Purpose
Manage Users is where you decide who can work in your Employer Portal and what they can see. From this page you add portal users, build custom roles, control which sensitive employee fields each role can see, resend registration emails, and hand over the Employer Administrator role. The roles themselves (what an Employer Administrator, a Reporting Manager and a custom role are) are explained in Understanding Roles and Access. Read that first if you are new to UZIO.
Who can do this: the Employer Administrator. Your broker can also manage your users from their portal. Manage Users is not one of the modules a custom role can be granted, so other admins cannot do this for you.
Manage Users is available in the Employer Portal on the web only. The UZIO Mobile App does not include user or role administration.
When to use this
- A new payroll or HR person needs access to the portal.
- An external accountant or auditor needs to see payroll or reports without being an employee.
- A manager needs more than the default Reporting Manager access, or should not see salaries.
- Someone leaves and their access must be removed.
- The Employer Administrator is changing.
The page at a glance
- All Users: everyone with portal access. A user appears once per role they hold.
- Standard Roles: the Employer Administrator (exactly one) and Reporting Managers (membership is automatic, based on direct reports).
- Custom Roles: the roles UZIO seeds for you (Payroll Admins, Benefit Admins, HR Admins, Payroll Support, HR & Benefit Support) plus any you create.
[Screenshot: Manage Users — role list and All Users]
Add a user to a role
- Open Manage Users, select the role, and click Add User.
- Pick the employee. To grant access to a non-employee such as an auditor or bookkeeper, choose Add an External User from the dropdown and enter their name and email.
- If the person already holds another custom role, choose whether to merge (they keep both roles and the access combines) or replace (they are removed from the previous roles).
- Save.
What happens after you add a user
- A user who is already registered keeps their existing login and simply sees more in the portal at their next sign-in.
- A user who has never registered receives a registration email naming the role. Until they register, they have no access. You can resend the email from the user's row (see User account actions).
- A user with several roles gets the highest access level any of their roles grants, both for company features and for each employee they can see. To remove someone completely, revoke each role separately.
Create a custom role
- Click Add New Role at the bottom of the role list.
- Name the role.
- Set Company Access. Each company-level feature (Payroll, Time Off, Reports, Settings, Documents Library and so on) is set to No Access, Full Access or Custom Access. Custom Access expands into per-feature choices.
- Set Employee Access:
- Choose the employee group: All Employees, Direct Reports, Direct & Indirect Reports, Specific Employees, or Employees Based on Criteria (job titles, departments, work locations).
- Set the data tiers: Basic Information, Employee Documents, Additional Information.
- Configure Sensitive Field Visibility (next section).
- Save, then add users to the role.
There is no limit on the number of custom roles. The seeded roles can be renamed and re-permissioned like any other.
Sensitive Field Visibility
Sensitive Field Visibility controls, per role and per field, how much of an employee's sensitive data the role's users see. It is set separately for two places: On Screens (every Employer Portal page where the field appears) and Reports (downloaded reports).
- Edit the role and expand Employee Access > Sensitive Field Visibility.
- For each field and each surface, choose No Masking, Partially Masked or Fully Masked. Partial masking leaves a trailing fragment so the user can confirm identity, for example an SSN shown as
•••-••-6789.
Fields covered: SSN, Date of Birth, Compensation Details, Routing Number, Bank Account Number, Personal Email, Personal Phone, Home Address, Driving License Information, and Gender Identity (No Masking or Fully Masked only). Changes apply immediately to every user assigned to the role.
How Compensation Details is partially masked. Partial masking on pay figures hides the leading digits and keeps the rest, so the reader can tell a rate from a salary without seeing the amount. The screen states the rule: a 2 to 3 digit figure has its first digit hidden ($28 shows as $•8), and a figure of 4 digits or more has its first two hidden ($79,000 shows as $••,000). It applies to Salary and Rate, so an hourly rate appears as $•8.50/hr. Set the field to Fully Masked instead if the figure should not be visible at all.
Because the two surfaces are set separately, a role can read a salary on screen and still receive it masked in a downloaded report. If someone reports that a report shows $••,000, check the Reports setting on their role rather than the On Screens one.
To hide salaries from managers, edit the Reporting Managers role and set Compensation Details to Fully Masked on both surfaces. This applies to every Reporting Manager.
Note: Access to AI Copilot, the Documents module and Employee Portal Impersonation is granted separately on the role. Sensitive Field Visibility does not switch those features on or off. Grant or withhold them deliberately when you build a role.
Manage the Reporting Managers role
- Membership is automatic. Assign direct reports to someone (employee profile > Job) and they gain the role and receive a one-time email. If they lose all direct reports, including terminated ones, the role and their Employer Portal access are removed automatically.
- Default access: view direct reports, approve and edit their timesheets, approve or deny their time off. You can widen this (view or full access to personal, job, family and contact information, payroll, benefits, documents, tasks, time off, timesheet and more). Any change applies to all Reporting Managers. For one manager who needs more, create a custom role and assign it in addition.
- In the UZIO Mobile App, managers see their direct reports only. Broader visibility granted through additional roles applies on the web.
Hand over the Employer Administrator role
Only the current Employer Administrator (or your broker) can do this.
- Open Manage Users > Employer Administrator and click Add User.
- Select the new administrator (an employee or an external user).
- Choose the outgoing administrator's new role: an existing role, or Assign No Role.
There is always exactly one Employer Administrator. The outgoing administrator loses that role the moment the new one is saved.
User account actions
On a user's row, the Actions menu offers:
- View Username: look up the login email.
- Send Registration Link: resend the registration email to someone who has not registered.
- Revoke Access: remove the user from that role. Repeat for each role to remove all access.
Being added to a role sends an email. Changing a role's permissions, or removing a user from a role, does not.
Linked companies (multi-FEIN)
With linked FEINs there is one Employer Administrator across all companies. Custom roles can be company-specific or common. When you create a role you select the companies it applies to. Company-level access is common to all selected companies; employee-level access is defined per company.
Common problems
The person I added says they never received the email. Check that the email address on their record is correct, ask them to check spam, then use Send Registration Link on their row. If they registered earlier with a different email, use View Username to tell them which address to sign in with.
I removed someone's role but they can still see payroll. They hold another role that also grants payroll. Open All Users, find every row for that person, and revoke each role.
A manager can see salaries. Compensation masking is set per role. Edit the Reporting Managers role (or the custom role the manager holds) and set Compensation Details to Fully Masked for On Screens and Reports. Remember that a user with several roles gets the least-masked setting among them.
A manager lost portal access. They no longer have direct reports assigned. Reassign the direct reports on the employees' Job pages, or give the manager a custom role.
I need a second Employer Administrator. There can be only one. Create a custom role with Full Access to the areas the second person needs and assign it instead.
Still stuck?
Please reach out to us at support@uzio.com or call +1-571-601-1752. Include the user's name and email, the role involved, what they see versus what you expect, and a screenshot of the role's Company Access and Employee Access settings.
Related articles
- Understanding Roles and Access in UZIO: the roles themselves
- Registration and Login for Employers
- Managing Employer Preferences: company-wide switches that apply regardless of role
- The Employees Timesheet: the timesheet permission in practice
Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article