Team and permissions overview
RecSphere is built around a workspace model where every user belongs to a single agency and acts through a defined role. This article explains how users, roles and the audit log fit together to keep your data secure.
Workspaces and users​
A workspace represents your agency. For RecSphere Ltd, the workspace holds every candidate, vacancy, client and contract your team works on. Users belong to one workspace, sign in with their own email address, and only see the data inside that workspace.
You can have as many users in your workspace as your plan allows. Adding a user does not give them access on its own; their role decides what they can see and do.
Roles drive permissions​
Each user has exactly one role. RecSphere ships with four default roles and lets you create custom roles when you need finer control.
- Admin - full access to every page, including billing, integrations and team management.
- Recruiter - day-to-day recruitment work: candidates, vacancies, shortlists and communications.
- Finance - contracts, payroll, invoices and exports, without access to recruitment workflows.
- Read-only - view-only access across the workspace.
- Custom - any combination of individual permissions you choose.
The role a user holds applies across every page. Changing a role updates their access immediately on their next page load.
Assign the most restrictive role that still lets each user do their job. It is much easier to widen access later than to recover from an unintended change.
The audit log records every change​
The audit log captures every meaningful action taken in your workspace: who logged in, what they edited, which records they exported, and which permissions they granted. It is your single source of truth when investigating a question like "who changed Sarah Williams' status last week?".
You will find the log under Admin > Audit log. See Audit log for filters, exports and retention.