Users, Roles & Permissions
User and role management determines who can access the CRM, what data they can view, and which actions they are authorized to perform. This guide covers account administration, hierarchical data access, role configuration, and best practices for team organization.
User Management
Adding Users
Create user accounts to grant team members access to the platform.
- Navigate to Settings → Users.
- Click + Add User.
- Complete the required fields:
| Field | Description |
|---|---|
| Name | Full name displayed across the platform |
| Login credential and notification address | |
| Phone | Contact number for telephony integration |
| Job Title | Organizational title for reference |
| Department | Functional group assignment |
- Select one or more roles to define the user's permissions.
- Assign a reporting manager to establish hierarchy-based data access.
- Click Create User to finalize.
The user receives a welcome email containing login credentials and onboarding instructions.
INFO
User accounts count toward your subscription's active seat limit. Deactivated users do not consume active seats.
User Hierarchy
The organizational hierarchy governs data visibility throughout the platform. Each user's position in the reporting chain determines which records they can access.
| Position | Data Visibility |
|---|---|
| Executive / Admin | All records across the organization |
| Manager | Own records plus all records owned by direct and indirect reports |
| Individual Contributor | Own assigned records only |
TIP
The hierarchy is determined by the "Reports To" field on each user profile. Ensure every user has a correctly assigned manager to prevent unintended data access gaps.
Hierarchy-based access applies to the following entities: Leads, Deals, Contacts, Accounts, and Activities.
Default Roles
The platform includes five pre-configured roles covering common organizational structures.
| Role | Description | Typical Use Case |
|---|---|---|
| Super Admin | Unrestricted platform access including billing, subscription management, and system configuration | Organization owner or IT administrator |
| Admin | Full access to all CRM features and settings; excludes billing management | Operations manager or CRM administrator |
| Manager | Team oversight with access to team data, reporting capabilities, and limited settings access | Sales manager or team lead |
| Sales Rep | Full management of own leads, deals, contacts, and activities | Field sales or inside sales representative |
| Viewer | Read-only access to assigned and shared records; no create, edit, or delete permissions | Stakeholders requiring visibility without modification rights |
WARNING
The Super Admin and Admin roles cannot be deleted or have their core permissions reduced. They serve as system-level access guarantees.
Creating Custom Roles
Define roles tailored to specific job functions or departmental requirements.
- Navigate to Settings → Roles.
- Click + Create Role.
- Enter a descriptive role name (e.g., "Marketing Coordinator," "Support Agent," "Finance Reviewer").
- Configure permissions for each module:
| Module | Available Permissions |
|---|---|
| Leads | View, Create, Edit, Delete, Import, Export, Convert |
| Contacts | View, Create, Edit, Delete |
| Deals | View, Create, Edit, Delete, Change Stage |
| Invoices | View, Create, Edit, Delete, Send |
| View Conversations, Send Messages, Manage Templates | |
| Reports | View, Export, Create Custom |
| Settings | View, Edit |
| Users | View, Create, Edit, Deactivate |
- Optionally configure field-level visibility to hide sensitive fields from this role.
- Click Save to activate the role.
INFO
Custom roles can be duplicated to accelerate the creation of similar permission sets. Use the Duplicate action from the role list to create a copy for modification.
Assigning Roles
Roles are assigned during user creation or through subsequent profile edits.
- Navigate to Settings → Users.
- Select the target user from the list.
- In the Roles section, add or remove role assignments.
- Click Save Changes to apply.
Role changes take effect immediately upon save. The user's sidebar navigation and available actions update on their next page load.
Multiple Roles
Users may be assigned more than one role. When multiple roles are applied, the following rules govern effective permissions:
| Rule | Behavior |
|---|---|
| Additive Permissions | If any assigned role grants a permission, the user possesses that permission |
| No Subtractive Override | A restrictive role cannot revoke a permission granted by another role |
| Admin Precedence | The Admin or Super Admin role, if assigned, supersedes all other role restrictions |
TIP
Use multiple roles to compose permissions for cross-functional team members. For example, assign both "Sales Rep" and "Marketing Viewer" to a user who needs lead management capabilities plus read access to campaign data.
Record Ownership
Every record (Lead, Deal, Contact, Account) has a designated Owner field that determines primary responsibility and access rights.
How Ownership Affects Visibility
| Scenario | Access Level |
|---|---|
| Record Owner | Full access (view, edit, delete) regardless of role restrictions |
| Owner's Manager | View and edit access through hierarchy |
| Owner's Manager's Manager | View and edit access through hierarchy (cascading upward) |
| Unrelated User (same role) | No access unless explicitly shared or Admin |
| Admin / Super Admin | Full access to all records regardless of ownership |
WARNING
Records without an assigned owner are visible only to Admin and Super Admin users. Ensure all records have an active owner to prevent data from becoming inaccessible to the responsible team.
Transferring Ownership
Reassign record ownership when team members change responsibilities, leave the organization, or when workload rebalancing is required.
Individual Transfer
- Open the target record.
- Click the Owner field.
- Select the new owner from the user list.
- Confirm the transfer.
Bulk Transfer
- Navigate to the relevant list view (Leads, Deals, Contacts, or Accounts).
- Select multiple records using the checkbox column.
- Click Actions → Transfer Ownership.
- Choose the destination user.
- Confirm the bulk operation.
INFO
Ownership transfer updates the hierarchy-based visibility immediately. The previous owner loses access unless they are in the new owner's management chain or hold an Admin role.
Team Setup Best Practices
Follow these guidelines when configuring your team structure for optimal data governance and operational efficiency.
Begin with default roles. Use the built-in Admin, Manager, and Sales Rep roles as your starting foundation. Create custom roles only when default roles do not adequately represent a job function.
Establish the reporting hierarchy. Assign a manager to every user account. This ensures data visibility flows correctly through the organizational chain and prevents orphaned access.
Group representatives under managers. Structure teams so that each manager oversees a logical group of contributors. This enables accurate team-level reporting and forecasting.
Configure lead assignment rules. Define round-robin distribution or manual assignment workflows to ensure equitable and timely lead allocation.
Apply the principle of least privilege. Grant only the permissions required for each role's function. Avoid assigning Admin access broadly.
Validate access as a non-admin user. Log in with a representative user account to verify that sidebar visibility, record access, and action buttons reflect the intended permission set.
Review roles quarterly. As team structures evolve, audit role assignments and hierarchy configurations to ensure continued alignment with organizational changes.
Related:
Next Step: Lead Management
