Table of Contents
- What is the Feature Access Matrix?
- Default access roles
- Custom access roles
- When to use Access roles and the Feature Access Matrix
- How to navigate to the Feature Access Matrix
- How to use the Feature Access Matrix
- How to manage Access roles
What is the Feature Access Matrix?
The Feature Access Matrix is the central place in Leapsome where admins control which features and actions each user role can access. The matrix gives you a single, consolidated view of all configurable permissions across the platform, organized by role.
Every permission toggle you see in the matrix maps to a specific capability: for example, the ability to create a review cycle, export the employee list, view the org chart, or access the Compensation module. You can enable or disable each capability independently for each role.
The matrix works together with Leapsome's access roles. A role is a named permission set that can be assigned to users. When you update a role's permissions in the matrix, all users assigned to that role are affected immediately.
Default access roles
Leapsome includes a set of default access roles that reflect the most common organizational structures. These roles cannot be deleted, but their permissions can be adjusted in the Feature Access Matrix (except for Super Admin, which always has full access).
| Role | Description |
|---|---|
| Everyone | Baseline permissions for all active users. Applies to all employees regardless of other roles assigned. |
| Manager | Users with direct reports. Can typically access data for their direct reports within enabled modules. |
| Team Lead | Users assigned as team leads in Leapsome. Similar to manager, but scoped to their team. |
| HRBP | HR Business Partner. A scoped role where the user's access is limited to a defined population of employees. Scope is set on the individual user's profile. |
| Admin | Has broad access to settings and features. Permissions are configurable in the Feature Access Matrix. |
| Super Admin | Has full access to all settings and data. Cannot be restricted via the Feature Access Matrix. |
Note: The HRBP role does not appear in the 'Access roles' list under Settings. It is assigned directly on the user's profile under 'Role' and its scope is defined there (shown below). However, HRBP permissions are still configurable in the Feature Access Matrix.
Custom access roles
In addition to the default roles, you can create custom access roles to cover use cases that the defaults do not address. Custom roles let you grant a specific combination of permissions to a group of users, with or without a defined user scope.
Common examples include:
- An HRBP-style role scoped to a specific location or country
- A 'Learning Creator' role for employees who can create learning content but have no other admin access
- A 'Compensation Reviewer' role for managers who can manage compensation proposals within their team
- An 'Onboarding Manager' role with permission to create and invite new employees
Custom roles can also be used as approvers in approval flows and as participants in access-controlled features across modules.
When to use access roles and the Feature Access Matrix
Use the Feature Access Matrix when you want to:
- Enable or disable a feature for a specific group of users (for example, allow managers to view review analytics for their team)
- Grant a non-admin user access to a specific admin capability without giving them full admin rights
- Restrict a default role from accessing a feature that is on by default
- Create a targeted role for HR Business Partners, regional managers, or module specialists
Use the 'Access roles' page (Settings > Employees > Access roles) when you want to:
- Create a new custom role with a specific permission set
- Review which users are assigned to a role
- Define the scope of a role (which employees a user with that role can see and act on)
- Manage document category access or attribute read / write access for a role
How to navigate to the Feature Access Matrix
- Go to 'Settings' in the left navigation.
- Click 'Employees'.
- Select 'Feature access matrix'.
To navigate to access roles:
- Go to 'Settings'.
- Click 'Employees'.
- Select 'Access roles'.
How to use the Feature Access Matrix
Enabling and disabling permissions per role
The matrix is organized into sections that reflect the modules and settings areas in Leapsome (for example: Employee profiles and list, Reviews, Surveys, Compensation, or Payroll). Each section can be expanded to reveal the individual permissions it contains.
Each permission row shows the default roles as columns. To change whether a role can access a specific feature:
- Find the relevant permission using the search bar or by expanding the relevant section.
- Click the toggle for the role you want to update.
- Save your changes.
Changes take effect immediately for all users assigned to that role.
Important constraints:
- Some permissions that would give a role global access to all users' data (for example, launching a review cycle for all employees) cannot be enabled for roles such as Everyone or Manager. This is a safeguard to protect data security and compliance.
- Super Admins always have all permissions enabled and cannot be restricted via the matrix.
- Export permissions (for example, 'Export employee list') should be reviewed carefully, as they can expose large datasets. Export access requires that view access for the same data is also enabled.
Understanding scoped permissions
Several permissions in the matrix work differently depending on whether the role has a user scope defined. A scoped permission means the user can only perform that action for the employees in their defined scope, not for all employees.
For example:
- A Manager with 'Create review cycles for users within their scope' enabled can launch a review cycle, but only for their direct reports.
- An HRBP with 'View the employee list' enabled can only see employees in their assigned scope.
- A custom role with a location-based scope can only access data for employees in that location.
