# Users and Roles

Invite somebody into Worklink, give them a role, and restrict an administrator to the offices they actually run.

An employee record says somebody works here. A user says somebody can sign in. This screen is the second of those, split into **Users**, who has access, and **Roles**, what access means.

![The Users tab, headed Users above the line Invite teammates and manage their roles and access, with a blue Invite User button at the right. A Search users box sits below it, above a table with columns User, Roles, Status and Actions. One row reads Eleanor Whitfield, admin@ironvale.com, a Platform Admin role chip, and a green Active status.](https://www.sorviai.com/help/worklink/settings/users-list.png)

*One row per person who can open Worklink, with the role they hold.*

## Invite somebody

- Go to **Worklink Settings > Users & Roles**, then open the **Users** tab.
- Select **Invite User** to open **Invite Team Member**.

  ![The Invite Team Member dialog. First Name and Last Name sit side by side, then Email marked required, a Role picker set to Employee, a Work Location picker reading No location (company default), and a Manages Locations picker reading All locations (no restriction) above the note Restricts an admin to only these offices. Leave empty for access to all locations. Cancel and a blue Send Invite button sit at the foot.](https://www.sorviai.com/help/worklink/settings/invite-modal.png)
- Enter their **Email**. It is the only required field, and it is where the invitation goes.
- Add a **First Name** and **Last Name**, then choose a **Role**.
- Set a **Work Location** if they belong to one office, or leave it on **No location (company default)**.
- Select **Send Invite**.

## Manages Locations, and why it is separate

Work Location is where somebody works. **Manages Locations**, just below it, is which offices they administer, and it appears on the invitation and on **Change Role** alike.

- **Left empty** (the default): No restriction. An administrator with this set sees and manages every office.
- **One or more offices** (a restriction): Narrows an administrator to those offices only. Use it for a regional HR manager who should not be editing another region's people.

> **Note:**
>
> **Manages Locations needs an employee profile**
>
> On **Change Role** the field appears only once the user has an employee record to attach it to. Until then it says so in place, rather than saving a restriction with nothing to apply it to.

## What a role is, and what it covers

![The Roles tab, headed Roles above the line Define roles and the permissions granted to users assigned to them, with a blue Role button at the right. A table with columns Role, Scope, Description and Actions lists Employee (System, Worklink, self-service clock in and out, 19 permissions), HR Admin (Admin, System, Worklink, full access to all attendance modules, 97 permissions), HR Manager (System, Worklink, 34 permissions), Platform Admin (Admin, System, Platform-wide, full administrative access) and Team Lead (System, Worklink, 12 permissions).](https://www.sorviai.com/help/worklink/settings/roles-table.png)

*The Scope column is the one to read: Worklink roles govern this app, a platform-wide role governs everything.*

Adding one opens **New Role**, which asks for a **Role Name**, a **Description** of what the role can do, and then the permissions themselves, granted per module rather than as a single switch. **Back to Roles** returns to the list.

> **Tip:**
>
> **Fill the description in**
>
> "What can this role do?" is the placeholder, and answering it properly is what stops a tenant accumulating four roles nobody can tell apart. The permission grid is the truth, but nobody reads a grid to pick from a dropdown.

## Changing somebody later

The row menu on the Users tab holds one action, **Change Role**. It swaps the role and, where the user has an employee profile, adjusts the offices they manage at the same time. A role's own menu, on the Roles tab, offers **Edit** and **Delete**.

> **Note:**
>
> **A user and an employee are two records**
>
> This screen governs the sign-in. Ending somebody's employment is a separation, handled through Offboarding, and it is not done by editing their user here.
