Skip to main content
Roles and permissions control who can create, edit, and view data in Topicflow.

User roles

Every user in Topicflow has a base role that determines what they can see and do day-to-day. Employee:
  • Can manage their own goals, meetings, and feedback
  • Can view their own reviews
  • Can participate in surveys
Manager:
  • Everything employees can do
  • Can manage goals and meetings for direct reports
  • Can write reviews for direct reports
  • Can view feedback for direct reports

Admin types

Topicflow has three admin roles, each scoped to a different set of responsibilities. Assigning the right admin type keeps sensitive people data separate from technical configuration.

Global Admin

Global admins have full access to every setting and all organizational data. They can:
  • Access all organization settings tabs (directory sync, integrations, notifications, programs, reviews, AI, and more)
  • View and manage people data across the organization
  • Add, remove, and change admin roles for other users
  • Create and manage programs, templates, and review cycles
On free-tier organizations, every member is automatically a global admin.

People Admin

People admins have the same access to settings and people data as global admins, with two restrictions:
  • Cannot manage other admins — only global admins can add, remove, or change admin roles
  • Scoped data visibility — people admins can only see data for their direct reports and the chain below them; they cannot view data for their own managers or peers outside their reporting line
This role is designed for HR and People team members who need to run programs, view reports, and manage employee data without having full organizational control.

IT Admin

IT admins have access to technical configuration only. They can manage:
  • Directory sync — HRIS connections and employee data sync
  • Integrations — Slack, Teams, GitHub, Jira, and other tool connections
  • Notifications — Organization notification settings
IT admins cannot access people data, create programs, manage reviews, or change admin roles. This role is intended for technical staff who configure SSO, SCIM, and integrations without needing visibility into performance or HR data.

Deactivation and session management

When a user account or organization membership is deactivated, all of that user’s active sessions are immediately invalidated. This means a deactivated user is logged out everywhere right away — there is no window where a deactivated account can continue to access Topicflow.

Best practices

  • Grant minimum necessary permissions
  • Use IT Admin for staff who only need to manage integrations and directory sync
  • Use People Admin for HR team members who manage programs and people data
  • Reserve Global Admin for users who need to manage other admins
  • Review admin assignments regularly

What’s next

Visibility and privacy

Configure data visibility