Teamflect lets you limit what certain admin roles can access based on user attributes such as Department, Country, Office Location, or custom user attributes.
This helps ensure that Scoped Administrators and Report Readers only manage or view the parts of the organization relevant to them: supporting localized oversight, compliance, and operational efficiency.
Common Scenarios
Scenario 1: Regional HR for country-specific compliance
Your company operates in Germany, France, and the UK, and each country has different HR compliance requirements.
You assign Scoped Administrator access to the HR lead in Germany with:
Country = Germany
So they can manage only German employees and stay focused on local requirements, without visibility into other countries.
Scenario 2: Office manager oversight for a single site
You have multiple physical offices (e.g., London, Toronto, Austin). Each office has an administrator who handles local people operations.
You assign Scoped Administrator access scoped by:
Office Location = London
So the London office admin only manages users tied to the London location.
Scenario 3: Department-only access for a functional admin (shared services)
Your Customer Support Operations team needs someone to manage/administer only Support users (not the whole org).
You assign a Scoped Administrator with:
Department = Customer Support
So they can administer that department without accessing employees in other functions.
Scenario 4: Regional leadership reporting without admin management
A regional leader needs to view reports for their region but should not have broader administrative capabilities.
You assign Report Reader with:
Country = Canada
So they can access only the Reports section in Admin Center, and only for Canada.
Scenario 5 (AND logic): Regional + Department scoping for precise ownership
A leader owns Sales for Germany and shouldn’t access Sales in other countries, or other departments in Germany.
You assign scoped access using multiple attributes (AND / must match all), such as:
Department = Sales
Country = Germany
Result: They can access only users who are both in Sales and in Germany, which prevents overexposure while still enabling accurate regional management.
⚠️ Note: To use scoped access, the attribute(s) you want to scope by (for example, Department, Office Location, or Country) must already exist in either Teamflect custom attributes or your Microsoft Entra ID (Azure AD) user profile data.
Before you start
You need to be a Global Administrator to access to the Teamflect Admin Center to edit user roles.
Make sure the relevant users have the correct attribute values populated (for example, Country = “Brazil”, Office Location = “San Francisco Office”). If values are missing, scoping may not work as intended.
Step 1: Access the Admin Center
Go to Teamflect Admin Center - https://admin.teamflect.com.
Navigate to Users → Active Users.
Step 2: Edit the User Role
Find the person you want to grant scoped access to.
In the Teamflect Role column, click the pencil (edit) icon next to their current role.
Step 3: Assign a Role and Access Type
In Select user role, choose one of the following:
Scoped Administrator (for delegated admin management within a defined scope)
Report Reader (for read-only access to Reports in the Admin Center)
Step 4: Define the Access Scope (attribute-based)
Under Access Scope:
Select the first attribute you want to use, such as:
Department
Country
Office Location
Any supported custom attribute
Choose one or more allowed values for that attribute.
Important: If you leave the values empty, the rule applies to all values of that attribute (meaning it won’t restrict access by that attribute).
Your Admin Center supports adding more than one attribute rule, repeat the process to further narrow access using additional attributes by clicking the ''Add new rule'' button and selecting various attributes that suit your exact scenario.
What this means for Scoped Admins vs. Report Readers
Scoped Administrators can manage only the users/areas that match their defined scope.
Report Readers can access only the Reports section in the Admin Center, and their visibility is limited based on the scope you set.
Attribute-based scoped access helps administrators focus on the areas they know best, reducing risk while improving efficiency, compliance, and accountability. It’s a practical way to scale administration across regions without giving everyone full global access.




