Skip to content

Roles & Permissions — Detailed Guide ​

Permission System Overview ​

ZenTraq uses a granular permission system with three layers:

  1. Role-Based — What actions a role can perform per module
  2. Field-Level — Which fields a role can see or edit
  3. Record-Level — Which records a user can access (hierarchy-based)

Module Permissions ​

Permission Matrix ​

Each module has these permission types:

PermissionWhat it Allows
ViewSee records in list and detail views
CreateAdd new records
EditModify existing records
DeleteRemove records
ImportBulk import from CSV
ExportDownload data as CSV/Excel
ConvertConvert leads to contacts/deals
TransferReassign record ownership
Bulk OperationsMass update, mass delete, mass transfer

Module-Specific Permissions ​

Leads ​

  • crm.lead.record.view
  • crm.lead.record.create
  • crm.lead.record.edit
  • crm.lead.record.delete
  • crm.lead.record.import
  • crm.lead.record.export
  • crm.lead.record.convert
  • crm.lead.record.transfer

Contacts ​

  • crm.contact.record.view
  • crm.contact.record.create
  • crm.contact.record.edit
  • crm.contact.record.delete

Deals ​

  • crm.deal.record.view
  • crm.deal.record.create
  • crm.deal.record.edit
  • crm.deal.record.delete

Invoices ​

  • crm.invoice.record.view
  • crm.invoice.record.create
  • crm.invoice.record.edit
  • crm.invoice.record.delete
  • crm.invoice.record.send

Communication ​

  • communication.email.send
  • communication.whatsapp.message.send
  • communication.whatsapp.template.manage
  • crm.call.record.create

Settings ​

  • settings.organization.view
  • settings.organization.edit
  • settings.users.view
  • settings.users.create
  • settings.users.edit
  • settings.users.deactivate
  • settings.roles.manage
  • settings.pipelines.manage
  • settings.customfields.manage

Reports ​

  • analytics.report.view
  • analytics.report.export
  • analytics.report.create

Field-Level Security ​

What is Field-Level Security? ​

Control which fields specific roles can see or edit on a record. For example:

  • Sales reps can't see "Annual Revenue" on leads
  • Junior staff can't see "Commission %" on deals
  • Only admins can see "Cost Price" on products

Configuring Field Security ​

  1. Go to Settings → Roles → [Select a Role] → Field Security
  2. For each entity (Lead, Contact, Deal), choose per field:
    • Visible — User can see the field
    • Editable — User can modify the field
    • Hidden — Field is completely invisible to this role

Common Field Security Rules ​

RoleHidden Fields
Sales RepAnnual Revenue, Cost Price, Commission %, Internal Notes
ViewerAll edit actions, Pricing fields
ManagerNone (sees everything except admin settings)
Partner/ExternalInternal scores, team notes, pricing margins

Secure Field Display ​

When a field is hidden for a user:

  • It doesn't appear on the form
  • It's excluded from list view columns
  • It's not included in exports
  • API responses also exclude it

Record-Level Security (Hierarchy) ​

How Hierarchy Works ​

CEO / Admin → Sees ALL records
  └── Regional Manager → Sees own + their team's records
        └── Team Lead → Sees own + direct reports' records
              └── Sales Rep → Sees only their OWN records

Configuring Hierarchy ​

  1. Settings → Users → Edit User
  2. Set the Manager field (reports to)
  3. This creates the hierarchy chain

Data Visibility Rules ​

User LevelLeads VisibleDeals Visible
AdminAllAll
ManagerOwn + subordinates'Own + subordinates'
Team LeadOwn + direct reports'Own + direct reports'
RepOnly own assignedOnly own assigned

Hierarchy in Practice ​

  • Lead List: Rep sees 25 leads (their own). Manager sees 150 (whole team's)
  • Dashboard: Shows metrics for visible records only
  • Reports: Scoped to the user's accessible data
  • Filters: "My Leads" vs "All Leads" (based on access level)

Creating a Custom Role ​

Step by Step ​

  1. Go to Settings → Roles
  2. Click + Create Role
  3. Enter role name (e.g., "Senior Sales Rep")
  4. Set module permissions (check/uncheck per action):
✅ Leads: View, Create, Edit, Convert
❌ Leads: Delete, Import, Export
✅ Deals: View, Create, Edit
❌ Deals: Delete
✅ Communication: Email Send, WhatsApp Send
❌ Settings: All
✅ Reports: View
❌ Reports: Export, Create
  1. Set field-level security per module
  2. Save the role

Assigning to Users ​

  1. Go to Settings → Users → Edit User
  2. Select the role(s) for this user
  3. Permissions take effect immediately

Multiple Roles ​

Users can have multiple roles. Permissions are additive:

  • If Role A allows "Lead View" and Role B allows "Lead Delete"
  • User gets both: View + Delete

Default Roles Explained ​

Super Admin ​

  • Full unrestricted access
  • Can manage billing and subscription
  • Cannot be deleted or restricted
  • Only one per organization (the registrant)

Admin ​

  • Full access to all CRM features
  • Can manage users, roles, settings
  • Cannot manage billing (only Super Admin)
  • Multiple admins possible

Manager ​

  • View and manage team's records
  • Run reports for their team
  • Cannot change settings or manage users
  • Can approve submissions

Sales Rep ​

  • Create and manage own leads/deals/contacts
  • Log activities and communication
  • Cannot see other reps' data
  • Cannot access settings or admin functions

Viewer (Read-Only) ​

  • Can view assigned records
  • Cannot create, edit, or delete anything
  • Used for executives who need visibility without editing
  • Cannot send communications

Permission Inheritance ​

How it flows: ​

Organization Level (Admin sets defaults)
  └── Role Level (permissions per module)
        └── User Level (role assigned + manager set)
              └── Record Level (ownership + hierarchy)

Audit & Compliance ​

Who changed permissions? ​

All role and permission changes are logged:

  • Settings → Activity Logs → filter by "Permission Changes"
  • Shows: who, what role, what was changed, when

Regular Review ​

Best practice: Review permissions quarterly

  • Remove unnecessary access
  • Check for departed employees' access
  • Verify hierarchy is up-to-date
  • Ensure no permission creep (accumulating too many permissions over time)

Tips ​

  • Principle of Least Privilege — Give only what's needed
  • Test as the role — Log in as a user with that role to verify
  • Use hierarchy carefully — One wrong manager assignment exposes data
  • Document your roles — Write down what each role is for
  • Don't create too many roles — 4-6 roles is usually enough
  • Review on employee changes — New role? Transfer? Departure? Update immediately

ZenTraq CRM — Built for every industry.