๐ Permission Control ยท Fine-grained Control of What Each Role Can Do
In the Enterprise Plan, you assign different permissions to different roles โ salespeople can only see their own customers and can't export; sales managers can see the whole department and can approve; interns can view but not edit. Paired with ownership management, this gives you full team collaboration + data security.
- No customer data leakage โ salespeople only see their own customers
- Clear division of labor โ each role's permission boundary is explicit
- Prevents misoperations โ interns / new hires can't delete or export sensitive data
- Smooth offboarding handoff โ offboarded permissions can be disabled in one click / customers reassigned
1. Add a Roleโ
Create permission templates per position (e.g. "Salesperson / Sales Manager / Intern / Marketing Specialist").
Steps:
| Step | Action |
|---|---|
| 1๏ธโฃ | Left sidebar โ [Enterprise] โ [Permission Control] |
| 2๏ธโฃ | At the bottom of the page [Role List] โ click [Add Role] |
| 3๏ธโฃ | Enter the role name (e.g. "Salesperson") โ save |

2. Edit Permissionsโ
Set what each role can / can't do.
Steps:
| Step | Action |
|---|---|
| 1๏ธโฃ | Left sidebar โ [Enterprise] โ [Permission Control] |
| 2๏ธโฃ | In [Role List], pick the role to edit (e.g. "Salesperson") |
| 3๏ธโฃ | The right side [Permission Scope] shows all assignable permissions |
| 4๏ธโฃ | Check / uncheck permissions โ save |

| Role | Customer Mgmt | Search | Export | Delete | |
|---|---|---|---|---|---|
| ๐ Salesperson | โ View + edit (own) | โ Send & receive | โ Search + save | โ | โ |
| ๐ Sales Manager | โ View + edit (whole dept) | โ Send & receive + audit | โ Search + save | โ | โ |
| ๐ Marketing Specialist | โ View only | โ Bulk send only | โ Search + save | โ | โ |
| ๐ Intern / New | โ View only (own) | โ View only | โ | โ | โ |
| ๐ Admin (system preset) | โ All | โ All | โ All | โ | โ |
๐ Pitfalls Roundupโ
| Pitfall | Consequence | How to avoid |
|---|---|---|
| ๐ด Giving salespeople "Export" | Customer data may be taken away / sold to competitors | Salesperson / intern default off for Export; admin handles single requests |
| ๐ด New hires with too many permissions | Accidental customer deletion / wrong-email sends hurt business | New hires start with "Intern" role, upgrade after they're up to speed |
| ๐ก Not following "principle of least privilege" | Over-permissioned roles | Each role gets only the permissions needed for the job โ less is more |
| ๐ก Admin role handed out loosely | Multiple people with top permissions โ management chaos | "Admin" only for the boss + 1โ2 core managers |
| ๐ก No periodic review | Permissions stale after offboarding / role changes | Quarterly audit of role permissions and member assignments |
| ๐ก Permission changes not announced | Members hit "feature unavailable" and are confused | When adjusting permissions, notify affected members |
โ FAQโ
Q1 ยท What's the difference between "Admin" and custom roles?โ
| Dimension | ๐ Admin (preset) | ๐ ๏ธ Custom Role |
|---|---|---|
| Origin | System preset, not deletable | User-created |
| Permission scope | All features, including permission management itself | Whatever you check |
| Can modify permissions | โ No (protected against accidental deletion) | โ Fully customizable |
Q2 ยท Can I create a "View only, no Export / Delete" role?โ
โ Yes. In [Permission Scope], only check the "View"-related permissions (e.g. "Customer-View" / "Email-View"), and don't check "Export / Delete" or other sensitive actions.
Q3 ยท Who's affected when I change a role's permissions?โ
Takes effect immediately, affecting all members assigned to that role.
โ E.g. remove "Export" from the "Salesperson" role โ all salespeople immediately lose Export.
Q4 ยท How does Permission Control relate to Ownership Management?โ
| Dimension | ๐ Permission Control | ๐ค Ownership |
|---|---|---|
| Determines | What can be done to customers (view / edit / export / delete) | Who owns the customer |
| Used together | Permission = "what to do" + Ownership = "to whom" |
โ Example: a salesperson's permission is "can edit own customers" + ownership management assigns customers A/B/C to them โ they can only edit A/B/C.
See ๐ Customer Ownership.
Q5 ยท Can I temporarily upgrade a member's permissions?โ
Yes. Change the member's role (e.g. temporarily from "Salesperson" to "Sales Manager"), then revert. Or create a temporary role just for that member.
๐ก Learning Tipsโ
| Principle | How |
|---|---|
| ๐ฏ Principle of least privilege | Each role gets only what's necessary, no extras โ the data security baseline |
| ๐ข Roles by position | "Salesperson / Manager / Marketing / Intern" โ divide by position, not person |
| ๐ Periodic review | Each quarter, audit all role permissions + each member's role assignment |
| ๐ Document the rules | Write up "what level uses what role" inside the team, avoid ad-hoc assignment |
| ๐จ Act immediately on offboarding | Disable / delete accounts immediately on offboarding; reassign customers in Customer Ownership |
๐ Related Featuresโ
| Topic | Link | Notes |
|---|---|---|
| ๐จโ๐ผ Team Members | member-management | Assign the roles you've built to specific members |
| ๐ค Ownership | ownership-management.md | Decides who owns the customer โ the basis for permissions to take effect |
| ๐ข Enterprise Basics | business-management | Enterprise overview + account creation |
| ๐ฅ Department Structure | department-management.md | Department + role + permission โ the trio |
| ๐ Quota Management | quota-management | Permissions + quotas jointly govern enterprise resources |
๐ Permalink: https://laifa.xin/zhinan/permissions-management