Skip to main content
Complete reference of permissions for each standard role. For custom roles see Team and roles.

Standard roles

Admin

Full workspace control.

Manager

Team and automation management.

User

Daily operational use.

Read-only

Read-only (accountant).

Guest

Limited access to specific projects.

CRM permission matrix

ActionAdminManagerUserRead-onlyGuest
See workspace deals
See own deals🔸
See team deals🔸
Create deals
Edit own
Edit others’🔸
Delete deals🔸
Export CSV🔸
Bulk import
🔸 = conditional (e.g. only if record owner, or only on team members)

Finance permission matrix

ActionAdminManagerUserRead-only
See active invoices🔸
Issue invoices🔸
See passive invoices
Approve passive invoices🔸
Bank reconciliation🔸
See balance sheet🔸
Period close
Modify chart of accounts

HR permission matrix

ActionHR AdminManagerUserEmployee (self)
Full employee master data🔸Only own
PayslipsOnly own
Salaries and costsOnly own
Approve team leaves
See colleague leaves🔸Team
Modify contracts
Performance review✅ (team)Only ownOnly own

Automation permission matrix

ActionAdminManagerUser
Create workflow
Modify workflow🔸
Activate/deactivate🔸
See run history🔸
Run manual workflows
Configure webhooks

Settings permission matrix

ActionAdminManagerUser
Workspace settings
Team and roles🔸 (team invite)
Billing
Integrations🔸
Custom objects
Global automations🔸

Ownership and visibility

Beyond roles, every record has:
Who “owns” the record (e.g. sales rep for deal). Always can modify.
Team can see/modify based on role.
  • Public: whole workspace
  • Team: only assigned team
  • Private: only owner + admin
Admin can define custom rules for specific records (e.g. “this deal visible only to 3 specific people”).

Field-level permissions

For sensitive fields you can make an attribute:
  • Visible only to certain roles
  • Read-only for certain roles
  • Hidden from certain roles
Example: “Salary” field on employee → visible only to HR Admin and CEO.

Custom roles

If the 5 standards don’t suffice, create custom from Settings → Team → Roles → + New:
  • Clone from existing (e.g. User + extra permissions)
  • Define granular per module
  • Apply to existing or new users

Audit log

Every sensitive action is logged:
  • Who (user)
  • What (action type)
  • When (UTC timestamp)
  • Where (IP + device)
  • Data (before/after for changes)
Access from Settings → Security → Audit log. CSV exportable for compliance.

Frequently asked questions

Permissions apply immediately. Already-open records may need refresh.
Yes, “Impersonate” function (Admin only). All actions logged as “X on behalf of Y”.