Scoped admins and perimeters
Give an admin rights over part of the company only, with include and exclude rules based on profile fields or managers, and preview the resulting population.
A Scoped admin is an admin whose reach is limited to a population of members, called their perimeter (Scope in the app). Typical uses: an HR business partner for one country, a site HR manager, a division head who runs campaigns for their division only. This page explains how perimeters work, how to set one up and what a scoped admin can and cannot do.
How a perimeter is built
A perimeter never lists people by name. It is made of rules on profile information, so it follows the organisation automatically: a new hire in the Marketing department becomes visible to the Marketing scoped admin without anyone updating the rules.
A perimeter has two parts:
| Part | What it does |
|---|---|
| Include | Selects the members the scoped admin can reach. Each row is a condition: a Filter (a profile field such as Work location, Contract type, Level, Job title, an organisation unit, a custom select field, or Manager) and one or more Option values. You can also tick Include everyone to start from the whole company. |
| Exclude | Removes members from that selection. It never adds anyone. |
The population is calculated as follows:
- Several values in the same row are combined with OR (Work location is Paris or Lyon).
- Rows on different filters are combined with AND (Work location is Paris and Contract type is Permanent).
- Exclusions are combined with OR: matching any exclusion row removes the member.
- The scoped admin's own direct and indirect reports are always part of their population, even if an exclusion would remove them.
- Only active members count. Deactivated members drop out automatically.
Example: Include "Work location: Paris, Lyon" and "Contract type: Permanent", exclude "Organisation unit: Executive committee". The scoped admin reaches every active permanent employee based in Paris or Lyon, except members of the executive committee, plus their own team.
Note: The Manager filter matches the direct reports (N-1) of the chosen managers.
Which fields can be used as filters
Only select-type and reference-type profile fields that have Show in filters turned on can be used in a perimeter (for example Job title, Work location, Contract type, Level, organisation units and custom select fields). If the field you need is missing, go to Settings › Profiles fields, edit the field and tick Show in filters. The info message in the perimeter editor reminds you of this: "Missing a filter ? Check the option "Show in filter" in Settings > People attributes." See People attributes.
Set up a scoped admin
Before you start
You must be an Admin. Make sure the fields you want to filter on have Show in filters enabled.
Steps
- Go to People › Members and edit the member (or use Add member for a new member). You can also select several members and use Manage access levels.
- In Access level, choose Scoped admin. Two tabs appear: Scope and Preview members.
- In the Scope tab, under Include:
- click Add scope,
- pick a Filter, then one or more Option values (for the Manager filter, the second field is a Manager search where you type a name),
- repeat for other conditions (the same filter cannot be used twice), or tick Include everyone. The counter next to Include shows how many members match (for example "- 6 members", or "Everyone").
- Under Exclude, click Add scope to add the conditions of members to remove. This part has its own counter.
- Open Preview members to check the result: the list shows each Member with their Job title, Contract type and Work location, with a Filter button.
- Click Save (or Create / Create and send invitation for a new member).
The scoped admin can check their own perimeter from their profile: the Access level field shows "Scoped admin (n members administrated)", and the link opens the list.
The following messages prevent you from saving an incomplete perimeter:
| Message | What to do |
|---|---|
| "Make sure to fill all attribute and option fields." | A row has no filter or no option. Complete it or remove it. |
| "Make sure to exclude at least one option when including everyone." | With Include everyone, add at least one exclusion (otherwise, simply make them an Admin). |
| "Make sure to exclude or include at least one option." | Add at least one rule. |
| "Make sure to have at least one include option with an exclude." | An exclusion alone needs an include rule (or Include everyone). |
If no member matches, the preview says "Please set a scope to define this admin's reach." and "For now this administrator doesn't have any effective rights on any member."
What a scoped admin can do
Within their perimeter, a scoped admin:
- sees the People › Members list, restricted to their population, and can open and edit those members' profiles (except access level and perimeter);
- sees interview, feedback and team survey campaigns owned or co-piloted by members of the perimeter, and skills cycles created or co-piloted by them;
- can view and unlock submitted interviews and reviews of perimeter members;
- sees the goals, leave requests and skills matrix of perimeter members, and can adjust their leave balances;
- has all Manager creator rights (create campaigns, templates, trainings, content);
- sees the Settings page and Goals › Dashboard / Statuses and Work Time › Configuration, mostly read only.
What a scoped admin cannot do
- Change access levels or anyone's perimeter (they can see their own perimeter, read only, on their profile).
- Deactivate or restore members, add or import members. The Import members button is visible to them, but uploading a file leads to the Restricted Access page.
- Edit company settings, profile fields, goal statuses, Work Time configuration or the skills box matrix.
- Use training management (Training Plans, providers, budgets).
- Create API keys or see HR sync reports.
- Edit templates created by other people (interview, feedback, team survey, skills).
Note: A few areas are company-wide rather than limited to the perimeter: a scoped admin can edit any OKR and any skill of the framework.
Things that change a perimeter
- Deleting an option or a field in Settings (for example a work location) removes the perimeter rules that used it, which can shrink or empty a scoped admin's population. Check your scoped admins after cleaning up lists.
- Changing the access level of a scoped admin to anything else deletes their saved rules. If you promote them again later, you have to define the perimeter again.
- Profile changes (a member moves to another site, gets a new manager) move them in or out of perimeters automatically.
- HR data sync: if your company synchronises members through the API, perimeters can also be sent by your HRIS. See Integrations and HR data sync.
Common questions
The filter I need is not in the list.
Only fields with Show in filters enabled appear. Edit the field in Settings › Profiles fields and tick Show in filters. Free-text, date and number fields cannot be used.
The scoped admin sees members outside the perimeter.
Their own direct and indirect reports are always visible to them. Check the org chart: those people probably report to the scoped admin.
The scoped admin sees nobody in Members.
Their perimeter has no rules, or the rules match nobody (for example after an option was deleted). Edit the member and check the Preview members tab.
Can a scoped admin select participants outside their perimeter in a campaign?
The member lists they see are limited to their perimeter, so they can only pick people within it.
Still stuck?
Our team answers every question. Tell us what you are trying to do and we'll walk you through it. Contact support