This article is for Primary admins who set up and manage roles and permissions in Gusto.
Roles and permissions control what someone can view and do in Gusto, as well as the emails they’ll get. You can assign a role to paid team members, unpaid team members or outside collaborators, like accountants, bookkeepers, or brokers.
You can set up unlimited All access admins.
Admins can be paid team members or outside collaborators.
Custom admin roles are available on Plus and Premium plans.
Plus includes 1 Custom admin role.
Premium includes unlimited Custom admin roles.
Gusto Pro accounts include unlimited Custom admin roles.
Roles are reusable — set up a role once, then assign it to as many people as you need.
You can add unlimited People managers with standard permissions, on any plan.
To change what a manager can do, create or customize a People manager role.
Other helpful articles
How to update company details (like your Signatory, addresses, and more)
For Gusto Pro accountants: Learn how to manage the firm’s clients.
You can add different types of people in Gusto.
Team members
Add from template
Multiples employees at once
Unpaid team members
Go to a different article to learn how to add unpaid team members.
External collaborators
Accountants
Bookkeepers
Other collaborators
As a Primary admin, you decide what each person can see and do in Gusto.
Signatory: One per company, set during onboarding
Can sign documents
To change the Signatory, update your company details.
Account owner (Primary admin): One per company
Can see and do everything in the company account
Only the Account owner can add, remove, or edit roles and permissions for other people.
Can be a team member or collaborator
All access admin
Can see and do everything in the company account
Cannot manage roles or permissions — only the Account owner can do that
Can be a team member or collaborator
If you assign an admin role to a team member, they need to switch between their employee and admin accounts to handle different tasks.
No limit to how many you can assign, on any plan
Custom admin (Plus and Premium plans)
Lets you pick which parts of Gusto the person can use, like payroll, benefits, reports, and more
Can be a team member or collaborator
If you assign an admin role to a team member, they need to switch between their employee and admin accounts to handle different tasks.
Roles are reusable — set up a role once, then assign it to as many people as you need
Plus includes 1 Custom admin role. Premium includes unlimited Custom admin roles.
People manager
Lets you hand off people-management tasks, like approving time off or timesheets
People managers never see sensitive data like Social Security numbers (SSNs), bank account info, or tax returns.
Most common for managers who need more than standard manager permissions
Outside collaborators who are not team members need an admin role instead — either Custom admin or All access admin.
No limit to how many you can assign, on any plan
Basic individual permissions: No limit
Let you delegate limited tasks to individual team members
You can add individual permissions for US employees and contractors, non-US contractors, and unpaid team members.
Expand the sections below for more detail.
All access admins can see and do everything in your company account. Give this role to company owners and administrators. Keep it to just a few people, since they can see all of your company information.
If that is more than someone needs, choose Custom admin instead.
Note: Even if you build a Custom admin role and select every role type and every permission, it is still not the same as making someone an All access admin.
Hire and dismiss people
Run payroll and pay contractors
Create reports
Manage taxes
Manage benefits
Manage company bank accounts
Manage and pay bills
Manage company data
Manage the company Signatory
View and edit compensation
All access admins cannot add, remove, or edit roles and permissions for other people. Only the Account owner (Primary admin) can do that.
You can assign All access admin to as many people as you need, on any plan.
Custom admins can use only the parts of Gusto you pick. As the Account owner (Primary admin), you choose which functions a Custom admin role includes, then assign that role to the people who need it.
Roles are reusable, so you can set up a role once and assign it to as many people as you need. Plus includes 1 Custom admin role, and Premium includes unlimited Custom admin roles. Custom admin roles are not available on Simple. Admins can upgrade their plan at any time.
Pay
Run payroll
Pay employees, view pay reports, manage expenses, edit pay schedules, and manage tax information and Payroll on Autopilot™.
If you’re using payroll approvals, Custom admins can request payroll approval on regular payrolls. We do not support approvals on other payroll types, like off-cycle and bonus payrolls.
Pay contractors
Pay contractors and view contractor payment reports.
Team members
Basic information
View and edit a team member’s personal information.
Hire and onboard
Add team members and contractors, create and manage job posts, send offer letters, send and review background checks, create and manage onboarding checklists, and manage documents, provisioning app integrations, and hiring integrations.
Manage and offboard
Dismiss team members, view and manage offboarding checklists, and manage expenses.
Pay and work
View and edit a team member’s compensation information.
Documents
View and edit a team member’s documents. Some documents may include sensitive information.
Reports
Payroll reports and tax filings
View financial reports, payroll history, employee compensation history, contractor payment history, and tax and compliance documents.
Accounting integrations
Set up and manage accounting integrations like QuickBooks and Xero.
Time & Attendance
Time tracking, scheduling, time off, and project tracking
Set up and manage time tracking, schedules, and time off policies. Create and publish scheduled shifts, review and approve team members’ hours and time-off requests, and sync hours to payroll.
Performance
Team insights
Set up employee surveys and view results.
