Access and permissions

Which permission each CRM screen needs, who may see and change what, and the rules that keep people from approving their own work.

On this page (18)

Permissions by screen

ScreenMenuPermission needed
CRM dashboardCRM > Dashboarddashboard.crm (and team scope on the data)
LeadsCRM > Leads > Leadscrm.view (list), crm.manage (create, change, delete)
Import leadsCRM > Leads > Import leadscrm.manage (menu); list needs crm.view; switch 'Lead imports'
Duplicate reviewCRM > Leads > Duplicate reviewcrm.view (list), crm.manage (resolve); switch 'Duplicate review'
Assignment queueCRM > Leads > Assignment queuecrm.view (list), crm.manage (run); only deals you may see; only teams you manage are placed
Campaign responsesCRM > Leads > Campaign responsescrm.view (list), crm.manage (hand off); switch 'Campaigns and responses'
My agendaCRM > My agendacrm.view
CommunicationsCRM > Communicationscrm.view; the Not matched list only for crm.configure holders and admins
OpportunitiesCRM > Opportunitiescrm.view (read), crm.manage (change); team scope
ActivitiesCRM > Activitiescrm.view (read), crm.manage (change)
Lead / opportunity recordCRM > Leads / Opportunities > open a recordcrm.view (read), crm.manage (write); owner / team manager / cover rule
Pipeline by stageCRM > Reporting > Pipeline by stagecrm.view
Monthly forecastCRM > Reporting > Monthly forecastcrm.view
Loss analysisCRM > Reporting > Loss analysiscrm.view
ForecastCRM > Reporting > Forecastcrm.view (read), crm.manage (submit, adjust); switch 'Forecast and quotas'
CRM analyticsCRM > Reporting > CRM analyticscrm.view; team scope
Account plans progressCRM > Reporting > Account planscrm.view
Pipeline stagesCRM > Configuration > Pipeline stagesUI: company admin; server route crm.manage
Sales teamsCRM > Configuration > Sales teamsUI: company admin; server route crm.manage
Lead sourcesCRM > Configuration > Lead sourcesUI: company admin; server route crm.manage
TagsCRM > Configuration > TagsUI: company admin; server route crm.manage
PipelinesCRM > Configuration > Pipelinescrm.configure (write), crm.view (read)
Loss and disqualification reasonsCRM > Configuration > Loss reasonscrm.configure
Lead mediumsCRM > Configuration > Lead mediumscrm.configure
CampaignsCRM > Configuration > Campaignscrm.configure; switch 'Campaigns and responses'
Qualification criteriaCRM > Configuration > Qualification criteriacrm.configure
Lead scoringCRM > Configuration > Lead scoringcrm.configure; switch 'Lead scoring'
TerritoriesCRM > Configuration > Territoriescrm.configure
Assignment rulesCRM > Configuration > Assignment rulescrm.configure
Coverage delegationsCRM > Configuration > Coverage delegationscrm.configure
Activity typesCRM > Configuration > Activity typescrm.configure
Task sequencesCRM > Configuration > Task sequencescrm.configure
CompetitorsCRM > Configuration > Competitorscrm.configure
QuotasCRM > Configuration > Quotascrm.configure; switch 'Forecast and quotas'
Account plansCRM > Configuration > Account planscrm.configure
Territory accessCRM > Configuration > Territory accesscrm.configure
ConnectorsCRM > Configuration > Connectorscrm.configure
CRM feature switchesApplications > CRM > Features (and Home > Fields)company.manage (Administration > Workspace > Apps)

Leads

RuleWhat the system does
Read needs crm.viewMenu absent / 403 'You do not have permission for this action.'; no lead data returned.
Team scope: a rep sees only their teams' dealsOnly North's deals / activities / figures appear in every screen and in Export; a team's deals are not mixed into totals.
Export respects scope and field securityFile has only A's deals; after hiding, the budget column is absent from list, record, export and the field is ignored if sent on save.

