You built your payroll system to run pay, not to be a security worry. But one afternoon you stop and ask a simple question: who in this company can actually see Social Security numbers, bank account details, and everyone's salary? If the honest answer is "I am not totally sure," you are not alone. Access tends to grow quietly. A role gets copied for a new hire, a manager gets extra permissions for a one-time project, someone leaves and their login lingers. None of it feels risky in the moment, and then it adds up.
The stakes are real. Pay and personal data are exactly what a bad actor wants, and they are also what an auditor asks about first. A single over-permissioned account can turn a small mistake into a big exposure. The fix is not to lock everything down so tightly that nobody can do their job. The fix is to give each person the access they need and nothing more, and to check that it stays that way.
This guide walks through how access works in ADP Workforce Now, the principles that keep it tight, how the main roles should differ, how to shut off access the moment someone leaves, and how to run a review that keeps the whole thing honest.
ADP Workforce Now is built around roles. A role is a bundle of permissions that decides what a person can see and do. Instead of hand-picking permissions for each individual, you assign people to roles, and the role carries the rules. This matters because roles scale and individual tweaks do not. When you grant permissions one at a time, you end up with dozens of slightly different accounts that nobody can explain a year later.
Define a small set of clear roles that match how your organization actually works. A practitioner role for the payroll and HR team. A manager role for people leaders. A basic employee role for self-service. Add specialized roles only when a real need shows up, and write down what each role is for. The goal is that anyone should be able to look at a person's role and know why they have the access they have.
The guiding principle is least privilege. Each person gets the minimum access required to do their job, and not one field more. It sounds strict, but it is really just tidy. A recruiter does not need to see bank account numbers. A department manager does not need to see pay for teams that are not theirs. A benefits coordinator may need deduction detail but not the ability to change tax setup.
Least privilege also protects your people from blame. When access is scoped tightly, a curious click cannot turn into a data incident, and an honest mistake has a smaller blast radius. Start every new role by asking what this person must touch to do the work, then grant that and stop. It is far easier to add a permission later than to notice, months on, that half the company can see the executive payroll.
Separation of duties means the person who can make a change is not the only person who can approve it. This is one of the most important controls in payroll, and it is the one auditors probe hardest. If a single account can add an employee, set their pay, approve the change, and release the payroll, you have a fraud risk and a single point of failure at the same time.
In practice, split the sensitive steps. One person enters a new hire or a pay change; another reviews and approves it before it takes effect. The person who sets up a bank account for direct deposit should not be the only set of eyes on the payroll that pays it. ADP Workforce Now supports approval workflows that route changes for a second review, and using them turns a trust-based process into a documented one. When an auditor asks how you prevent a single person from paying themselves a raise, you want a clear answer.

Three tiers of access cover most of what a company needs, and keeping them distinct is half the battle.
The employee tier is self-service. Through their own login, employees see and manage their own information: pay statements, tax withholding elections, direct deposit, personal contact details, and benefits during enrollment. They see their own record and no one else's. This tier should be the default for the vast majority of your workforce.
The manager tier adds a view into a defined team. A people leader can see and often approve items for their direct reports, such as time, time off, and some personnel changes. The important word is defined. A manager's access should be scoped to their own team, not the whole company. When managers can see pay or personal data for people who do not report to them, you have a leak waiting to be noticed.
The practitioner tier is your payroll and HR professionals. They reach across the organization to run pay, manage deductions and taxes, and maintain records. Because this tier is powerful, it deserves the most care. Keep the number of practitioners small, split their sensitive duties as described above, and never treat practitioner access as a convenience to hand out because someone asked.
The most common gap we find is not a clever attack. It is an account that should have been switched off and never was. When someone leaves the company or changes roles, their access needs to change the same day, not at the next review.