Performance reviews
Create review cycles, manage employee performance reviews, view submitted reviews, and share completed reviews with employees.
Learning
Learning courses
Enroll people in courses from the catalog.
HR resources
HR resource center
Use all HR resources and reach certified HR pros.
Benefits
All benefits
Set up and manage all company benefits, including health insurance, 401(k), and others.
View Gusto’s Employee Benefits Election report.
Important: Anyone with this permission can see sensitive info in this report, even if their other permissions are limited. This includes Social Security numbers, dates of birth, annual wages, and more.
Integrations
Third-party
Manage third-party integrations.
People manager permissions let you hand off specific tasks without showing someone sensitive data. You can use them for US employees and contractors, non-US contractors, and unpaid team members.
You can also set up a People manager role with a fixed set of permissions, then assign that role to as many people as you need.
There is no limit to how many People managers you can have, on any plan.
People managers never see sensitive information like Social Security numbers (SSNs), bank account info, or tax elections.
As the Account owner (Primary admin), you can give People managers permissions for these less-sensitive functions.
Team members
Basic information — control who can see team members’ information like email, phone number, emergency contact, reporting details, and birthday
Pay and work — control who can see team members’ compensation and work history
Documents — control who can see team members’ documents, including I-9s and other onboarding documents
Time & Attendance
Team time off — control who can see team members’ time off, including balances, accruals, and requests
Time tracking — control who can view and approve team members’ timesheets
Scheduling — control who can see team members’ schedules
Expenses
Team expenses — control who can see team members’ expenses
Only the Account owner (Primary admin) can set up or edit permissions. You can do this by opening a team member’s profile or by creating a role and assigning it to them.
You can add individual permissions for US employees and contractors, non-US contractors, and unpaid team members.
Note: People managers never see sensitive details like Social Security numbers (SSNs), bank account info, or tax elections.
To set up or edit individual permissions for a team member, follow these steps.
Go to People.
Click the name of a US employee.
Under Additional, click Permissions.
Click Add permissions to set up new permissions.
To edit an existing role or permission, click its name, and then click Edit role.
Toggle to the level you want them to have (People manager, Custom admin, or All access admin).
Click Continue.
As the Account owner (Primary admin), you can give People managers permissions for these less-sensitive functions.
Team members
Basic information — control who can see team members’ information like email, phone number, emergency contact, reporting details, and birthday
Pay and work — control who can see team members’ compensation and work history
Documents — control who can see team members’ documents, including I-9s and other onboarding documents
Time & Attendance
Team time off — control who can see team members’ time off, including balances, accruals, and requests
Time tracking — control who can view and approve team members’ timesheets
Scheduling — control who can see team members’ schedules
Expenses
Team expenses — control who can see team members’ expenses
Collaborators work with your company, but may not be on the company’s payroll. They may be:
Accountants
Bookkeepers
Other collaborators
Only the Account owner (Primary admin) can add collaborators. If the person is part of your organization directly, but not getting paid, you may want to set them up as an unpaid team member.
To add an external collaborator and set up their permissions, follow these steps.
Go to People.
Next to Add person, click the caret and choose Add collaborator.
Select the collaborator type (accountant, bookkeeper, broker, or other).
Enter the collaborator’s details.
First name
Last name
This invites them to your organization — make sure this information is correct.
Personal note (optional)
Choose their role (Custom admin or All access admin).
Custom admin
Choose the permissions for each function.
Collaborators can only see the parts of Gusto that match their permissions. For example, if they do not have Benefits permissions, the Benefits section does not appear for them.
All access admin
All access admins get a fixed set of permissions that you cannot change.
Click Save collaborator.
Collaborators get an email about their new role. If they do not see it, have them check their spam folder or confirm they used the correct email address.
Only the Account owner (Primary admin) can manage collaborators’ roles and permissions.
To update an outside collaborator’s role, follow these steps.
Go to People.
Click Collaborators.
Click their name.
Next to their role, click Edit or Remove.
Edit — change their permissions, then click Save.
Remove — take away their permissions completely and remove their role from the system.
Follow the steps that match how you set up the person in Gusto.
If they’re already a team member — update their personal email or details in their Gusto team member profile, not their admin profile.
If you added them as a collaborator — remove their admin role and re-add them with updated info.
Only the Account owner (Primary admin) can add, remove, or edit permissions for other people.
Roles are reusable, so you can set up a role once and assign it to as many people as you need.
To create and customize a role, follow these steps.
In the left menu, click your company name.
Under Settings, click Permissions.
The table shows the roles, permissions, and relationships of all current admins, managers, and other team members.
Use the Users tab to manage individuals or the Roles tab to manage roles.
To create a new role, click Add a role.
Select the role type (People manager, Custom admin, or All access admin).
Choose the permissions (for Custom admin or People manager roles).
All access admins get a fixed set of permissions that you cannot change.
For People manager roles, assign permissions, like who can see team members’ time off and schedules.
Click Continue.