Lead / opportunity record

RuleWhat the system does
Create and edit need crm.manageCreate / edit refused with 403 (route policy crm.manage); the form shows no Edit button; the record is read-only.
Delete needs crm.manage and the right to change that record'Only the owner or a team manager can change this CRM record.' (403); nothing deleted.
A deal of another team cannot be opened by reference or id'Record not found.' (404) - the same answer as for a number that does not exist, so its existence is not disclosed.
Read only team members cannot changeR reads but every change is refused; R cannot be chosen as owner ('The owner must be a representative or manager in this team.').
Only the owner, a team manager, an admin or covering colleague changes a dealA: 'Only the owner or a team manager can change this CRM record.'; M succeeds. A covering colleague (valid delegation) also succeeds on the cover dates.
A non-admin cannot make an unassigned (no team) recordRefused (the team rule cannot be satisfied: 'Only the owner or a team manager can change this CRM record.'); the screen labels blank as 'Unassigned - administrators only'.
Company isolation'Record not found.'; no data of the other company; masters, stages and teams are also per company ('Record not found.' when posting another company's team or stage id).
Field access restrictions apply to the deal everywhereThe record, list, board, export and API answers hide / mask the fields; a write of a restricted field is refused or ignored consistently.
Stage list and other lookups come from the user's company onlyOnly this company's active stages, members and teams (non-admin: only their own teams) are offered.
Only a manager reopens a closed record'Only a team manager can reopen a closed record.' (403).
Create a new customer from a lead is administrator-only'Administrator access required.' (403); linking an existing customer is allowed.
Request-key replay safety'This request key was already used with different details.' (create), 409 'This quotation request key was already used with different details.' (quotation); the same key and details return the first answer.
Every important act is auditedAudit trail (Administration > Audit) shows crm.created / qualified / won / reopened / assigned / deleted / configuration / quota.approved / connector.* with the actor, number and the changed fields; deletion keeps number and title.
Closing your own task does not need edit rights, nothing else doesDone succeeds; editing or cancelling by someone with no deal rights is refused.
Consent: an absent register is not a yesRefused ('No consent register is installed, so purpose-bound contact is not allowed.'); opt-out in the register blocks each following attempt.
Only open records changeEach is refused ('Reopen and unarchive the record before ...'; 'Reopen and unarchive the record before reassigning it.').
Deletion cannot become a data-loss shortcutRefused with the 'Archive it instead' messages; one request per record so each deletion is authorised and audited alone.
Territory and duplicate matches are never taken across companiesNo duplicate candidate, territory or customer match crosses companies.

CRM dashboard

RuleWhat the system does
Dashboard needs dashboard.crmDashboard menu entry gone and its API answers 403; Leads / Opportunities still open.

Configuration

RuleWhat the system does
Masters need crm.configure to changeConfiguration entries with crm.configure are hidden; a direct POST gives 403 'You do not have permission for this action.'; Sales manager (has crm.configure) can.

Import leads

RuleWhat the system does
Import needs crm.manage403; no leads created. A user with crm.manage can import; the imported leads belong to the importer.
Upload hardeningOver 10 MB: 'Import files may be at most 10 MB.'; non-text files give 'No known columns...' or 'The file is empty.'; values are stored as text only (never executed); rows over 5,000 refused.

Ownership tab

RuleWhat the system does
Only a manager of the team (or admin) reassignsRep: 'Only a manager of the team (or an administrator) can reassign this record.'; manager works inside their team; moving into another team needs manager rights there too.

Forecast

RuleWhat the system does
Maker-checker on forecast adjustments'A manager other than the person who submitted it adjusts a forecast.' / 'Record not found.' (not visible) or 'Only a manager of the team (or an administrator) adjusts this forecast.'
Visibility of submissionsA sees only own; North's manager sees own and North's; admin sees all; an unrelated rep sees none of them.

Quotas

RuleWhat the system does
Maker-checker on quota approvalX: 'Somebody other than the person who set the quota approves it.'; Y approves; approve needs crm.configure.

Connectors

RuleWhat the system does
Hook key authenticationWrong or off: 401 'Unknown or switched-off connector.' with no data written; right key logs the event. The key is stored only as a SHA-256 and shown once on creation or rotation.
Connector management needs crm.configure403; the menu entry is hidden. Authorisation (who and when) is recorded and audited as 'crm.connector.authorized' / on / off / rotated.
Webhook is an unauthenticated route by designWorks only with a valid key; no company data is returned beyond status, id and deal id; wrong keys all answer the same 401.

Communications

RuleWhat the system does
Unmatched communications only for configurersRep sees an empty list; configurer / admin sees the unmatched events. Logged communications are only those on deals the user may see.

Duplicate review

RuleWhat the system does
No cross-team hintsA sees the candidate but the other side reads 'Another team's record' - no number or title leaks; only candidates of deals A may see are listed.

Territory access

RuleWhat the system does
Territory-limited people see only their territoriesEvery path answers only Dubai (and child) deals; others 'Record not found.'; creating outside gives 'This record falls outside the territories you work.'
Changing territory access takes effect at onceT's visibility changes on the next request (permission version bumped), without signing out.

Sales teams

RuleWhat the system does
Removing a member removes access at onceA loses North's deals immediately (permission version bumped); switching a team off has the same effect.

Coverage delegations

RuleWhat the system does
Cover is limited by team, person and dateAllowed only on North deals within the dates; refused otherwise; the covered person's own rights are unchanged.

Campaign responses

RuleWhat the system does
A response is never consentNo consent rows are written by CRM; the response row shows consent 'not implied'; marketing contact stays refused until consent is recorded with evidence.
RuleWhat the system does
Merging needs write access to both records'Only the owner or a team manager can change this CRM record.' / 'Record not found.'; the survivor and the source are unchanged.

CRM feature switches

RuleWhat the system does
A switched-off feature refuses changes but stays readableChanges refused with capability_disabled, menus hidden, history stays readable (reads pass); reads of masters still work.