</Steps>

Delegation always resolves against your current org chart, not a snapshot taken when the rule was created. As people move in or out of that person's reporting subtree, the delegated scope follows along. Changes — including saving or removing a rule — take effect within about an hour.

### Removing delegation

To remove access, go to **Settings > Access Delegation** and delete the delegation rule. Windmill starts another access refresh after you save the change.

## Connected-system permissions

For connected content that has source-level access controls, Windmill keeps that permission context. Examples include:

* A private Google document stays limited to people who can access it in Google Drive.
* A meeting transcript stays limited by the meeting and source access rules.
* A private Slack channel does not become visible to people outside that channel.

Some integrations provide company-level activity or usage data instead of user-scoped content. Those integrations use the applicable Windmill feature permissions. For example, Admins and Data Analysts can view company-wide analytics.

## FAQs

<AccordionGroup>
  <Accordion title="What is the difference between Admin and HR Admin?">
    Admins have all workspace capabilities. HR Admins have broad people-operations and company-setting capabilities, but they do not have every Admin capability. For example, HR Admins do not receive company-wide analytics access from their role.
  </Accordion>

  <Accordion title="Can I give temporary access without changing a role?">
    Use access delegation when someone needs a supported manager reporting scope. Windmill does not set an end date for a delegation rule. Remove the rule when the access is no longer required.
  </Accordion>

  <Accordion title="Can I provide company-wide analytics without Admin access?">
    Yes. Assign the Data Analyst role. This role provides analytics for all employees without workspace administration permissions.
  </Accordion>

  <Accordion title="What happens to access when someone changes managers?">
    When a member's manager changes in your HRIS or org chart, their old manager loses access to their data within 24 hours. The new manager gains access immediately.
  </Accordion>

  <Accordion title="Who can see an employee's weekly recap?">
    The employee can see their own Recap. Managers can see Recaps in their reporting scope. A member with the applicable delegated scope can also see the Recap. HR Admin status alone does not provide access to every employee's Recap.
  </Accordion>

  <Accordion title="Who can add integrations?">
    Admins, HR Admins, and Integration Managers can create and manage company integrations. Any member can create a personal integration if they have the required permission in the connected system.
  </Accordion>

  <Accordion title="Do archived employees lose access immediately?">
    Yes, when an employee is archived in Windmill or your HRIS, they lose access to the Windmill Dashboard immediately. However, historical data (like past feedback and recaps) is preserved.
  </Accordion>

  <Accordion title="Why can I not change or remove the last Admin?">
    Windmill requires at least one active Admin. Assign the Admin role to another active member before you change or remove the last Admin. A member also cannot remove their own member access.
  </Accordion>

  <Accordion title="Can I create a custom role?">
    Windmill provides Admin, HR Admin, Integration Manager, Data Analyst, and Team Member roles. Contact [support@gowindmill.com](mailto:support@gowindmill.com) if your organization needs a different access model.
  </Accordion>
</AccordionGroup>
