Skip to main content
Complete reference of permissions for each standard role. For custom roles see Team and roles.

Standard roles

Admin

Full workspace control.

Manager

Team and automation management.

User

Daily operational use.

Read-only

Read-only (accountant).

Guest

Limited access to specific projects.

CRM permission matrix

🔸 = conditional (e.g. only if record owner, or only on team members)

Finance permission matrix

HR permission matrix

Automation permission matrix

Settings permission matrix

Ownership and visibility

Beyond roles, every record has:
Who “owns” the record (e.g. sales rep for deal). Always can modify.
Team can see/modify based on role.
  • Public: whole workspace
  • Team: only assigned team
  • Private: only owner + admin
Admin can define custom rules for specific records (e.g. “this deal visible only to 3 specific people”).

Field-level permissions

For sensitive fields you can make an attribute:
  • Visible only to certain roles
  • Read-only for certain roles
  • Hidden from certain roles
Example: “Salary” field on employee → visible only to HR Admin and CEO.

Custom roles

If the 5 standards don’t suffice, create custom from Settings → Team → Roles → + New:
  • Clone from existing (e.g. User + extra permissions)
  • Define granular per module
  • Apply to existing or new users

Audit log

Every sensitive action is logged:
  • Who (user)
  • What (action type)
  • When (UTC timestamp)
  • Where (IP + device)
  • Data (before/after for changes)
Access from Settings → Security → Audit log. CSV exportable for compliance.

Frequently asked questions

Permissions apply immediately. Already-open records may need refresh.
Yes, “Impersonate” function (Admin only). All actions logged as “X on behalf of Y”.