Skip to content
Start free trial

Permissions and security

HARi controls access with teams and roles. Every record belongs to a team. A role attached to that team says what members may do, and whether that right stops at the team, the business unit, or the whole workspace. The person named Owner is who follows up — they are not, by themselves, the lock.

Verizon’s 2024 Data Breach Investigations Report found the human element was a component of 68% of breaches (Verizon, 2024 DBIR). The practical CRM answer is the one you can explain on a record: click Who can see this? and read the names.

Settings → Access:

  • Roles — what a person may do (Create, View, Edit, Delete, Reassign) and how far
  • Users — invite people and pick the team they join
  • Teams — who is in the group, which roles they carry, which records they hold
  • Business Units — folders of teams, when one workspace has more than one wall
  • Access Inspector — one person, or one record

Start with teams and roles. Then who can see what, private records, business units, and export monitoring.

Older docs called these permission profiles. The product now says roles. Same idea, different word: a named bundle of rights, attached to a team, not typed onto each user.

Typical starting points:

Starting pointWhat it is for
BaselineSee the team’s own records, change nothing
ViewerSee the business unit, change nothing
EditorCreate and edit the team’s records; cannot reassign
ManagerEdit the business unit, including moving records to another team
AdministratorEvery record, plus security administration

You can create as many named roles as you need (CRM Viewer, Billing Manager). Details: set up role permissions.

The team that holds the record is the security boundary. New records take your default working team. Change team moves them. Make private moves them onto your personal team.

The Owner line under the title is the responsible person. Reassign and Claim change that person. They do not change who can see the row. Harvard Business Review found firms that contacted a new lead within an hour were nearly 7 times as likely to qualify it as those that waited even an hour longer (Harvard Business Review, “The Short Life of Online Sales Leads”, 2011). Owner is that follow-up name. The lock is the team.

The owner shown by name under a contact's title, with a Reassign button beside it

  1. Open the record and find Owner under the title.
  2. Click Reassign.
  3. Type a teammate’s name and pick them.

The change saves when you choose someone and is written to History.

The Reassign owner picker searching a teammate by name

A record with no Owner shows Claim. Click it to put your name on follow-up. That still does not move the record to your personal team.

Who can reassign Owner vs who can change team

Section titled “Who can reassign Owner vs who can change team”
  • Changing Owner needs Edit on that record.
  • Moving the record to another team, or making it private, needs Reassign on the role. An Editor does not get that by default.

On a role, extra checkboxes cover workspace-wide actions:

  • Export records — download a CSV (still limited to rows you can view). See export monitoring.
  • Import records
  • Mass update / Mass delete
  • View audit log
  • Access admin panel, Edit schema, Manage API keys
  • Security administration — roles, teams, units, invitations that change access

The Owner line under the title is the responsible person. Reassign and Claim change that person. They do not change who can see the row — that is the team. Same steps as Reassigning the responsible person.

Settings → Access → Users, then deactivate. Team-owned records stay on the team — colleagues keep working them. Records on the leaver’s personal team are moved, with a warning about who will newly see them, so nothing is stranded and nothing is silently widened. You pick a successor. The audit log records the move.

Reactivating a user turns login back on. Records that were moved do not slide back by themselves. Team memberships stay as they were.

Every change is recorded: who, when, old value, new value, which record. Open the History tab on the record. Retention is configurable; old months can be dropped.

  1. Start from a starting point, then narrow — do not begin at Administrator.
  2. Put people on a work team on day one so their first records are not silently private.
  3. Use Who can see this? before you promise a colleague they can open a row.
  4. Watch Export Logs after someone leaves.
  5. Keep the Administrator count small.