> ## Documentation Index
> Fetch the complete documentation index at: https://help.honestly.com/llms.txt
> Use this file to discover all available pages before exploring further.

# How does Auto-Assignment work, and are admins protected?

> Set roles and data access from rules instead of person by person — and see why your admins are never changed by them.

Assigning a role and data access to every new person by hand is slow, and easy to get wrong on a large import. **Auto-Assignment** lets you set up rules once so that everyone gets the right role and permissions automatically — whether they were added manually, via CSV or through an HCM sync.

[Open Account settings ↗](https://webapp.honestly.de/app#/account/settings) · Opens the webapp — please log in first · Admins only

You will find it under **Account settings → Auto-Assignment**.

### How the rules work

A rule set is a list of rules, checked from top to bottom. The first rule a person matches decides their role and their permission scope; no later rule can override it. Everyone who matches no rule falls to the **Fallback rule** at the bottom, which always applies and needs no conditions.

Each rule is made of conditions that must all apply. A condition looks at an attribute — for example job title, department or job level — or at whether the person **has direct reports** in your org chart. You give the rule a role (Report viewer, Analyst or Manager) and a permission scope, and that is what a matching person receives.

### Your admins are never touched

This is the part customers ask about most, so it is worth stating plainly: **Admins are exempt from the rules — their role and their data access stay unchanged.**

* You do not need a helper attribute such as "is admin". The protection is built in and applies automatically to anyone who is an Admin at the moment the rules run.
* A rule can never hand out the **Admin** role. Admin stays a deliberate choice you make by hand in a person's profile.
* Because of this, a rule like "has direct reports → Analyst" will not downgrade your existing admins. They are skipped before any rule is checked.

#### If you remove someone's admin role

Admin status is read fresh every time the rules run, not stored as a snapshot. So if you take the Admin role away from someone by hand, they are no longer exempt: from that point on the rules apply to them like anyone else.

### Draft, preview and publishing

Nothing changes while you are editing. **Rules start out as a draft. Nothing changes until you publish them.**

When you are ready, click **Review & publish**. The preview checks every person against your rules and shows, before anything happens:

* **Who changes** — how many people get a different role or data access.
* **People losing access** — who ends up with a smaller role or narrower data access than before.
* **People receiving an email** — anyone without an account who becomes Manager, Analyst or Report viewer gets an account and an email asking them to set a password. People who already have an account get none.
* **Admins with no change** — a count confirming your admins are left as they are, with the note *"Rules never change the role of an admin."*

Only when you click **Publish and apply** do the rules take effect.

<Note>
  Emails that have gone out cannot be recalled. Use the preview to check who would receive one before you publish.
</Note>

### When roles are re-checked

Once published, the rules stay in force. They are checked again after every change to a person and after every CSV or HCM import, so a new hire or a changed job title lands in the right role without anyone doing it by hand.

### What Auto-Assignment does not touch

Surveys and survey properties are not part of Auto-Assignment. Any survey or survey-property permissions you granted directly stay exactly as they are.

For what each role can see and do, see [Rights & roles](/help/employees/rights-and-roles).
