Guides by role
What we can do in the Workbench depends on two things: our role on each engagement (lead, analyst or viewer) and, separately, whether we have PII access (access to names and emails) on it. A few colleagues are also platform administrators. This page sets out what each role is for, the pages each needs, and a checklist.
The rules are enforced by the database, not only by the screens, so a button that isn't shown to us really isn't available. See Team and roles for how roles are granted.
Who can do what
| Action | Viewer | Analyst | Lead | Administrator |
|---|---|---|---|---|
| See the engagement (only engagements we're staffed on) | ✓ | ✓ | ✓ | Every engagement |
| Read every tab of a staff list: the report, Explorer, Organisation, Savings by group, Classifications, Copilot case, Rollout plan, Assumptions | ✓ | ✓ | ✓ | ✓ |
| Try assumptions and Copilot settings without saving them | ✓ | ✓ | ✓ | ✓ |
| Ask questions with Ask this workforce (when AI is available) | ✓ | ✓ | ✓ | ✓ |
| Compare staff lists | ✓ | ✓ | ✓ | ✓ |
| Export deliverables that contain no names | ✓ | ✓ | ✓ | ✓ |
| Upload, continue or delete staff lists | ✓ | ✓ | ✓ | |
| Override classifications | ✓ | ✓ | ✓ | |
| Save assumptions; rescore with newer reference data | ✓ | ✓ | ✓ | |
| Write the executive summary or value-chain map with AI | ✓ | ✓ | ✓ | |
| Save and delete rollout plans | ✓ | ✓ | ✓ | |
| Manage the team, including granting PII access to others | ✓ | ✓ | ||
| Change engagement settings (name, industry pack, region, retention, sharing) | ✓ | ✓ | ||
| Change the engagement's report wording | ✓ | ✓ | ||
| Close, reopen or purge the engagement | ✓ | ✓ | ||
| Read the engagement's audit trail | ✓ | ✓ | ||
| Delete an engagement outright | ✓ | |||
| Use Admin: users, classification cache, audit trail, reference data, Prompt Lab, AI usage | ✓ |
Every signed-in colleague can also create clients and engagements and use Methodology and Benchmarks.
Two rules sit across the table:
- Writing needs an active engagement. Once an engagement is closed, everything in it is read-only for everyone until a lead reopens it.
- Names and emails need PII access, whatever the role, administrators included. See With access to names and emails.
Consultant or analyst
Analysts do most of the hands-on work: getting the staff list in, making sure titles are classified properly, setting the assumptions, building Copilot plans and producing deliverables.
Pages to know
- Preparing a staff list and Uploading a staff list
- Classifications and overrides, and Correct a classification
- The report, Explorer, Savings by group, Organisation, Value chain and Assumptions
- Copilot business case, Rollout plan and Plan a Copilot pilot
- Exports and Prepare a client pack
- Refresh with a new staff list and Compare staff lists
Checklist
- Check the file against Preparing a staff list before uploading.
- On upload, check the column mapping, the row filter and the tenant names; map FTE and tick any Extra groupings the client wants savings shown by; leave Store names and emails, encrypted unticked unless the work needs names.
- Clear the review queue on Classifications, largest titles first, with a rationale for every override.
- Agree the employer-cost multiplier and location factors with the lead, then Save and rescore.
- If the staff list offers Rescore with version N, decide with the lead whether to rescore before figures go to the client.
- Check every figure's provenance badge before it goes in a deliverable; salmon badges are assumptions.
- Label capacity as gross annual capacity, not savings, in anything we write.
Engagement lead
Leads own the engagement: who's on it, how it's set up, what goes to the client, and when the data is purged. A lead can do everything an analyst can.
Pages to know
- Engagements, Team and roles and Share an engagement
- Closing an engagement and Respond to a deletion request
- Names, emails and personal data
- Provenance and methodology and Benchmarks
- Prepare a client pack
Checklist
- When creating the engagement, choose the right Industry pack and Keep data after closing (days), and untick Share job-title classifications across engagements if the client's contract forbids any reuse.
- Add the team with the least access the work needs: viewer unless they change things; PII access only when the work needs names.
- Review overrides on the Overrides tab before the analysis is finalised.
- Sign off the assumptions and the reference data version each deliverable uses.
- Add any client-specific wording (section paragraphs, the value-concentration point, word swaps) under Report wording on the engagement's Settings tab before exporting; only leads (and administrators) can change it.
- Read the Audit trail before sending a pack: exports, reveals of names and changes are all there.
- Close the engagement when the work is done, and purge early if the client asks.
- Remove people from the team when they roll off.
Viewer
Viewers read and export; they don't change anything. It suits a partner reviewing the work, or a colleague who presents the findings. On the Assumptions and Copilot case tabs a viewer can try values to see their effect, but can't save them.
Pages to know
- Quick start
- The report, Explorer, Savings by group, Organisation and Copilot business case
- Provenance and methodology
- Exports and Compare staff lists
Checklist
- Use the provenance badges to see where a figure comes from before quoting it.
- Check the staff list's reference data version and any Review before sharing label on an AI summary.
- Ask the lead for analyst access if changes are needed; the screens say Viewers can read this engagement but not change it; the engagement lead can grant analyst access.
Administrator
Administrator is a platform role, separate from engagement roles. Administrators manage who can sign in, the shared classification cache, the reference data and AI prompts every figure is built from, and they watch the platform-wide audit trail and AI spend. On any engagement they can act as its lead, shown as Admin view where they aren't on the team, and they alone can delete an engagement outright.
Pages to know
- Administration, Users and Audit trail
- Classification cache
- Reference data and Update pay data
- Prompt Lab and Change an AI prompt
- AI usage
Checklist
- Add colleagues on Admin → Users before their first sign-in when they need to go straight onto a team; deactivate leavers the day they go.
- Keep at least two administrators.
- Load new editions of source data (such as ONS ASHE pay) as a new reference data version, with notes on what changed and why.
- Test every prompt change against the live version before publishing.
- Check AI usage against the monthly budget.
- Remove wrong entries from the classification cache rather than overriding them engagement by engagement.
Being an administrator gives no access to names and emails. An administrator who needs them on an engagement must be on its team with PII access, granted by someone else, like anyone else.
With access to names and emails
PII access is granted per engagement, to a person, on top of their role. It's needed to:
- store names and emails at upload (Store names and emails, encrypted);
- reveal names in the Explorer and the organisation chart (Show names (audited));
- match a client's list of emails (licensed users, or a named cohort) against the stored, encrypted emails;
- export the Copilot allocation workbook with names.
Every one of these is recorded in the audit trail with a purpose, and marked with a salmon dot.
Nobody can grant PII access to themselves, administrators included: another lead or an administrator grants it. The one exception is the person who creates an engagement, who becomes its first lead with PII access.
Pages to know
- Names, emails and personal data
- Rollout plan (matching licence lists and the allocation workbook)
- Respond to a deletion request
Checklist
- Store names only if we need named licence lists or to match a list by email; employee IDs cover everything else.
- Reveal names only for the task in hand; Hide names (or leaving the page) forgets them.
- Treat the allocation workbook as personal data: send it only through an approved, secure route.
- Give up PII access when the work no longer needs it: a lead can untick it on their own row; anyone else asks a lead.