Access and permissions
Which permission each CRM screen needs, who may see and change what, and the rules that keep people from approving their own work.
On this page (18)
Permissions by screen
| Screen | Menu | Permission needed |
|---|---|---|
| CRM dashboard | CRM > Dashboard | dashboard.crm (and team scope on the data) |
| Leads | CRM > Leads > Leads | crm.view (list), crm.manage (create, change, delete) |
| Import leads | CRM > Leads > Import leads | crm.manage (menu); list needs crm.view; switch 'Lead imports' |
| Duplicate review | CRM > Leads > Duplicate review | crm.view (list), crm.manage (resolve); switch 'Duplicate review' |
| Assignment queue | CRM > Leads > Assignment queue | crm.view (list), crm.manage (run); only deals you may see; only teams you manage are placed |
| Campaign responses | CRM > Leads > Campaign responses | crm.view (list), crm.manage (hand off); switch 'Campaigns and responses' |
| My agenda | CRM > My agenda | crm.view |
| Communications | CRM > Communications | crm.view; the Not matched list only for crm.configure holders and admins |
| Opportunities | CRM > Opportunities | crm.view (read), crm.manage (change); team scope |
| Activities | CRM > Activities | crm.view (read), crm.manage (change) |
| Lead / opportunity record | CRM > Leads / Opportunities > open a record | crm.view (read), crm.manage (write); owner / team manager / cover rule |
| Pipeline by stage | CRM > Reporting > Pipeline by stage | crm.view |
| Monthly forecast | CRM > Reporting > Monthly forecast | crm.view |
| Loss analysis | CRM > Reporting > Loss analysis | crm.view |
| Forecast | CRM > Reporting > Forecast | crm.view (read), crm.manage (submit, adjust); switch 'Forecast and quotas' |
| CRM analytics | CRM > Reporting > CRM analytics | crm.view; team scope |
| Account plans progress | CRM > Reporting > Account plans | crm.view |
| Pipeline stages | CRM > Configuration > Pipeline stages | UI: company admin; server route crm.manage |
| Sales teams | CRM > Configuration > Sales teams | UI: company admin; server route crm.manage |
| Lead sources | CRM > Configuration > Lead sources | UI: company admin; server route crm.manage |
| Tags | CRM > Configuration > Tags | UI: company admin; server route crm.manage |
| Pipelines | CRM > Configuration > Pipelines | crm.configure (write), crm.view (read) |
| Loss and disqualification reasons | CRM > Configuration > Loss reasons | crm.configure |
| Lead mediums | CRM > Configuration > Lead mediums | crm.configure |
| Campaigns | CRM > Configuration > Campaigns | crm.configure; switch 'Campaigns and responses' |
| Qualification criteria | CRM > Configuration > Qualification criteria | crm.configure |
| Lead scoring | CRM > Configuration > Lead scoring | crm.configure; switch 'Lead scoring' |
| Territories | CRM > Configuration > Territories | crm.configure |
| Assignment rules | CRM > Configuration > Assignment rules | crm.configure |
| Coverage delegations | CRM > Configuration > Coverage delegations | crm.configure |
| Activity types | CRM > Configuration > Activity types | crm.configure |
| Task sequences | CRM > Configuration > Task sequences | crm.configure |
| Competitors | CRM > Configuration > Competitors | crm.configure |
| Quotas | CRM > Configuration > Quotas | crm.configure; switch 'Forecast and quotas' |
| Account plans | CRM > Configuration > Account plans | crm.configure |
| Territory access | CRM > Configuration > Territory access | crm.configure |
| Connectors | CRM > Configuration > Connectors | crm.configure |
| CRM feature switches | Applications > CRM > Features (and Home > Fields) | company.manage (Administration > Workspace > Apps) |
Leads
| Rule | What the system does |
|---|---|
| Read needs crm.view | Menu absent / 403 'You do not have permission for this action.'; no lead data returned. |
| Team scope: a rep sees only their teams' deals | Only North's deals / activities / figures appear in every screen and in Export; a team's deals are not mixed into totals. |
| Export respects scope and field security | File has only A's deals; after hiding, the budget column is absent from list, record, export and the field is ignored if sent on save. |
Lead / opportunity record
| Rule | What the system does |
|---|---|
| Create and edit need crm.manage | Create / edit refused with 403 (route policy crm.manage); the form shows no Edit button; the record is read-only. |
| Delete needs crm.manage and the right to change that record | 'Only the owner or a team manager can change this CRM record.' (403); nothing deleted. |
| A deal of another team cannot be opened by reference or id | 'Record not found.' (404) - the same answer as for a number that does not exist, so its existence is not disclosed. |
| Read only team members cannot change | R reads but every change is refused; R cannot be chosen as owner ('The owner must be a representative or manager in this team.'). |
| Only the owner, a team manager, an admin or covering colleague changes a deal | A: 'Only the owner or a team manager can change this CRM record.'; M succeeds. A covering colleague (valid delegation) also succeeds on the cover dates. |
| A non-admin cannot make an unassigned (no team) record | Refused (the team rule cannot be satisfied: 'Only the owner or a team manager can change this CRM record.'); the screen labels blank as 'Unassigned - administrators only'. |
| Company isolation | 'Record not found.'; no data of the other company; masters, stages and teams are also per company ('Record not found.' when posting another company's team or stage id). |
| Field access restrictions apply to the deal everywhere | The record, list, board, export and API answers hide / mask the fields; a write of a restricted field is refused or ignored consistently. |
| Stage list and other lookups come from the user's company only | Only this company's active stages, members and teams (non-admin: only their own teams) are offered. |
