- 10 Minutes to read
- Print
- DarkLight
- PDF
Approval Role Setup
- 10 Minutes to read
- Print
- DarkLight
- PDF
Admin users can manage approval-related permissions on the Approval Role Setup page based on each user’s responsibilities. Approval roles can be configured for an individual user or a User Group.
When assigned at the user level, available permissions include Edit Scenario, Enable Workforce User Access Tab, Enable Template Snapshot, Create and Manage Views, and Edit Subline Summary Line, along with Budget Entity and Approval Role assignments.
When assigned at the group level, available permissions include Edit Scenario, and Enable Workforce User Access Tab, along with Budget Entity and Approval Role assignments.
Assign or Edit Approval Role for a User
Navigate to Maintenance > Administration > User & Role Management.
Search for the desired user and click the Shield icon to open Security Configurations.
Click Approval Role Setup from the list.
On the Approval Role Setup page, turn permission checkboxes on/off for:
.png?sv=2022-11-02&spr=https&st=2025-11-02T12%3A43%3A54Z&se=2025-11-02T12%3A53%3A54Z&sr=c&sp=r&sig=J7CYKQsRYsb4bnPv2GTIESC9Iza7uEWSWVOQ75rUwEI%3D)
Assign the Budget Entity Levels and Role to give access.
Click the Save icon to apply changes.
Notes:
If Approval Role Management isn’t enabled under Navigation Access, users can view but cannot edit this page.
For permissions managed at the group level, such as Edit Scenario or Enable Workforce User Access Tab, the corresponding checkboxes appear disabled on the user page. This indicates that these settings are controlled by the User Group and can only be modified from the User Group scope.

Assign or Edit Approval Role for a User Group
Navigate to Maintenance > Administration > User & Role Management.
In the User Group tab, search for the desired user group and click the Shield icon to open Security Configurations.
Select Approval Role Setup.
On the Approval Role Setup page, turn permission checkboxes on/off for:
Select Budget entity Levels as needed and assign the appropriate Role for each budget entity.
Click the Save icon to apply changes.
Notes:
If Approval Role Management isn’t enabled under Navigation Access, users can view but cannot edit this page.
Group-inherited permissions cannot be edited at the user level; modify them from the User Group scope instead.
The User Group dropdown does not include an option to select Everyone. Users must be assigned to specific user groups individually.
Admins cannot assign the following permissions within the User Group context:
Enable Template Snapshot
Create and Manage Views
Edit Subline Summary Line
User & User Group Level Permissions for Approval Role Setup
Administrators can assign permissions at both user and user group levels to define who can edit, view, or approve data within the planning process.
Edit Scenario
The Edit Scenario permission allows users to copy Global Entity templates to Budget Entities and edit those copies during the budgeting process. This ensures that users can modify planning data as needed while maintaining the original templates for reference or reuse.
Administrators can assign this permission at either the User or User Group level. When assigned to a User Group, all members automatically inherit the ability to edit budget scenarios for the specified entities.
Note:
If Edit Scenario is disabled, the Global Process option on the Planning Control Panel is not available.
.png?sv=2022-11-02&spr=https&st=2025-11-02T12%3A43%3A54Z&se=2025-11-02T12%3A53%3A54Z&sr=c&sp=r&sig=J7CYKQsRYsb4bnPv2GTIESC9Iza7uEWSWVOQ75rUwEI%3D)

Enable Workforce User Access Tab
You can control who can manage the User Access page from the Approval Role Setup page. Only users with Enable Workforce User Access Tab permission can view and manage the compensation items mapped to employees.
Admin users can also hide sensitive information on the User Access page, such as salary or benefits. This option allows administrators to hide selected compensation items from the following areas:
Employees tab (for Admin and End Users)
Employee Add/Edit pages
Employee Report
All Views
Dynamic Reports
Report Sets
Standard Reports
Customize Roster page
By default, the Enable Workforce User Access Tab permission is disabled for all users. Once enabled, the User Access tab becomes visible when users open the Workforce Planning Setup page.
When this permission is assigned at the User Group level, it appears disabled on the individual user’s page because it is controlled by the group. However, the user still inherits the access. See the Inherited Security tab for the source group that grants the permission.
To learn more about Workforce user access feature, click here.


