Who sees what
mizuiro’s job is to keep the right information in front of the right people. Every record - a touchpoint, a performance review, an expense report - has explicit rules about who can see it, who can edit it, and who can open the detail page. This page is the reference for how those rules work, written for managers who need to reason about confidentiality.
In one line: managers see everything in their company. Supervisors see what’s relevant to the people they look after. Employees see their own records and the things that have been explicitly shared with them. What “relevant to the people they look after” means depends on your supervisor scope setting from the setup wizard.
There’s also an HR role: a company-wide “mini manager” who looks after everyone’s records, but only inside the HR areas (performance, presence, incidents, kudos, reports, and training). Outside those, they see nothing. There’s a section on HR further down.
You picked one of these at setup; it can’t be changed afterwards.
Assigned scope is narrow. A supervisor only acts on people in the teams they lead. The Sales supervisor doesn’t see the Engineering team’s expense reports, training records, conferences, or touchpoints. Performance documents (reviews, concerns, improvement plans, written warnings) and incidents are private to the supervisor who created them - even another supervisor on the same team can’t read the contents.
Shared scope is wide. Every supervisor can see every record in the company. This works for smaller organizations where the supervisor layer functions more like a co-management layer with the primary manager.
Across both scopes, managers always see everything. And employees only ever see their own records, plus anything you’ve explicitly shared with them (e.g. a performance review you toggled to be visible to its subject).
The grid below assumes a module is turned on. If a module is off for your company, nobody sees its records.
| Module | Manager | Supervisor (assigned) | Supervisor (shared) | Employee | HR |
|---|---|---|---|---|---|
| Employees (directory) | Everyone | Everyone | Everyone | Everyone by default (you can narrow it to their own teams, or nobody), but a coworker’s card, People list row, team page row and search result show directory fields only - name, title, team, @mention, email. Employment status, employee number, hire date, probation and other employment dates, phone, last login, and scheduled status changes are all hidden, and the People list has no status tabs or status/hire-date sorts for them. Their own card shows everything. | Everyone, full details (company-wide) |
| Presence calendar | Everyone | People on their teams | Everyone | No access to the Presence module. With Time off on, a filtered calendar of their own time on that page (no in late / left early / no show / long break) | Everyone |
| Touchpoints | All | Touchpoints they conducted or that involve their team | Everyone | Their own non-private touchpoints, when employee visibility was on at creation | Never (not an HR area) |
| Minutes (freeform meeting minutes) | All | Only the meetings they wrote | Only the meetings they wrote | Never | Never (not an HR area) |
| Tasks | All except other people’s self-assigned (private notes) | Their team’s tasks + their own + tasks they created | All except other people’s self-assigned | Tasks assigned to them | Never (not an HR area) |
| Expenses | All | Their own + their team’s | Everyone | Their own | Never (not an HR area) |
| Policies | All, incl. drafts | Published ones that apply to them; acknowledge | Published ones that apply to them; acknowledge | Published ones that apply to them; acknowledge | Published ones that apply to them; acknowledge (reader only, no manager side) |
| Time off | All | Their own + their team’s | Everyone | Their own, plus a filtered calendar of their own presence (no in late / left early / no show / long break) | Never (not an HR area) |
| Conferences | All | Their own + their team’s | Everyone | Their own | Never (not an HR area) |
| Training | All | Their own + their team’s | Everyone | Their own | All |
| Awards | All | Their team’s | Everyone | Their own | Never (not an HR area) |
| Kudos | All | Their team’s | Everyone | Their own | All |
| Performance reviews | All | Reviews they conducted (their team’s too, if you allow it) | Everyone | Reviews about them that the manager has explicitly shared | All |
| Performance concerns | All | Concerns they recorded (their team’s too, if you allow it) | Everyone | Never (manager-only sensitive HR) | All |
| Improvement plans (PIPs) | All | PIPs they created (their team’s too, if you allow it) | Everyone | Their own plan (read-only, once communicated; no linked evidence or manager notes) | All |
| Written warnings | All | Warnings they issued (their team’s too, if you allow it) | Everyone | Their own (read-only, with acknowledgement) | All |
| Incidents | All | Incidents they filed (ones involving their team too, if you allow it) | Everyone | Never | All |
| Polls | All | Company-wide polls, polls targeting their teams, polls they’re invited to, and ones they created | Everyone | Company-wide polls, polls targeting their teams, polls they’re invited to, and ones they created | Never (not an HR area) |
| Kikubari (people insights) | All | Their team’s | Everyone | Never (they contribute through get-to-know-you polls, not by opening Kikubari) | Never (not an HR area) |
| Contacts | Everyone | Everyone | Everyone | Everyone (company-wide directory), unless you hide Contacts from employees | Everyone (company-wide directory) |
| Reports | All company data | Restricted to their teams in assigned scope | All company data | No access (manager / supervisor only) | HR-area reports only (nothing that draws on expenses, tasks, or other non-HR areas) |
The History tab is a chronological audit of HR events for one person: profile changes, status changes, performance concerns, PIPs, written warnings, and incidents. It’s designed to give whoever is looking after the person a complete picture.
To support that, the History tab always shows every event the employee is associated with, even ones the viewer doesn’t have read access to.
What changes per viewer is whether each event is clickable. If a supervisor in assigned scope is looking at a teammate’s history and sees a performance concern recorded by a different supervisor, the row appears - they can see the date, the type of event, and who filed it - but the reference number is shown as plain text rather than a link, and the severity badge is hidden. Hovering shows “You don’t have access to this record.”
This is deliberate. A complete audit picture matters more than strict hiding, and the protected content (the specifics inside the record) stays unreachable.
The presence calendar follows the same principle: a touchpoint badge that the viewer can’t open renders as a static violet pill rather than a link. Incident badges are always non-clickable by design.
HR accounts are for people who look after the whole company’s HR records without running the whole company. Think of them as a “mini manager” scoped to the HR side of mizuiro: they have manager-level reach over everyone’s records, but only inside the HR areas - performance (reviews, concerns, improvement plans, written warnings, probation), presence, incidents, kudos, training, and reports. Everywhere else - expenses, tasks, conferences, awards, polls, meetings, Kikubari - they have no access at all, and those areas don’t even appear in their sidebar.
Unlike an observer, HR can read and write in their areas: they file incidents, record performance concerns, log training, and so on, across the whole company rather than just one team. Reports are filtered to the HR areas, so an HR user never sees a company-spend or expense report.
You invite an HR user the same way you add anyone else, from the People page - pick HR as their role. They aren’t assigned to teams, because they look after everyone.
Observer accounts are a special kind of manager account with read-only access. An observer sees everything a manager would see - no records are hidden - but every write action is blocked at the server level. They can browse, search, export, and review, but they can’t add, edit, delete, or approve anything.
Observers exist so a business owner, accountant, or board member can stay across what’s happening without needing operational permissions.
If you’re trying to figure out whether someone on your team can or can’t see a specific record, the quickest check is to ask them to look. If they can see the record, the access rules allowed it. If they can’t, the rules excluded them. The grid above is the intent, and mizuiro enforces it everywhere: a record someone isn’t allowed to see is never put in front of them in the first place, rather than hidden in the interface.
If you think you’ve found a case where someone is seeing something they shouldn’t, email support and tell us how to reproduce it. We treat visibility bugs as security bugs and respond fast.