Skip to main content
Harly uses workspace-scoped RBAC. A role combines a set of permissions with an optional scope (job access, departments, regions).

Built-in roles

Custom roles can be created in Settings → Roles with any combination of the available permissions. Only the owner role is non-editable.
A scoped administrator cannot create a role broader than its own permission ceiling. Review role changes in the audit log after every organisational change.

Permissions

Permissions follow the pattern resource:action. The available permissions are:

Contextual scopes

Layer scopes on top of a role’s permissions to restrict what data a member sees:
  • Job access: all: member sees all jobs and their candidates.
  • Job access: assigned: member sees only jobs they are on the hiring team for.
  • Departments: restrict to specific departments.
  • Regions: restrict to specific regions.
Use assigned for recruiters who should work only on their requisitions. Add department or region constraints for larger teams with geographic or functional divisions.

MFA and session controls

Owners can enforce MFA from Settings → Security. When MFA is enforced, members without a configured factor are blocked from the workspace until they enroll. Additional controls available in Settings → Security:
  • Passkeys
  • Trusted domains
  • IP allowlists
  • Risk detection

Audit review

Review security and administrative events periodically and after any incident. Export the audit log before deleting or anonymizing records that may be needed for an active investigation.
A candidate’s deletion request is not a security incident. Handle it through the privacy workflow, not the audit log.