Skip to main content

Roles & access

Not everyone who logs in to Oho should be able to do everything. A role decides what a person can see and do — from full control of the platform down to read-only reporting. This page explains the four roles, what each one can do, and how you narrow a person's view to just the part of the business they look after.

Roles are set when you invite someone, and an admin can change them at any time. If you're ready to add people, see Invite your team & assign roles.

The four roles

Everyone who signs in to Oho is one of four roles. The two admin tiers split running compliance from setting the platform up:

  • Super Admin — the technical tier, usually IT or whoever owns the Oho setup. Super Admins do everything an Admin does, and additionally connect data sources and verification sources, manage users and roles, edit policies, and issue API tokens. This is the role that gets your organisation running.
  • Admin — full control of compliance across the whole business. Admins work with every worker in every organisation, configure screening packages, tags and email templates, and verify credentials — but they don't touch the technical setup.
  • Manager — runs compliance day-to-day. Managers add and edit workers, record and verify credentials, and send recruitment and fetch requests — but only within the organisations they've been assigned, and they can't change settings.
  • Observer — read-only. Observers can view workers, credentials, and the compliance dashboards, and export reports, but they can't make changes.

Most people are Managers or Observers. You need at least one Super Admin — without one, nobody can connect a data source or invite the rest of the team.

What each role can do

CapabilitySuper AdminAdminManagerObserver
View workers, credentials & compliance
Export & download reports
Add & edit workers, credentials & exemptions
Send recruitment & fetch requests
Configure screening packages, tags & email templates
Connect data sources & verification sources
Manage users, roles & policies
Issue API tokens & service accounts
AccessAll organisationsAll organisationsAssigned organisationsAssigned organisations

Each role includes everything the one below it can do. Both admin tiers see the whole business; Managers and Observers see only what they've been given access to (below).

Only a Super Admin can create another Super Admin

The Super Admin role doesn't appear in the role dropdown for anyone else, so nobody can promote themselves to it by accident. Keep more than one Super Admin — if the only one leaves, no one can connect a source or invite a replacement.

Scoping access to organisations

Your people are grouped into organisations — sites, business units, or regions. When you invite a Manager or Observer, you choose which organisations they're responsible for, and from then on their view of workers and compliance is limited to those groups. Neither admin tier is scoped — Super Admins and Admins see every organisation.

You can also narrow a Manager or Observer to one or both sides of Oho:

  • Recruit — screening applicants before they start.
  • Continuous checks — the ongoing monitoring of workers already on the books.

So a recruiter might be a Manager scoped to Recruit for two sites, while a site supervisor is a Manager scoped to Continuous checks for their own location only.

Seeing personal information

Some of what Oho holds about a person is more sensitive than the rest: their date of birth, personal email address and phone number, home address, ABN, and any alternate names recorded for identity checks. Oho hides these from everyone by default. If you don't have access, you see a partially masked value instead of the real one:

FieldWhat you see without access
Personal emailj•••••••••@••••.com
Personal phone+•• ••• ••• 678
Date of birth••••-••-••
Home address••••••••, Melbourne VIC ••••
ABN•• ••• ••• •56

Enough is left showing to confirm you're looking at the right person — the last few digits of a phone number, the suburb and state of an address — without exposing the value itself.

Names, work email, work phone, job title and organisation are not treated as personal information and are always visible. Searching, filtering and reporting on those is unaffected.

Giving someone access

Access is granted through a policy called View PII, not through a role — because needing someone's date of birth is about the job they do, not their seniority. A payroll officer who is a Manager may need it; an Admin who never handles personal data doesn't have to have it.

To grant it:

  1. Go to Settings → Access → Policies. This is a Super Admin screen — if you can't see it, ask whoever set your Oho up.
  2. Open the View PII policy.
  3. Set it to Active if it isn't already — it ships switched off.
  4. Add the people or groups who need it, and save.

Both admin tiers have this access automatically. Everyone else sees masked values until they're added.

Editing a worker without this access is perfectly safe: the masked values you were shown are ignored when you save, and the real ones underneath are left exactly as they were.

First sign-in

When someone you've scoped signs in for the first time, Oho greets them and shows the organisations you reserved for them, asking them to pick the ones they're responsible for before they continue. That choice sets which workers and compliance they'll see from then on. Super Admins and Admins skip this step, because they already see everything.

Signing in with your company login

If your organisation uses single sign-on, people reach Oho through your identity provider (Okta, Microsoft Entra ID, Google Workspace, or another) rather than an Oho password. SSO decides who can sign in; the roles and scoping on this page still decide what they can do once they're in. See Set up SSO.