Permissions & settings
Permissions & data visibility
CRM access is controlled at three levels, all configurable in CRM → Settings:
| Level | Controls | Typical example |
|---|---|---|
| Feature permissions | Whether a user can read/write contacts, leads, deals, contracts, or renewals at all | A rep has deals:write; a read-only auditor only has contacts:read. |
| Data scope | Which records a user can see for a permission they hold: own / team / all | A rep sees only their own deals; a sales manager sees their whole team’s; a director sees everything. |
| Admin settings | Who can configure pipeline stages, custom fields, lead-scoring rules, and CRM automations | Requires the CRM admin permission, separate from day-to-day read/write access. |
Win/Loss Analysis, Pipeline Forecast, and Service Renewals each have their own dedicated permission, so you can grant a manager visibility into forecasting without also granting them contract or renewal access, or vice versa.
Related settings
| To change | Go to |
|---|---|
| Pipeline stages, probabilities, and move rules | Settings → CRM Stages |
| Custom fields on contacts, leads, and deals | /crm/settings |
| Lead scoring rules | /crm/settings |
| Who sees which records | Settings → Roles → Data scope |
| Require an account on a deal · require a close date | Settings → ERP features |
What deal.won creates downstream | Settings → ERP features |
| CRM automation rules | /crm/automation/workflows |
| AI assistants and their suggestions | /crm/automation/agents |