Purpose
This article explains who can do what in UZIO: the two portals, the standard and custom roles, and how access is granted and scoped through Manage Users. Every Role & permissions callout elsewhere in this help center points back here. Read it before you give anyone access, and whenever an article says "Employer Admin" and you want to know whether that means you.
Who needs this: anyone administering UZIO, and anyone deciding what access to give a new manager, admin, or outside accountant.
When to use this
- You are the new Employer Administrator and want to delegate payroll or HR work safely.
- A manager needs to approve time but must not see pay rates.
- An outside bookkeeper or auditor needs to run reports without seeing SSNs.
- Someone says "I can't see the Payroll menu" and you need to know why.
How to read "Employer Admin" in other articles
UZIO has exactly one Employer Administrator per company. When another article says an action is for the "Employer Admin", it means the Employer Administrator or any user whose role grants the relevant permission. For example, an article that says "Employer Admins can run payroll" applies equally to a user in the Payroll Admins role. If you cannot see or do something an article describes, the cause is almost always the role you hold, not the article. Ask your Employer Administrator to check your role in Manage Users.
The two portals, and why one person may use both
- The Employer Portal is where management work happens: payroll, timesheets, benefits administration, policies, settings, and user access.
- The Employee Portal is every employee's personal space: their own timesheet, pay stubs, time-off requests, benefits enrolment, tax and banking details.
Admins and managers are usually employees of the organisation as well. They do management work in the Employer Portal and manage their own pay and time off in the Employee Portal. That is two hats, one person, and one login. Registering once with a unique email gives access to both portals with the same credentials. See Registering and Logging In.
Where access is managed
Manage Users in the left navigation is the control centre. It lists every user with elevated access and the role or roles they hold. A person can hold more than one role at a time, for example Employer Administrator and Reporting Manager. The how-to for adding users and building roles is Managing Users and Roles.
[Screenshot: Manage Users showing Standard Roles, Custom Roles, and the All Users list (use demo data)]
Standard roles
| Role | How you get it | What it grants |
|---|---|---|
| Employer Administrator | Exactly one per company (or across linked FEINs). This is the primary admin. To hand it over, the current Employer Administrator or your broker uses Add User on the role page and picks a new role for the outgoing admin (or Assign No Role) | "Full access to employee and company information. Can also manage roles and users." (verbatim role description). These permissions cannot be reduced |
| Reporting Manager | Automatic. "Managed automatically based on whether or not an employee has direct reports." (verbatim). Give someone direct reports and they gain the role and receive an email the first time. If they no longer have any direct reports, including terminated ones, the role and their employer-portal access are removed automatically | By default: view the list of direct reports, approve and edit their timesheets, approve or deny their PTO requests. Editable, but any change applies to all Reporting Managers at once |
What Reporting Managers see by default
The Reporting Managers role ships with every Company Access module set to No Access. Managers do not see company-level Payroll, Benefits, Settings, and so on. Their access is employee-level, scoped to Direct Reports:
- Basic Information: Custom Access (a subset of profile fields)
- Employee Documents: No Access
- Additional Information: Custom Access. Per-item permissions such as Employee Timesheet and Manage Time Off live here
- Sensitive Field Visibility: a separate control over sensitive fields (below)
An Employer Administrator can widen or narrow these defaults for all managers at once. For one manager who needs more, add a custom role to that person instead.
Note: Because there is only one Employer Administrator, every "other admin" in your organisation is a custom-role admin. A user can hold several roles. Where roles overlap, the highest level of access from any assigned role wins, for both employee data and company features.
Custom roles
Below the standard roles, UZIO seeds ready-made custom role templates. You can rename them, change their permissions, and add users to them. There is no limit on the number of custom roles.
| Seeded role | Intent |
|---|---|
| Payroll Admins | Run and manage payroll at company level. Full access to employees' basic info, payroll info, and tax and compliance documents |
| Benefit Admins | View benefit proposals and monitor enrolments (proposal setup and management belong to the broker). Full access to basic info, enrolment info, and enrolment documents |
| HR Admins | Hire employees and manage HR activities. Full access to basic info, time off, timesheet, tasks, and all documents |
| Payroll Support | View only: basic info, payroll and benefits info, timesheet info |
| HR & Benefit Support | View only: proposals, enrolments, HR activities; basic info, benefits, time off, timesheet, documents, tasks |
Create your own with Add New Role. Every custom role is built from the same two blocks.
