Skip to main content

Control Who Can See Which Applicants and Workers

How access works in Fountain: locations, openings and job restrictions, User Groups, and what to check when someone sees too much or too little.

Access decides which applicants and workers each of your users can see. You control it by giving people locations, location groups, openings and jobs — either directly, or through User Groups. What you set applies across Fountain, so a user sees the same set of people wherever they work.

This article explains how access is calculated, how to set it up with User Groups, and what to check when someone sees more or less than you expect.

Access is not the same as permissions

Access controls which people a user can see. Roles and permissions control what they can do with them. A recruiter can have permission to message applicants and still see none, because access has not been given. See User Management: Roles and Permissions.

How Fountain calculates access

A user sees everything in the locations they were given that also matches their job restrictions, plus everything in the openings they were given directly.

What adds access

Locations and location groups. A location group also brings every location inside it, and a location brings every opening inside it.

Openings. Granted one by one.

Access granted directly to a user and access granted through a User Group are combined. Neither replaces the other.

If a user belongs to User Groups covering locations L1 and L2, location groups G1, G2 and G3, and openings O1, O2 and O3 — and is also given direct access to opening O4, location L3 and location group G4 — then they can see:

  • location groups G1, G2, G3 and G4

  • locations L1, L2 and L3, plus every location inside G1, G2, G3 and G4

  • openings O1 to O4, plus every opening inside all of the locations above — narrowed by their job restrictions, if they have any

What narrows access

Job restrictions. Jobs cut down what the locations already gave. They never grant anything on their own.

A user with access to the location Lombard Street and to the jobs Cashier and Barista sees only Cashier and Barista openings at Lombard Street. They do not see the other jobs at Lombard Street, and they do not see Cashier or Barista at any other location.

Because job restrictions quietly reduce what a location grants, they are the most common reason a user with plenty of locations still sees very little.

What overrides everything else

Three things grant access regardless of how you configure locations, openings, jobs and User Groups. Account for them before you conclude that access is set correctly.

Override

Effect

How to control it

Public openings

An opening not marked Limit Access is visible to every user in the account

Open the opening and turn on Limit Access

Unrestricted-access permission

Ignores all location, location group, opening, job and User Group restrictions

Remove it from any role that is not an administrator role

Ownership

Opening owners and location owners keep access to what they own

Reassign the owner on the opening or location

Depending on the settings screen you are looking at, the unrestricted-access permission is labelled Unrestricted applicant access (bypasses user-level access) or Can view all workers independently of user access. Both do the same thing: they switch off every restriction described in this article. Reserve them for administrators.

Set up access with User Groups

When several people need the same access, put them in a User Group rather than assigning locations and openings to each person one by one. A group of 500 recruiters covering 1,000 openings is one group to maintain instead of 500 user records.

Name the group after the boundary it represents — a region, a brand, a district — so the reason it exists is still obvious a year later.

Create a User Group

  1. Click your account name in the bottom left corner, then Settings.

  2. Under Users, click User Groups.

  3. Click Add user group.

  4. Type a Name.

  5. Choose an Access TypeLocations, Location Groups or Openings.

  6. Pick the entries the group covers from the Resources list. It is searchable and paginated, and Select all applies to every match, not only the page you are looking at.

  7. Click Save.

Each User Group covers one Access Type. To give a team a set of location groups plus a few extra openings, create one group of each type and assign both — a user's groups add up.

Put users in a group

There are three ways a user ends up in a User Group:

  • You assign them. Open the user under Settings > Users and select the groups they belong to.

  • A role adds them. If the group is linked to a role, granting that role adds them automatically. See Assign User Groups automatically below.

  • Your identity provider adds them, if you drive membership through SCIM.

A user can belong to as many User Groups as needed, and their access is the sum of all of them. To check the result from the other direction, open the group itself — its Current users panel lists everyone in it, however they got there.

Give one user access directly

Direct access is for exceptions — one person who needs one extra opening or one extra location. It is assigned on the user record under Settings > Users, and it adds to whatever their User Groups already give them.

A direct grant on an opening also takes priority over job restrictions: the user sees that opening even when its job is not in their job list. That makes it the right tool for a one-off exception, and the wrong tool for anything recurring — direct grants are the hardest access to review later, because they sit on individual user records instead of in one named group. If you assign the same direct access twice, make it a User Group instead.

Why a user sees more or less than you expect

A user sees more than expected

  • The openings are public. This is the most common cause by a wide margin. Check whether the openings in question have Limit Access turned on; without it, every user in the account sees them.

  • Their role bypasses access. Check the role for the unrestricted-access permission described above.

  • They own the opening or the location. Ownership is not affected by group or location settings.

  • A location group grew. Adding a location to a location group gives it to everyone whose access includes that group, without any change to their user record.

  • They kept a group after a role change. A group linked to a role adds members when the role is granted, but never removes them when it is taken away. Check the group memberships on the user directly.

A user sees less than expected, or nothing

  • Job restrictions are cutting the list. Jobs narrow locations. A user whose job list matches no opening in their locations sees nothing. Either widen the job list, or grant the specific openings directly.

  • No openings exist yet under their locations. An empty list can simply mean there is nothing there.

  • The change has not taken effect yet. In Hire Go, the set of openings a user can reach is cached for up to one hour. A change you just made — granting access or removing it — can take that long to appear. Allow for this when you check your work, and do not re-edit in the meantime; repeated edits while waiting are a common way to end up with access you did not intend.

Assign User Groups automatically

Two options remove the manual step of putting each person into the right group.

From your identity provider, with SCIM

If you provision users with SCIM, group membership can be driven from your identity provider alongside roles and location access, so a change in your directory reaches Fountain without anyone editing a user by hand.

This is off by default and has to be turned on deliberately. Before enabling it, ask your Fountain Customer Success contact what happens to memberships you assigned by hand, so you do not lose assignments your directory does not know about. See SCIM User Provisioning.

When a role is granted

A User Group can be linked to one or more roles. Granting a user any of those roles automatically adds them to the group, so nobody has to remember to do it separately. You set this on the group itself, under Add users when a role is granted, by picking the roles in the Roles list.

Taking the role away does not remove the access

Role links only ever add members. If you later remove that role from a user, they stay in the group and keep the access it grants. To remove the access, take them out of the group as well.

This matters most when someone changes team or leaves: review their group memberships, not just their role.

Did this answer your question?