Roles & Access

Compose access from a grid. Set your own roles.

Admins compose roles from modules and access levels, and assign them to anyone. A person gets the combined total of their roles, project roles and special powers.

raven / access — compose App Role
ModuleViewerMemberAdminSettings
Delivery
Recruitment
Attendance
Assets

Access is unioned across every role a user holds.

How access is composed

Three layers, combined per user.

Access is additive. A person gets the highest level granted from any source.

App Roles

Reusable roles built from modules and access levels. Access can be org-wide or limited to a manager's own reporting line.

Project roles

Raven gives these from project membership. You never assign them by hand. A project's PM becomes a Delivery Management Member. A Tech Lead becomes a Delivery Viewer.

Special powers

Extras granted to individual people. Examples: budget visibility for a read-only Delivery role, or the right to sign off staffing at the final executive step.

Access ladder
  • —NoneNo access to the module.
  • VViewerRead-only — view records and reports.
  • MMemberOperate — create and edit day-to-day records.
  • AAdminAdminister — manage the whole module.
  • ASAdmin · SettingsAdminister plus manage credentials & settings.
Special powers
  • Budget visibility

    Adds budget and cost visibility to a read-only Delivery role.

    held by · Accountant

  • Staffing sign-off

    The right to sign off on staffing at the final executive approval step, after Ops has reviewed the request.

    held by · Granted per person

The 15 built-in roles

Every role, every module.

Earlier names (Admin / PM / Product-Ops / Viewer) are retired.

Access ladder—NoneVViewerMMemberAAdminASAdmin · Settings(s) = scoped to reporting line
RoleDeliveryClientsKnowledgeAttendance1:1 ConnectPeopleAnnounceRecruitmentInterviewsPayrollAPAssetSeatHelpdeskSaaSData ReconClaudeSOPsContractsreservedInviteRoles
Global AdminFull access to every module plus Settings, invites and role management.ASASASASASASASASASASASASASASASASASASAS
Global Admin (no settings/invite)Admin in every module (Payroll, Interviews, Claude Team and SOPs excepted), but can't reach Settings, invite users or edit roles.AAAAAAASA··AAAAAAS··A——
AccountantOwns finance-adjacent modules and works AP as a payment maker; read-only in Delivery with budget visibility.V··A······MA··AA··A——
Head of DeliveryOrg-wide delivery oversight — every project, timesheet and allocation — plus the Knowledge Base, without writing any of it.M·M················——
Executive OfficeAdmin in Delivery, Knowledge and Seat; read-only across most of the rest.A·AVV··V···VAVVV···——
HR LeadershipHR, recruitment and people-management admin in one — with compensation tracking, delivery and SaaS visibility scoped to their reporting line.Ms··AAsAASAAMsVAMAMsA···——
HR MemberDay-to-day HR operations — attendance, seats, assets, helpdesk, data recon, people analytics and announcements.···M·MM····MMMMM···——
RecruiterManages the Keka Hire pipeline in Recruitment and builds interview kits.······MMM··········——
Hiring ManagerScoped Viewer on their own jobs (salary redacted); admin in the Interviewer Console.·······VsA··········——
InterviewerBrowse the vetted question bank and run assigned sessions.········V··········——
People Manager1:1s over their reporting line; scoped delivery, attendance and SaaS visibility.Vs··VsMs·M·······Vs····——
Project LeadPMs and tech leads — author their projects' Knowledge Base entries.··M················——
Office AdminMember-level operations across the physical workplace, plus announcements and AP visibility.···M··M···VMM······——
SalesViewer in Knowledge Base; Client Management is granted per person.··V················——
All employeesApplies to everyone: own profile, own timesheet, org chart, directory and dashboard.···················——

Every employee gets a baseline: their own profile and timesheet, the org chart, the employee directory and the dashboard home. No module grant needed.

Access that adds up.

Build a role once and assign it to many people. Every change goes in a full audit log.

Explore modules