Skip to main content

๐Ÿ”‘ Permission Control ยท Fine-grained Control of What Each Role Can Do

In the Enterprise Plan, you assign different permissions to different roles โ€” salespeople can only see their own customers and can't export; sales managers can see the whole department and can approve; interns can view but not edit. Paired with ownership management, this gives you full team collaboration + data security.

๐ŸŽฏ Why Permission Control matters
  • No customer data leakage โ†’ salespeople only see their own customers
  • Clear division of labor โ†’ each role's permission boundary is explicit
  • Prevents misoperations โ†’ interns / new hires can't delete or export sensitive data
  • Smooth offboarding handoff โ†’ offboarded permissions can be disabled in one click / customers reassigned

1. Add a Roleโ€‹

Create permission templates per position (e.g. "Salesperson / Sales Manager / Intern / Marketing Specialist").

Steps:

StepAction
1๏ธโƒฃLeft sidebar โ†’ [Enterprise] โ†’ [Permission Control]
2๏ธโƒฃAt the bottom of the page [Role List] โ†’ click [Add Role]
3๏ธโƒฃEnter the role name (e.g. "Salesperson") โ†’ save

Permission Control ยท Add Role modal: enter role name (e.g. Salesperson / Sales Manager) + save button, role appears in the list


2. Edit Permissionsโ€‹

Set what each role can / can't do.

Steps:

StepAction
1๏ธโƒฃLeft sidebar โ†’ [Enterprise] โ†’ [Permission Control]
2๏ธโƒฃIn [Role List], pick the role to edit (e.g. "Salesperson")
3๏ธโƒฃThe right side [Permission Scope] shows all assignable permissions
4๏ธโƒฃCheck / uncheck permissions โ†’ save

Permission Control ยท edit permission scope: left role list + right permission checkboxes (Customer / Email / Search etc. broken down by View / Edit / Export / Delete)

๐Ÿ’ก Common role permission templates
RoleCustomer MgmtEmailSearchExportDelete
๐Ÿš€ Salespersonโœ… View + edit (own)โœ… Send & receiveโœ… Search + saveโŒโŒ
๐Ÿ‘” Sales Managerโœ… View + edit (whole dept)โœ… Send & receive + auditโœ… Search + saveโœ…โœ…
๐Ÿ“Š Marketing Specialistโœ… View onlyโœ… Bulk send onlyโœ… Search + saveโŒโŒ
๐ŸŽ“ Intern / Newโœ… View only (own)โœ… View onlyโŒโŒโŒ
๐Ÿ‘‘ Admin (system preset)โœ… Allโœ… Allโœ… Allโœ…โœ…

๐Ÿ“‹ Pitfalls Roundupโ€‹

PitfallConsequenceHow to avoid
๐Ÿ”ด Giving salespeople "Export"Customer data may be taken away / sold to competitorsSalesperson / intern default off for Export; admin handles single requests
๐Ÿ”ด New hires with too many permissionsAccidental customer deletion / wrong-email sends hurt businessNew hires start with "Intern" role, upgrade after they're up to speed
๐ŸŸก Not following "principle of least privilege"Over-permissioned rolesEach role gets only the permissions needed for the job โ€” less is more
๐ŸŸก Admin role handed out looselyMultiple people with top permissions โ†’ management chaos"Admin" only for the boss + 1โ€“2 core managers
๐ŸŸก No periodic reviewPermissions stale after offboarding / role changesQuarterly audit of role permissions and member assignments
๐ŸŸก Permission changes not announcedMembers hit "feature unavailable" and are confusedWhen adjusting permissions, notify affected members

โ“ FAQโ€‹

Q1 ยท What's the difference between "Admin" and custom roles?โ€‹

Dimension๐Ÿ‘‘ Admin (preset)๐Ÿ› ๏ธ Custom Role
OriginSystem preset, not deletableUser-created
Permission scopeAll features, including permission management itselfWhatever you check
Can modify permissionsโŒ No (protected against accidental deletion)โœ… Fully customizable

Q2 ยท Can I create a "View only, no Export / Delete" role?โ€‹

โœ… Yes. In [Permission Scope], only check the "View"-related permissions (e.g. "Customer-View" / "Email-View"), and don't check "Export / Delete" or other sensitive actions.

Q3 ยท Who's affected when I change a role's permissions?โ€‹

Takes effect immediately, affecting all members assigned to that role.

โ†’ E.g. remove "Export" from the "Salesperson" role โ†’ all salespeople immediately lose Export.

Q4 ยท How does Permission Control relate to Ownership Management?โ€‹

Dimension๐Ÿ”‘ Permission Control๐Ÿค Ownership
DeterminesWhat can be done to customers (view / edit / export / delete)Who owns the customer
Used togetherPermission = "what to do" + Ownership = "to whom"

โ†’ Example: a salesperson's permission is "can edit own customers" + ownership management assigns customers A/B/C to them โ†’ they can only edit A/B/C.

See ๐Ÿ“š Customer Ownership.

Q5 ยท Can I temporarily upgrade a member's permissions?โ€‹

Yes. Change the member's role (e.g. temporarily from "Salesperson" to "Sales Manager"), then revert. Or create a temporary role just for that member.


๐Ÿ’ก Learning Tipsโ€‹

PrincipleHow
๐ŸŽฏ Principle of least privilegeEach role gets only what's necessary, no extras โ€” the data security baseline
๐Ÿข Roles by position"Salesperson / Manager / Marketing / Intern" โ€” divide by position, not person
๐Ÿ”„ Periodic reviewEach quarter, audit all role permissions + each member's role assignment
๐Ÿ“‹ Document the rulesWrite up "what level uses what role" inside the team, avoid ad-hoc assignment
๐Ÿšจ Act immediately on offboardingDisable / delete accounts immediately on offboarding; reassign customers in Customer Ownership

TopicLinkNotes
๐Ÿ‘จโ€๐Ÿ’ผ Team Membersmember-managementAssign the roles you've built to specific members
๐Ÿค Ownershipownership-management.mdDecides who owns the customer โ€” the basis for permissions to take effect
๐Ÿข Enterprise Basicsbusiness-managementEnterprise overview + account creation
๐Ÿ‘ฅ Department Structuredepartment-management.mdDepartment + role + permission โ€” the trio
๐Ÿ“Š Quota Managementquota-managementPermissions + quotas jointly govern enterprise resources

๐Ÿ”— Permalink: https://laifa.xin/zhinan/permissions-management