Who Can See What
FiscFlow shows each person only the work that's theirs to see. This page explains what makes something visible to you, why "seeing" and "acting" can differ, and when a change to access actually takes effect.
The two ways you can see something
You can see a submission, requisition, or position through exactly one of two paths:
You own it
You always see your own submissions, your own positions, and the requisitions they're on - no filter required.
You're granted as an approver
You hold a position whose approval filters match the item, in the same fiscal year - and no Deny filter excludes it.
Three things that override everything
No matter how filters are set, an approver sees nothing unless all three hold:
- Their role can view work items
The master switch for seeing anyone else's work.
- Their user account is active
A deactivated account sees nothing granted by filters.
- The fiscal years match
A filter only grants within its own assignment's fiscal year. Last year's access doesn't reveal this year's work.
Members of the Administrators role bypass all visibility rules. Everyone else is governed by ownership plus approval filters.
Seeing isn't the same as acting
This is the subtle behavior people notice most. On a multi-site position, visibility is scoped per site:
- You might see a position in your list, yet be unable to see or act on a submission tied to a site you're denied on.
- A submission at a site you're allowed on is visible and actionable; the same position's submission at a denied site is neither.
- Individual hours entries follow the assignment, not the site. Per-site scoping is enforced at the submission level - so a submission at a denied site is hidden from you, but the individual hours rows beneath it can still be visible. Refining scoping down to each hours row is a known follow-up.
The rule is consistent: if you can't see a submission, you can't approve it either. The list and the action buttons always agree.
How Allow and Deny scope differ
| Filter | Scope behavior |
|---|---|
| Site/Location Deny on a requisition or position list | Applies per site - denying one of several sites doesn't hide the whole position if another allowed site still carries it. |
| Account Deny (no site) | Applies broadly - it can veto the whole item regardless of site. |
| Any Deny vs. Allow | Deny always wins where it matches. |
When a change to access takes effect
FiscFlow keeps a fast, cached picture of what each person can see, and refreshes it intelligently:
| Change | When you see it |
|---|---|
| A change you make (adding a filter, approving, editing a position) | Immediately. |
| A change someone else makes that affects your access | The next time you open a view (within a few seconds), or when you press Refresh. |
| Routine edits (a comment, an amount, a status tweak) | Don't change anyone's visibility, so nothing needs to refresh. |
If site assignments are rewritten by a bulk import or an outside-the-app process without touching the owning position or site record, the affected people may not see the change until their next login. When in doubt after a large import, have users sign out and back in.
"Why can't I see this?" - a checklist
If someone expects to see a submission and doesn't, walk these in order:
- Does their role have Can view work items?
- Is their user account active?
- Is their approver position in the same fiscal year as the item?
- Do they have an Allow filter that matches its account/site/classification?
- Is a Deny filter excluding it (remember Deny wins)?
- For a multi-site item, are they allowed on that specific site?
- Did the access change recently? Have them press Refresh or re-open the view.