Scoped permissions are particularly relevant for HRBP-style roles and custom roles with a defined user scope.
Recent addition: Users with scoped roles (HRBPs or custom roles) can now create review cycles using existing templates and send surveys to users within their scope. These permissions are available in the Reviews and Surveys sections of the matrix.
AI features section
AI-related feature access is configured in its own section of the matrix, called 'AI features'. This section covers access to Leapsome AI (Leapy), AI features within Reviews (such as calibration pre-read and AI-assisted writing), and any other AI capabilities enabled for your workspace.
For more detailed information on AI in Leapsome, please visit here.
How to manage Access roles
Viewing and editing an access role
Go to Settings > Employees > Access roles. Click any role to open its detail page. The detail page is organized into the following tabs:
Basics
Enter or update the role name. This is the only required field when creating a role.
Users with this role
Shows the number of users assigned to the role. Click to open a modal listing all assigned users. From the same modal, you can add or remove users. Changes are saved in bulk when you click 'Save'.
User scope
Defines which employees a user with this role can access. The default is 'none', meaning there is no scope restriction and the role's permissions apply globally. If you want to limit the role to a specific population (for example, employees in a specific team, location, or matching a custom attribute), configure the scope here.
For user-based scopes (where the accessible population is defined individually per user rather than by a fixed rule), the scope is set on the individual user's profile, not here.
Permissions
Shows all permissions currently enabled for the role, as well as other permissions that can be assigned. Permissions are grouped by category. If the role has a recommended permission set (for example, for a standard HRBP or manager role), a button to load the suggested permissions is shown.
Select or deselect permissions using the checkboxes, then click 'Save'. A preview modal shows the changes before you confirm.
Documents
Shows document categories and the access level (view / upload / delete) granted to the role for each category. Adjust the settings and save. A preview modal is shown before saving. Please note, the document categories themselves are managed via 'Settings' > 'Documents' > 'Document categories'.
Attributes
Shows all employee profile attributes and the read / write access level granted to the role. Adjust as needed and save with a preview modal. Please note, attributes themselves are managed via 'Settings' > 'Employees' > 'Profile fields and access'.
Creating a custom access role
- Go to Settings > Employees > Access roles.
- Click 'Add role'.
- Enter a role name on the Basics tab.
- Go to the Permissions tab and select the permissions you want to enable.
- Optionally, configure document and attribute access on the Documents and Attributes tabs.
- Optionally, set a user scope on the User Scope tab.
- Save your changes.
- Go to Settings > Employees > Feature access matrix to verify and adjust the role's permissions in the matrix view if needed.
- Assign the role to users via the Users with this role tab, or via individual user profiles.
Setting the user scope for a role
A user scope limits which employees a user with the role can see and interact with. There are two types:
- Role-based scope: The population is defined by a rule, for example all employees in a specific location, team, or matching a custom attribute. This is configured on the User Scope tab of the role.
- User-based scope: The population is defined individually for each user who holds the role. This is configured on the individual user's profile under 'Role' > the custom role name. Use this type when different users with the same role need access to different people.
Scoped roles work together with the permissions in the Feature Access Matrix. If a permission is enabled for a scoped role, the user can only perform that action for the employees in their scope.
For custom roles with a role-based scope, 'OR' logic for multi-criteria scopes (for example, Team A or Location B) is supported. Users will see all employees matching any of the defined criteria.
Managing document and attribute access
Document category access and employee attribute access are managed separately from the main permission toggles. These are configured on the Documents and Attributes tabs of the access role detail page.
For document categories: you can grant view, upload, and / or delete access per category. A user can only upload documents to a category if they also have view access.
For employee attributes: you can grant read and / or write access per attribute. If you enable write access without read access, read access will be added automatically.
Note: The 'View the change log on the user profile' permission (under Employee profiles and list in the matrix) controls whether users with a given role can see the change log tab on an employee's profile. This is separate from attribute-level read access. Super Admins always have this enabled.
Assigning access roles to users
Access roles are assigned on the user's profile:
- Go to the employee's profile.
- Click 'Role' or 'Additional roles'.
- Select the role to assign.
- Save.
Module admin roles (such as Surveys module admin) are also assigned from the user's profile under 'Role'.
As soon as a role is assigned, the user gets all permissions associated with that role. There is no delay.
Bulk-assigning access roles
For large teams, you can bulk-assign user-scoped access roles via the Leapsome public API. The endpoint allows you to:
- Fetch all available access roles in your account
- Update a specific user's access scope, specifying the role and the list of users that person should have access to
This is particularly useful for onboarding or restructuring scenarios where many users need the same scoped role assigned at once.
For assigning a role to users without a scope requirement, use the 'Users with this role' tab on the role's detail page to add multiple users in one step.