Enable Template Snapshot
The Enable Template Snapshot permission allows finance users to take backups of GSTC templates for each budget entity and restore them when needed. This helps preserve versions of planning templates for audit or rollback purposes.
This permission is available only at the user level and is enabled by default. Administrators can disable it for specific users from the Approval Role Setup page if template backups or restores should be restricted.
When disabled, users cannot create or restore template snapshots within their assigned budget entities.
To learn more about Snapshots, click here.
.png?sv=2022-11-02&spr=https&st=2025-11-02T12%3A43%3A54Z&se=2025-11-02T12%3A53%3A54Z&sr=c&sp=r&sig=J7CYKQsRYsb4bnPv2GTIESC9Iza7uEWSWVOQ75rUwEI%3D)
Create and Manage Views
The Create and Manage Views permission allows users to create, customize, and manage template views within the planning environment. This enables users to organize and analyze data according to their specific reporting or input needs.
This permission is available only at the user level and is enabled by default. When disabled, the Create and Manage options will not appear in the Views menu, preventing the user from creating or modifying any template views.
To learn more about Views, click here.
.png?sv=2022-11-02&spr=https&st=2025-11-02T12%3A43%3A54Z&se=2025-11-02T12%3A53%3A54Z&sr=c&sp=r&sig=J7CYKQsRYsb4bnPv2GTIESC9Iza7uEWSWVOQ75rUwEI%3D)
Edit Subline Summary Line
The Edit Subline Summary Line permission controls who can edit summary lines in Subline templates. It ensures that only authorized users can modify key calculated or aggregated values in Subline templates.
This permission is available only at the user level. When disabled, users can view summary lines but cannot edit or overwrite them, which helps prevent accidental changes or deletion of critical formulas.

Budget Entity Permissions and Approval Role
The Budget Entity Permissions and Role section defines access for each user or group across different budget entities and approval roles. Administrators use this grid to control which entities a user or group can view, edit, or approve.
Use the Levels columns to define the entity path (for example, Level 1: NON USD → Level 2: ALL). Assign a Role for each entity path based on the organization’s approval hierarchy.
You can add or remove rows using the Add (+) and Delete options as needed.
When approval roles are assigned at the group level, all members automatically inherit the assigned Budget Entity access and roles. Group-inherited rows appear as read-only on individual user pages and can only be edited from the User Group scope.

