Decide who sees what, one role at a time.

Create roles, give each one an access level, and point approval rules at the level instead of a job title. When someone needs a second hub, grant it to them directly. Edit a role once and everyone who holds it updates immediately.

Weight 60HR Manager14 people hold itSave role
People14 updatednobody reissued
ApprovalsRe-routedno policy edit
HubsHome onlygrants untouched
AuditOne changenot fourteen
One edit, not fourteen.
One roleChange one role, and everyone holding it changes

Access is the role, not a list of people. Widen the role and every person on it widens with it, the same day, with nothing to reissue.

The access screen

Permissions per role, per hub.

Roles run down the left, each with its access level. Every HQ appears across the top with its four permission levels. Each cell shows how many of that hub's permissions the role holds, out of the total available.

NearSyncHuman ResourcesAccess controlSearch, plan and askKAll hubs
Access controlActing hub: DubaiSearch rolesNew role
HubSeeDoManageAdmin
Human Resources12/128/810/104/6
Finance9/93/70/110/5
Sales7/70/60/90/4
Operations6/62/50/80/3

Editing a role changes access immediately for everyone assigned to it.

Approvals reach the right manager on their own.

Roles

Create roles, and set what each one can do.

Change a role once, and everyone who holds it gets the change immediately.

  • Start from a preset, or build a role from scratch
  • Give the role an access level for approval rules to use
  • Grant or remove permissions per HQ, at four levels
  • Draft a role with NearSync AI and review it before saving
New roleFrom preset
NameRegional HR Lead
PresetHR Manager
Access level60
Ceiling90, Admin
Weights
Admin90
Dept Head80
Manager60
Senior40
Staff25
Client5
Draft it with AIthen read it before you save it
Approval policies

Set approval rules for eight kinds of decision.

Each tier names an access level rather than a specific person, so it keeps working when people or titles change.

  • Write tiers for expenses, leave, discounts and advances
  • Add tiers for hiring, procurement, refunds and commission
  • Route by access level, by named person, by role, or up the reporting line
  • Require a receipt, and escalate after a time you set
ExpensesAll hubs
1Up to 500Any Manager, 60+
2500 to 5,000Any Dept Head, 80+
3Over 5,000Admin
Escalate after48 hours
Receipt requiredOver 500
Categories
MoneyFive of them
LeaveIn days
DiscountsIn percent
Someone has no manager?it warns you before the routing fails
Hub access

Give someone access to a second hub.

The grant belongs to the person, so nothing changes for anyone else with the same role.

  • Set a home hub for every member of staff
  • Grant an individual access to another hub
  • Take the access back whenever you need to
  • Apply an approval rule to one hub, or to all of them
Hub accessAisha Rahman
Home hubDubai
Cross-hub grantsRiyadh×Bengaluru×
Everything elseNot visible
Who can hold one
Hub-scopedYes
EitherYes
Global rolesNo
Remove the chipand the hub goes with it, same day
Cover while away

Hand your approvals to a colleague while you are away.

Choose who covers for you, set the first and last day, and pick what they cover: leave, expenses, hiring, procurement, timesheets, deal discounts, or all of it. Run two at once if you want, so leave goes to one person and expenses to another. The person covering sees a list of what they are holding for you.

Two weeks off
Leave requestsCovered by your deputy
ExpensesCovered by Finance
Runs12 to 26 May
Ends on the date you set, or sooner if you remove it
Access, explained

See where every one of a person's permissions came from.

Open anyone and read everything they can do, with each line labelled: it came with their department, it came with their role, or somebody granted it to them directly. Add one extra permission for that person, or take one away, without editing the role everyone else holds.

One person's access
Came with the department18
Came with the role7
Granted to them alone2
Taken away from them alone1
Change one person without changing the role
Setup check

Find the gaps that would stop an approval reaching anybody.

One check reads your reporting lines, your roles, your approval tiers and your alert rules, then lists what is missing: someone with no manager, a role nobody holds, an approval tier nobody is senior enough to satisfy. Each item tells you what it is holding up and links to the screen where you fix it. The check follows fixed rules, so it finds the same problems every time.

What it found
No manager set2 people
Role nobody holds1 role
Tier nobody can approve1 tier
Every item links to the screen that fixes it

Access

Who can do what.

Viewing the roster, changing somebody's manager and creating a role are three separate permissions, using the same four levels as every other part of NearSync.

See

View the roster, the org chart and who holds which role.

Do

Change a reporting manager, or invite a new user.

Manage

Create roles, set permissions and write approval tiers.

Admin

Full access to everything, not limited by the permission grid.

Admin is the highest role and is not constrained by the permission grid, so it is worth keeping to the smallest group that genuinely needs it.

One request, routed

The amount decides who needs to approve it.

Every amount range has its own approval tier. The tier decides how senior the approver must be, and how long to wait before escalating. The audit trail keeps the whole story: which tier matched, who approved, and when.

The policy checks the amount and matches it to an approval tier.

Teams and access guides

See Human Resources on your own data.

Half an hour on your own hubs, leave rules and pay cycles, with payroll reading all of it.