Access roles and permissions
Understand the roles, the access scope, read-only mode and how to create/clone roles.
Each user has a role that defines the access SCOPE. Within your scope, access is total (create, view, edit and delete), except when the role is read-only. The first user of the tenant is always Administrator.
Standard roles
- Administrator: full access + general system settings.
- Sales Manager: full access to all sales data, but without the general settings.
- Sales Coordinator: full access to the data of their team.
- Account Manager: full access only to their own records (the ones they own).
- Marketing: access to the marketing/leads data.
- Audit: read-only; can view but not create, edit or delete.
Visibility scope
The scope controls WHICH records the role accesses, from the most restricted to the broadest:
- Own: only the records where the user is the owner.
- Peers: the records of any colleague from the user's teams (a horizontal view among peers).
- Team: for LEADERS, it covers the team and the subteams below it (a hierarchical view). Anyone who is not a leader with "team" scope sees only their own.
- Territory: covers the records of everyone in your territory AND in the descendant territories (territory hierarchy). Ideal for a regional manager who covers subregions. Anyone not in any territory who is granted "territory" sees only their own.
- All: everything in the organization (tenant).
The scope is defined per RESOURCE: the same role can, for example, see "all" Contacts but only its "own" deals. The lists come already filtered according to your scope on each resource, so you never see (not even in the totals) what is outside it. This is enforced at the data layer and cannot be bypassed through the interface.
Access per object
Beyond the scope, you can define, per role, which OBJECTS it sees and edits. In Settings, under Roles and permissions, open "Access by object" and check View/Edit for each object.
Feature resources (menus and screens)
Beyond objects, the permission matrix includes feature RESOURCES that control the visibility of dedicated screens: Social, App marketplace, Gamification (ranking), Telephony, Kiosk, Canvas and layouts, Activity types, Blueprints (processes), Journeys and Integrations, among others. By default these menus stay visible to every role; to hide them for a role, remove "View" (read) access on the matching resource in the matrix.
Create and clone roles
- Go to Settings, under Roles and permissions.
- Click "New role" (define name, scope, read-only and access to settings) or "Clone" on an existing role.
- Adjust the "Access by object" of the new role.
- Assign the role to users in Settings → Users.