You can set the user Level and Role using any of the three available methods:
Note:
Import Approval Role option is not available at User Group Approval Role setup. Only export is available. You can export group-level approval role data for reference or audit purposes.
Add/Edit Budget entity permissions and Approval role on the Approval Role Setup page
Click the cell under Level 1, then select the budget entity you want to give the user an approval role for.
(Optional) Click the cells under columns Level 2, Level 3, and so forth, to add drill-down capabilities to associate with role privileges. For example, Level 1 might be associated with a worldwide organization, Level 2 with the American branch of the organization, Level 3 with the organization’s California offices.
Click the cell under the Role column, then select a role for the user for the budget entity chosen. Note that roles are defined on the Approval Role page.
Import Approval Role
Approval roles can be imported to the respective user using the following steps.
Click the Upload File icon.
Approval Role Upload dialog box appears.
Note:
The uploading file should follow the format specified by Planful. The Sample Excel template instructs you to organize the data and load it back into the application.
1. To obtain a sample format, click Download Sample Template.2. Open the downloaded template. The template displays the required fields and also provides information about how you can enter the correct data in all the fields.
3. Enter the relevant details in the User ID, Approval Role, Member Type, Level 1, Level 2, and Level 3 columns according to the instructions provided in the sample template. Ensure that you delete all the instructions in the sample file before uploading it. The following table contains sample data for the columns in the sample template.
User ID
Approval Role
Member Type
Level 1
Level 2
Level 3
benbradle@planful.com
Reviewer
Rollup
Budget Hierarchy
Denver - Denver HQ
benpage@planful.com
Budget Approver
Leaf
Budget Hierarchy
Denver - Denver HQ
Australia
ben@planful.com
Simple Budget Approver
Leaf
Budget Hierarchy
Denver - Denver HQ
Australia
In the required levels, every rollup member must have the details in the “Member Code - Member Name” format.
You can have more levels depending on the hierarchy that you have defined in the application.
Ensure that you delete all the instructions in the sample file before uploading it.
4. Save the XLSX file to your computer.
Click Choose File and upload the template from your computer.
Click any one of the following options from the Upload Actions field:
Overwrite: To overwrite all the existing levels and approval roles. Or, to overwrite a specific level or overwrite specific approval roles. To do so, you can download the file for a specific user and update the required levels/approval role, and then upload the file to replace the existing data for this user with the data in the uploaded file.
Note:
If you want to overwrite specific levels or overwrite specific approval roles, it is important that you download the ApprovalRoleExport excel file by using the required option from the Export drop-down list.
Append: To update the existing approval roles and to add additional levels with approval roles.
Click Upload.
After the file has been uploaded, a confirmation message is displayed. Click through to the Detail View dialog box (as shown here) to view the status of the upload action. Additionally, a process called ApprovalRolesUpload is created on the Job Manager page (as shown here).
If the upload process failed or was completed with errors, select the Click Here link under the Status column of the Detail View dialog box. This action downloads an Excel file with detailed information about why the failure occurred.
An example of a failed upload process is shown here. Fix the errors and upload the file again.
After the approval roles have been uploaded successfully, a confirmation message is displayed. The uploaded approval roles are displayed on the Approval Role Setup page, as shown here.
Best Practices:
To make permission management easier, you can use the user export options. If you use this feature, you do not have to worry about the format; you can just make the necessary changes to the exported information and quickly reload the file.
You can use the Overwrite functionality to replace data. If you want to completely remove the existing data and replace it with new data, use the Overwrite option; otherwise, you can just use the Append option.
If you are a bit hesitant to use this functionality, you should try out this new feature in your sandbox environment. After you are familiar with the functionality, you can make any changes to the Approval Roles or Permissions on your production environment.
Export Approval Role
Export Approval Role at User-Level Setup:
You have the ability to export the Level and Role details of a user. Once exported, you can make modifications or add additional information, and then import the updated data.
Click the Export drop-down list. A list of options appears.
You can perform any one of the following actions:
Click Export All Users to export the approval roles and budget entity permissions of all the users in the application.
Click Export Current User to export the approval roles and budget entity permissions of the user currently selected in the User list box.
Click Export Selected Users to export the approval roles and budget entity permissions of the users selected in the Export Selected Users window.
Click Ok.
The ApprovalRoleExport excel file is downloaded with the required approval roles.
Make the required changes, and then import the uploaded file.
Export Approval Role at User Group-Level Setup:
At the User Group level, only export is supported for audit or reference purposes. Administrators can use this feature to review existing group-level approval role data.
To export Approval Roles at the User Group level, the following include options are available:
Export All User Groups – Exports approval roles and budget entity permissions for all user groups.
Export Current User Group – Exports approval roles and budget entity permissions for the currently selected group.
User Security and Inherited Security Tabs
When the selected user inherits permissions and roles from the user group level, the Approval Role Setup page includes two tabs: User Security and Inherited Security.
The User Security tab lists all budget entities and role assignments defined at the user level.

The Inherited Security tab, displays the Budget Entities, Roles, and the User Group(s) from which the user group access is inherited.

Use these views to audit permissions and troubleshoot why a user or user group can or cannot access a specific budget entity.
.png?sv=2022-11-02&spr=https&st=2025-11-02T12%3A43%3A54Z&se=2025-11-02T12%3A53%3A54Z&sr=c&sp=r&sig=J7CYKQsRYsb4bnPv2GTIESC9Iza7uEWSWVOQ75rUwEI%3D)