| Only a manager reopens a closed record | 'Only a team manager can reopen a closed record.' (403). |
| Create a new customer from a lead is administrator-only | 'Administrator access required.' (403); linking an existing customer is allowed. |
| Request-key replay safety | 'This request key was already used with different details.' (create), 409 'This quotation request key was already used with different details.' (quotation); the same key and details return the first answer. |
| Every important act is audited | Audit trail (Administration > Audit) shows crm.created / qualified / won / reopened / assigned / deleted / configuration / quota.approved / connector.* with the actor, number and the changed fields; deletion keeps number and title. |
| Closing your own task does not need edit rights, nothing else does | Done succeeds; editing or cancelling by someone with no deal rights is refused. |
| Consent: an absent register is not a yes | Refused ('No consent register is installed, so purpose-bound contact is not allowed.'); opt-out in the register blocks each following attempt. |
| Only open records change | Each is refused ('Reopen and unarchive the record before ...'; 'Reopen and unarchive the record before reassigning it.'). |
| Deletion cannot become a data-loss shortcut | Refused with the 'Archive it instead' messages; one request per record so each deletion is authorised and audited alone. |
| Territory and duplicate matches are never taken across companies | No duplicate candidate, territory or customer match crosses companies. |
CRM dashboard
| Rule | What the system does |
|---|---|
| Dashboard needs dashboard.crm | Dashboard menu entry gone and its API answers 403; Leads / Opportunities still open. |
Configuration
| Rule | What the system does |
|---|---|
| Masters need crm.configure to change | Configuration entries with crm.configure are hidden; a direct POST gives 403 'You do not have permission for this action.'; Sales manager (has crm.configure) can. |
Import leads
| Rule | What the system does |
|---|---|
| Import needs crm.manage | 403; no leads created. A user with crm.manage can import; the imported leads belong to the importer. |
| Upload hardening | Over 10 MB: 'Import files may be at most 10 MB.'; non-text files give 'No known columns...' or 'The file is empty.'; values are stored as text only (never executed); rows over 5,000 refused. |
Ownership tab
| Rule | What the system does |
|---|---|
| Only a manager of the team (or admin) reassigns | Rep: 'Only a manager of the team (or an administrator) can reassign this record.'; manager works inside their team; moving into another team needs manager rights there too. |
Forecast
| Rule | What the system does |
|---|---|
| Maker-checker on forecast adjustments | 'A manager other than the person who submitted it adjusts a forecast.' / 'Record not found.' (not visible) or 'Only a manager of the team (or an administrator) adjusts this forecast.' |
| Visibility of submissions | A sees only own; North's manager sees own and North's; admin sees all; an unrelated rep sees none of them. |
Quotas
| Rule | What the system does |
|---|---|
| Maker-checker on quota approval | X: 'Somebody other than the person who set the quota approves it.'; Y approves; approve needs crm.configure. |
Connectors
| Rule | What the system does |
|---|---|
| Hook key authentication | Wrong or off: 401 'Unknown or switched-off connector.' with no data written; right key logs the event. The key is stored only as a SHA-256 and shown once on creation or rotation. |
| Connector management needs crm.configure | 403; the menu entry is hidden. Authorisation (who and when) is recorded and audited as 'crm.connector.authorized' / on / off / rotated. |
| Webhook is an unauthenticated route by design | Works only with a valid key; no company data is returned beyond status, id and deal id; wrong keys all answer the same 401. |
Communications
| Rule | What the system does |
|---|---|
| Unmatched communications only for configurers | Rep sees an empty list; configurer / admin sees the unmatched events. Logged communications are only those on deals the user may see. |
Duplicate review
| Rule | What the system does |
|---|---|
| No cross-team hints | A sees the candidate but the other side reads 'Another team's record' - no number or title leaks; only candidates of deals A may see are listed. |
Territory access
| Rule | What the system does |
|---|---|
| Territory-limited people see only their territories | Every path answers only Dubai (and child) deals; others 'Record not found.'; creating outside gives 'This record falls outside the territories you work.' |
| Changing territory access takes effect at once | T's visibility changes on the next request (permission version bumped), without signing out. |
Sales teams
| Rule | What the system does |
|---|---|
| Removing a member removes access at once | A loses North's deals immediately (permission version bumped); switching a team off has the same effect. |
Coverage delegations
| Rule | What the system does |
|---|---|
| Cover is limited by team, person and date | Allowed only on North deals within the dates; refused otherwise; the covered person's own rights are unchanged. |
Campaign responses
| Rule | What the system does |
|---|---|
| A response is never consent | No consent rows are written by CRM; the response row shows consent 'not implied'; marketing contact stays refused until consent is recorded with evidence. |
Timeline & consent
| Rule | What the system does |
|---|---|
| Merging needs write access to both records | 'Only the owner or a team manager can change this CRM record.' / 'Record not found.'; the survivor and the source are unchanged. |
CRM feature switches
| Rule | What the system does |
|---|---|
| A switched-off feature refuses changes but stays readable | Changes refused with capability_disabled, menus hidden, history stays readable (reads pass); reads of masters still work. |