Make offboarding a checklist item that sits right next to the final paycheck. When a practitioner or manager departs, deactivate their access as part of the termination process, and reassign anything they owned so work does not stall. When someone moves to a new role, do not simply add the new permissions on top of the old ones. Reset to the role that matches the new job. Layering access across role changes is how people quietly end up able to see everything. Tie the access change to the same trigger that ends their pay, and the gap closes on its own.
Access drifts. The only way to keep it honest is to look at it on a schedule. A periodic access review is a simple, repeatable check: pull the list of who has which role, and confirm each one still makes sense.
Do it at least twice a year, and after any reorganization. Ask three questions of every account with elevated access. Does this person still work here in this role? Do they still need this level of access? Is anyone carrying practitioner or admin rights who should not? Bring the manager of each team into the review so the people who know the work confirm the access. Document what you checked and what you changed. That record is gold when an auditor asks how you govern access, and it is the difference between hoping your setup is clean and knowing it is.
Pay special attention to the accounts that never seem to change. A practitioner who has been in the seat for years often accumulates permissions from old projects and temporary fill-ins that nobody ever pulled back. Long-tenured accounts are exactly where quiet over-access hides, precisely because no one questions them. Treat every elevated login the same in a review, regardless of how long the person has been there, and you close the gap that trust tends to leave open.
A client asked us to look at their ADP Workforce Now security after a near miss, where a departing employee still had a live login a month after leaving. We pulled the full list of roles and access. Out of about 300 employees, roughly 40 had manager access and about 15 had practitioner or admin rights. For a company that size, the practitioner count was far too high.
Digging in, we found that several managers could see pay data for teams outside their own, and four former employees still had active elevated access. We rebuilt the model around three clear tiers, scoped every manager to their own team, and cut practitioner access from about 15 down to 6 people whose jobs actually required it. We split the sensitive duties so no single account could both enter and approve a pay change, and we set a twice-yearly review on the calendar. The numbers here are rounded for illustration, but the shape is typical: most over-access is not malicious, it is just old, and it clears up fast once someone looks.
"Who can see Social Security numbers in ADP Workforce Now?" Only the roles you allow. Sensitive fields like Social Security numbers and bank details are controlled by role permissions, so the real question is which roles have that access and whether each holder truly needs it. In most companies, the answer should be a short list of practitioners, not managers and not the general workforce.
"Can a manager approve their own pay change?" They should not be able to, and a good setup prevents it. Separation of duties and approval workflows are built to stop a single person from both making and approving a sensitive change. If your current configuration allows self-approval anywhere, that is worth fixing before your next audit, not after.
"How often should we review access?" At least twice a year, and always after a reorganization or a round of departures. Reviews catch the drift that builds up between them: the leftover logins, the layered permissions, the manager who kept access after moving teams. A short review on a schedule beats a long cleanup after an incident.

A healthy setup is boring in the best way. Roles are few and clearly named. Almost everyone is an employee with self-service access to their own record. Managers see only their own teams. Practitioner access is a short, deliberate list. Sensitive duties are split so no one person controls a payroll change end to end. Offboarding switches off access the same day someone leaves. And a review runs on the calendar, documented, so the picture stays clean between check-ins.
You do not get there with one heroic project and then forget it. You get there by setting the model once, tying access changes to the events that should trigger them, and looking at the whole thing a couple of times a year. Done that way, security stops being a worry you carry and becomes a system you trust.
We are former ADP service professionals, and we work with ADP exclusively. We have configured these roles from the inside, so we know where access hides and how to tighten it without breaking anyone's workflow. When you want a straight answer about who can see what, you do not open a ticket and wait on hold. You get a dedicated consultant who knows ADP Workforce Now and will map your access, fix the gaps, and set up a review you can actually keep. No tickets, no hold queues. We've got you.
Not sure who can see your payroll data right now? REQUEST A CONSULTATION (ignitehcm.com/solutions/optimization).
ADP and the ADP logo are registered trademarks of ADP, Inc. This article is general guidance only. Data-security and access-control requirements vary by industry and jurisdiction and change over time; confirm your specific obligations with your licensed advisor or ADP representative.