1. Company Access
Which company-level features the role can use. Each module is set to No Access, Full Access, or Custom Access (Custom expands into per-feature choices):
Payroll · Expenses · Benefits · Hiring and Termination · Employee Communication · Employee Compensation Statement · HR Compliance · Manage Resources · Task Library · Documents Library · Time Off · Schedule and Time Tracking · Integrations · Reports · AI Copilot · Settings
2. Employee Access
Whose data the role can see, and how much of it:
- Scope: "Select the group of employees whose data the user associated with this role can access". Options: All Employees / Direct Reports / Direct & Indirect Reports / Specific Employees / Employees Based on Criteria. Criteria include work location, department, and job title, so you can limit an office manager to one location.
- Data tiers: Basic Information, Employee Documents, Additional Information (each No Access / Full Access / Custom Access).
- Sensitive Field Visibility: per-role, per-field masking of sensitive data, configured independently for two surfaces: On Screens (every employer-portal page where the field appears) and Reports (standard reports). Fields: SSN, Date of Birth, Compensation Details, Routing Number, Bank Account Number, Personal Email, Personal Phone, Home Address, Driving License Information, Gender Identity. Options per field: No Masking / Partially Masked / Fully Masked. Gender Identity offers No Masking or Fully Masked only. Partial masking shows a trailing fragment for identity confirmation, for example
●●●-●●-6789. Changes apply immediately to everyone in the role.
Note: Sensitive Field Visibility does not govern AI Copilot, Documents, or Employee Portal Impersonation. Access to those is granted separately on each role.
[Screenshot: Add New Role showing Company Access levels and the Employee Access scope dropdown (use demo data)]
Mobile
Roles and permissions are managed in the Employer Portal on the web. The UZIO Mobile App applies them: a Reporting Manager sees only direct reports under More > Manage Team, and broader visibility granted by a custom role appears on the web, not in the app. See The Reporting Manager Role.
Common problems
Someone can't see a menu item or page that an article describes
Two causes. Either the module is not enabled for your company (the item is greyed out for everyone, including the Employer Administrator), or the person's role does not include it. Check the role in Manage Users. If the Employer Administrator cannot see it either, the module needs to be enabled by UZIO; see Still stuck?.
A manager needs to approve time but must not see pay
Edit the Reporting Managers role and set Compensation Details to Fully Masked under Sensitive Field Visibility. Remember this applies to every Reporting Manager. Timesheet approval itself comes from Employee Access > Additional Information > Employee Timesheet.
We want two Employer Administrators
UZIO allows one. Give the second person a custom role instead, starting from one of the seeded templates and widening it as needed. A custom role can hold every Company Access module at Full Access. Managing roles and users is part of the Employer Administrator's description ("Can also manage roles and users"); whether a custom role can be given that ability depends on what its Company Access includes, so check the role's options in Manage Users.
An outside accountant or auditor needs access
In Manage Users, choose the role, click Add User, and pick Add an External User. Enter their name and email; UZIO emails them a registration link. Use a view-only role such as Payroll Support and mask SSN and bank fields under Sensitive Field Visibility. See Managing Users and Roles.
A manager lost access overnight
The Reporting Manager role is removed automatically when the person has no direct reports left, including after terminations. Reassign at least one direct report, or give them a custom role.
Who is not covered here
Broker, carrier, and UZIO internal roles exist on separate portals and are outside employer documentation. If a UZIO partner or your broker administers your account, their access is managed on their side.
Still stuck?
If a module is missing for everyone in your company, or you need a change UZIO must make on its side, please reach out to us at support@uzio.com or call +1-571-601-1752. Include your company name, the menu item or feature in question, and a screenshot of what the Employer Administrator sees.
Related articles
- Managing Users and Roles: add users, create custom roles, hand over the Employer Administrator role
- Registering and Logging In to the Employer Portal
- The Reporting Manager Role in UZIO
- Approving Timesheets and Syncing Hours to Payroll
- Adding and Managing Time Off Policies
Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article