Roles & Permissions — Detailed Guide
Permission System Overview
ZenTraq uses a granular permission system with three layers:
- Role-Based — What actions a role can perform per module
- Field-Level — Which fields a role can see or edit
- Record-Level — Which records a user can access (hierarchy-based)
Module Permissions
Permission Matrix
Each module has these permission types:
| Permission | What it Allows |
|---|---|
| View | See records in list and detail views |
| Create | Add new records |
| Edit | Modify existing records |
| Delete | Remove records |
| Import | Bulk import from CSV |
| Export | Download data as CSV/Excel |
| Convert | Convert leads to contacts/deals |
| Transfer | Reassign record ownership |
| Bulk Operations | Mass update, mass delete, mass transfer |
Module-Specific Permissions
Leads
crm.lead.record.viewcrm.lead.record.createcrm.lead.record.editcrm.lead.record.deletecrm.lead.record.importcrm.lead.record.exportcrm.lead.record.convertcrm.lead.record.transfer
Contacts
crm.contact.record.viewcrm.contact.record.createcrm.contact.record.editcrm.contact.record.delete
Deals
crm.deal.record.viewcrm.deal.record.createcrm.deal.record.editcrm.deal.record.delete
Invoices
crm.invoice.record.viewcrm.invoice.record.createcrm.invoice.record.editcrm.invoice.record.deletecrm.invoice.record.send
Communication
communication.email.sendcommunication.whatsapp.message.sendcommunication.whatsapp.template.managecrm.call.record.create
Settings
settings.organization.viewsettings.organization.editsettings.users.viewsettings.users.createsettings.users.editsettings.users.deactivatesettings.roles.managesettings.pipelines.managesettings.customfields.manage
Reports
analytics.report.viewanalytics.report.exportanalytics.report.create
Field-Level Security
What is Field-Level Security?
Control which fields specific roles can see or edit on a record. For example:
- Sales reps can't see "Annual Revenue" on leads
- Junior staff can't see "Commission %" on deals
- Only admins can see "Cost Price" on products
Configuring Field Security
- Go to Settings → Roles → [Select a Role] → Field Security
- For each entity (Lead, Contact, Deal), choose per field:
- Visible — User can see the field
- Editable — User can modify the field
- Hidden — Field is completely invisible to this role
Common Field Security Rules
| Role | Hidden Fields |
|---|---|
| Sales Rep | Annual Revenue, Cost Price, Commission %, Internal Notes |
| Viewer | All edit actions, Pricing fields |
| Manager | None (sees everything except admin settings) |
| Partner/External | Internal scores, team notes, pricing margins |
Secure Field Display
When a field is hidden for a user:
- It doesn't appear on the form
- It's excluded from list view columns
- It's not included in exports
- API responses also exclude it
Record-Level Security (Hierarchy)
How Hierarchy Works
CEO / Admin → Sees ALL records
└── Regional Manager → Sees own + their team's records
└── Team Lead → Sees own + direct reports' records
└── Sales Rep → Sees only their OWN recordsConfiguring Hierarchy
- Settings → Users → Edit User
- Set the Manager field (reports to)
- This creates the hierarchy chain
Data Visibility Rules
| User Level | Leads Visible | Deals Visible |
|---|---|---|
| Admin | All | All |
| Manager | Own + subordinates' | Own + subordinates' |
| Team Lead | Own + direct reports' | Own + direct reports' |
| Rep | Only own assigned | Only own assigned |
Hierarchy in Practice
- Lead List: Rep sees 25 leads (their own). Manager sees 150 (whole team's)
- Dashboard: Shows metrics for visible records only
- Reports: Scoped to the user's accessible data
- Filters: "My Leads" vs "All Leads" (based on access level)
Creating a Custom Role
Step by Step
- Go to Settings → Roles
- Click + Create Role
- Enter role name (e.g., "Senior Sales Rep")
- Set module permissions (check/uncheck per action):
✅ Leads: View, Create, Edit, Convert
❌ Leads: Delete, Import, Export
✅ Deals: View, Create, Edit
❌ Deals: Delete
✅ Communication: Email Send, WhatsApp Send
❌ Settings: All
✅ Reports: View
❌ Reports: Export, Create- Set field-level security per module
- Save the role
Assigning to Users
- Go to Settings → Users → Edit User
- Select the role(s) for this user
- Permissions take effect immediately
Multiple Roles
Users can have multiple roles. Permissions are additive:
- If Role A allows "Lead View" and Role B allows "Lead Delete"
- User gets both: View + Delete
Default Roles Explained
Super Admin
- Full unrestricted access
- Can manage billing and subscription
- Cannot be deleted or restricted
- Only one per organization (the registrant)
Admin
- Full access to all CRM features
- Can manage users, roles, settings
- Cannot manage billing (only Super Admin)
- Multiple admins possible
Manager
- View and manage team's records
- Run reports for their team
- Cannot change settings or manage users
- Can approve submissions
Sales Rep
- Create and manage own leads/deals/contacts
- Log activities and communication
- Cannot see other reps' data
- Cannot access settings or admin functions
Viewer (Read-Only)
- Can view assigned records
- Cannot create, edit, or delete anything
- Used for executives who need visibility without editing
- Cannot send communications
Permission Inheritance
How it flows:
Organization Level (Admin sets defaults)
└── Role Level (permissions per module)
└── User Level (role assigned + manager set)
└── Record Level (ownership + hierarchy)Audit & Compliance
Who changed permissions?
All role and permission changes are logged:
- Settings → Activity Logs → filter by "Permission Changes"
- Shows: who, what role, what was changed, when
Regular Review
Best practice: Review permissions quarterly
- Remove unnecessary access
- Check for departed employees' access
- Verify hierarchy is up-to-date
- Ensure no permission creep (accumulating too many permissions over time)
Tips
- Principle of Least Privilege — Give only what's needed
- Test as the role — Log in as a user with that role to verify
- Use hierarchy carefully — One wrong manager assignment exposes data
- Document your roles — Write down what each role is for
- Don't create too many roles — 4-6 roles is usually enough
- Review on employee changes — New role? Transfer? Departure? Update immediately