For People manager roles, select the scope.
Everyone
Direct and indirect reports
Indirect reports include everyone your direct reports manage.
Select people or groups
Departments
Job titles
Worker status (active)
Individuals
Click Continue.
Choose who gets this role.
This can include groups based on manager status or job title, as well as individual team members.
Click Continue.
Give the new role a name.
Review the summary and click Save role.
If you need to change anything, click Edit.
Everyone you assign gets an email about their new role. If they do not see it, have them check their spam folder or confirm they used the correct email address. They can only see the parts of Gusto that match their permissions.
For example, if they do not have Benefits permissions, the Benefits section does not appear for them.
The current Account owner (Primary admin) can assign a new Account owner.
If the current Primary admin is unreachable or has left the company, other admins or signatories can request to become the new Account owner.
Once you assign a new Account owner, you can no longer edit roles or permissions.
If the Account owner left the company, and another admin or signatory cannot request to become the new Account owner, you’ll need to contact us for next steps.
No Gusto account? Email [email protected] with documents proving you have the authority to “transact on behalf of the business.” Send a copy of a photo ID and your Articles of Incorporation, or an operating agreement that contains this information.
To contact us, sign in to your Gusto account and click the help icon in the top-right corner of the page.
To change the Account owner as the current Primary admin, follow these steps.
In the left menu, click your company name.
Under Settings, click Permissions.
In the Users tab, click your name (tagged “Account Owner”).
Next to Individual access, click View details, then click Change Account Owner.
Choose a new Account owner from the dropdown.
Important: After you make this change, you can no longer add or remove admins. Only the new Account owner can undo this action.
Click Save.
Only the Account owner (Primary admin) can add, remove, or edit permissions for other people. If you’re not the Account owner, contact them for help.
If the Account owner left the company, the Signatory must request a support call in Gusto from their account.
To contact us, sign in to your Gusto account and click the help icon in the top-right corner of the page.
No Gusto account? Email [email protected] with documents proving you have the authority to “transact on behalf of the business.” Send a copy of a photo ID and your Articles of Incorporation, or an operating agreement that contains this information.
To manage permissions for any person or role, follow these steps.
In the left menu, click your company name.
Under Settings, click Permissions.
Choose the tab based on what you need to do.
Users — manage one person at a time
Click Users.
Click the person’s name.
Choose to Edit or Remove each type of permission they have.
Roles — manage roles
Click Roles.
To edit or remove a role, click the role title.
Click Edit next to the permissions you want to change.
To remove the role entirely, scroll to the bottom of the page and click Remove role. This takes away the permissions of everyone who currently has this role. We’ll send them an email about the change.
Select the permissions you want to give, then click Save.
Q: Does Gusto send notifications about permission or role changes?
A: We email people when you add or remove roles. We do not email about edits to permissions someone already has.
Q: Can people see their own permissions in Gusto?
A: No. Only the Account owner or All access admins can view someone’s assigned permissions.
Q: Can I assign People manager roles to outside collaborators who are not team members?
A: No. People manager roles are for team members only. Outside collaborators need a Custom admin or All access admin role.
Q: How can I scale someone back from All access admin or Custom admin to People manager?
A: Remove their current role and set up a new People manager role, or adjust their Custom admin or All access admin permissions.
Q: Can I see who changed permissions or roles?
A: We do not have an audit or change log.
Q: Can I still assign managers and direct reports?
A: Yes, the process works the same. You can also set up a People manager role and tailor its permissions.
Q: Are there limits on how many roles I can set up?
A: People manager and All access admin have no limit, on any plan. Custom admin roles are available on Plus and Premium. Plus includes 1 Custom admin role, and Premium includes unlimited Custom admin roles. Roles are reusable, so you can assign one role to as many people as you need.
Q: If I add a Gusto Pro accounting firm, do they get full access?
A: Yes. The firm admin can see and do everything, and can assign permissions to others at the firm.
Q: (for accountants) How do permissions work for multiple accountants at one firm?
A: Each accountant’s permissions depend on what their firm admin assigns.
Q: Can I combine manager permissions with company-wide admin permissions in one role?
A: No. Manager permissions only cover a person’s direct and indirect reports. Admin roles (Custom admin or All access admin) apply company-wide, so they always take priority over the narrower manager scope. If someone needs both, set them up with two separate Gusto accounts, each with its own email address — one account with manager permissions for their reports, and one with a Custom admin or All access admin role for the company-wide functions. They sign in to whichever account matches the task.
Q: Should I choose Custom admin or All access admin for a team member?
A: Choose Custom admin when a person only needs certain company-wide functions, like time tracking, time off approval, running reports, or hiring and offboarding team members. Choose All access admin only when someone needs to see every function, and keep it to just a few people.
Q: Do all reporting fields need the same permissions?
A: No. Most fields need at least one specific permission, but a few, like Social Security numbers, are visible only to All access admins, no matter what else a Custom admin role allows. See required permissions for each reporting field for the full list.