Companies can delegate HR tasks securely using the new role and permissions management system in the employer portal of the Bundesagentur für Arbeit (Germany’s Federal Employment Agency). Employees, individual locations and external service providers receive only the specialist roles they need for their tasks. Every authorised person requires their own account and must use mandatory two-factor authentication.
What is changing about access rights in the employer portal?
Companies can now allocate tasks more precisely without giving everyone involved extensive administrative rights. Alongside two administrative roles, eight specialist roles are available.
On 12 August 2026, the Bundesagentur für Arbeit provided information about the improved role and permissions management system in the employer portal. The two administrative roles are Unternehmens-Admin (company admin) and Gruppen-Admin (group admin).
The Unternehmens-Admin manages permissions across the entire company. A Gruppen-Admin, by contrast, is responsible for a defined group, such as a branch, department or business unit.
There are also eight specialist roles:
- Entlassungsanzeigen (redundancy notifications)
- Arbeitnehmerüberlassung (temporary agency work)
- ausländische Beschäftigte (foreign employees)
- Weiterbildungsförderung (continuing education funding)
- Kurzarbeitergeld (short-time work allowance)
- Lohnkostenzuschüsse (wage cost subsidies)
- Personalmarketing (recruitment marketing)
- Personalsuche (recruitment)
One person may be assigned several specialist roles. Each role can also be assigned as many times as required. For example, two HR employees can handle Personalsuche, while only the payroll team is given access to Kurzarbeitergeld.
How can HR tasks be delegated securely?
Assign each role to a specific task and grant only the permissions required for it. This makes it possible to track who publishes vacancies, applies for funding or processes information about foreign employees.
A company with three branches can create a separate group for each location. The manager at each location receives the Gruppen-Admin role and manages the people responsible there. At the same time, the central HR department can take on specialist roles for all locations if this suits the company’s internal organisation.
Roles can also be divided by department. For example, the recruitment team can receive the Personalsuche and Personalmarketing roles. Payroll can be given Kurzarbeitergeld and Lohnkostenzuschüsse. A person responsible for international employees receives the appropriate ausländische Beschäftigte specialist role.
Before setting up the system, it is worth creating a simple table with four columns:
- Name of the authorised person
- Location or department
- Required specialist role
- Person responsible for reviewing and withdrawing access
This overview does not automatically prevent roles from being assigned incorrectly. However, it makes regular checks easier. If roles and other digital processes have not yet been organised consistently, a structured approach to the digitalisation of processes can help replace paper lists and separate Excel files.
How are tax advisers and other service providers included?
Tax advisers, professional firms and other external service providers can be assigned specific individual roles. They do not require full administrative rights.
This is useful, for example, if a tax advisory firm handles Kurzarbeitergeld but does not need access to Personalsuche or Personalmarketing. An external recruitment agency can instead receive the Personalsuche role without being able to process funding applications or redundancy notifications.
According to the Bundesagentur für Arbeit, accounts belonging to authorised representatives can be managed more precisely. Authorised representatives registered before 20 July 2026 automatically receive the “Personalsuche” role and retain their previous access.
Companies should still review this automatically transferred access. The key questions are whether the authorisation remains valid and whether the person still performs the task. If the relationship with a professional firm or service provider ends, the responsible administrator should withdraw access promptly.
What login and security measures are required?
Every authorised person requires their own account. Shared login details are not compatible with permissions assigned to named individuals and make checks more difficult.
Two-factor authentication is mandatory. It adds a second form of verification to the password or standard login. According to the Bundesagentur für Arbeit, the available options are BundID, Passkey, BA-Secure-App or TOTP, and the Unternehmenskonto (company account).
A passkey is a digital login key stored on a device. TOTP is a time-limited, one-time code generated by a suitable app. The Bundesagentur für Arbeit provides an overview of access options and available methods on its eServices für Unternehmen page.
When introducing the system, your company should decide which login method will be used and who will provide support when a device is replaced. You also need a defined process for new starters, internal transfers and departures. A new smartphone or an employee leaving the company must not result in access remaining unchecked indefinitely.
How can SMEs introduce the new permissions system effectively?
Start with the online services you actually use, rather than every role that might theoretically be relevant. You should then check, at least whenever staffing changes occur, whether the assigned permissions are still required.
The following process is suitable for introducing the system:
- Record all existing users and authorised representatives.
- Define locations, departments or business units as groups.
- Appoint the Unternehmens-Admin and the required Gruppen-Admins.
- Assign specialist roles based on specific tasks.
- Set up individual accounts and two-factor authentication.
- Review automatically transferred Personalsuche permissions.
- Schedule regular reviews of permissions.
Separating administration from specialist work is particularly important. Someone who handles recruitment does not automatically need permission to manage access rights. Conversely, a Gruppen-Admin does not necessarily require every specialist role.
ibx company advises small and medium-sized businesses in Hannover and the surrounding region on introducing clear digital processes and appropriate responsibilities. If you would like to review your roles, groups and existing HR processes together, you can arrange a no-obligation initial consultation about practical implementation.