Roles (Funktionsstufen)
A catalog of role classifications: a code, a name, a description of the scope and responsibility the level represents. Roles can be scoped to a legal entity where different Rechtsträger genuinely classify differently. Codes are unique, and a role in use by an assignment cannot be deleted — the history has to stay resolvable.Salary bands
A band attaches a pay range to a role. Two shapes are supported:
Bands are dated, so an annual revision creates a new version rather than rewriting
history. A payslip from two years ago still resolves against the band that applied
then.
Assignments
An assignment places an employee in a role, and in a step where the band uses steps, from a given date. Assignments are dated for the same reason employment periods are: a promotion is a new assignment, not an overwrite. Each assignment records the placement rationale — why this person sits at this point in the band. That is the sentence a manager needs when the question is asked, and the record that makes pay decisions reviewable.The employee self-view
Employees see their own compensation picture in the portal and the mobile app:- Their role and what it means.
- The band that applies to it.
- Where they sit within it, and the recorded rationale.
The self-view is strictly a self-view. It does not compare the person against colleagues, does not
show a percentile, and does not rank. Per ADR-006, the product
explains pay policy — it does not gamify it.
Salary visibility
Compensation policy is one thing; individual salary amounts are another and are closed by default.
Masking happens at the API layer. A masked field is masked in the response, not hidden
in the browser.
Administering grants is
ADMIN-only. Granting salary access is itself a
compensation-sensitive decision, so it does not sit with the people who use it.
Permissions
Bands and assignments are HR master data — unlike the legal-entity records, they do not
re-route statutory declarations — so HR staff manage them. Employees read their own
view through a session-scoped portal route that needs no role permission at all.