InsightHireHelp Center

Roles & permissions

Org roles, what each role can access, and how platform feature flags interact with permissions.

InsightHire uses organization-scoped roles. Permissions are enforced in the API (insighthire-api) on every tRPC procedure — the UI hides unavailable actions, but the server is authoritative.

Standard org roles

RolePositionsCandidatesReview queueSettingsBilling
OwnerFullFullFullFullFull
AdminFullFullFullFullView
RecruiterCreate/edit assignedFullFullLimited
Hiring ManagerView assignedView assignedView assigned
MemberViewViewAccount only

Hiring Manager vs Recruiter

  • Recruiters own pipeline motion: invites, stage changes, rejections, messaging.
  • Hiring Managers consume evidence: watch videos, leave feedback, complete scorecards. They cannot change org-wide settings unless also Admin.

Position-level access

Positions can restrict visibility to:

  • All org recruiters (default)
  • Explicit hiring team (recruiter + named hiring managers)
  • Private drafts (admin/recruiter only until published)

When job governance is enabled, requisition owners and approvers gain additional read access during approval — see Job governance.

Feature flags vs roles

Platform admins enable capabilities per tenant in InsightHire Admin → Integrations & Features. A recruiter may have permission to use custom pipelines, but the Custom Pipelines flag must be on for the org or the settings pages and kanban board won't appear.

Flags that commonly gate UI:

Flag slugUnlocks
custom_fieldsSettings → Custom Fields, values on positions
job_governanceRequisitions, approvals, intake forms, templates
custom_pipelinesPer-job stages, automations, task inbox
structured_interviewsInterview kits, scorecards, feedback enforcement
custom_reportsReport builder, dashboards, scheduled email
dei_complianceDemographics, EEOC export, blind review, fraud queue
candidate_surveysNPS surveys on stage change
culture_fit_scoringCulture profiles and culture-weighted scoring
talent_networkTalent network CRM surfaces

Contact InsightHire support or your CSM to enable flags in production.

Invitations & SSO

Team invites: Settings → Team → Invite. WorkOS AuthKit handles SSO when configured for your domain. Invited users inherit the role selected at invite time; admins can change roles later.