Skip to content
Start free trial

Teams and roles

A role says what someone is allowed to do. A team says who has that role. Every record belongs to a team, so who can open it is a function of team membership — not a one-off share, and not “this person owns it, therefore they can see it.”

Open Settings → Access. Roles, Users, Teams, Business Units, and Access Inspector sit in that group.

The Teams page with CRM Viewers selected, showing one member and tabs for Members, Roles, Records, and Settings

You never attach a role to a person. You attach the role to a team, then add people to that team. Someone in two teams gets the wider of the two.

That split is the least-privilege idea in ordinary language. Jerome Saltzer put it: “Every program and every privileged user of the system should operate using the least amount of privilege necessary to complete the job” (Communications of the ACM, 1974). HARi’s version is: pick a starting point (Viewer, Editor, Manager…), attach it to the team that actually does the work, and stop there.

Verizon’s 2024 Data Breach Investigations Report found the human element was a component of 68% of breaches — error, stolen credentials, or social engineering, not a clever exploit (Verizon, 2024 DBIR summary). Giving a sales team “see the whole workspace” because it is easier than picking a team is how that 68% gets a foothold in a CRM.

The Roles list: Billing Manager, Billing Viewer, CRM Manager, CRM Viewer, each summarised by what they can change and how far

For each record type a role can grant five actions, each with a reach:

ReachWhat it means
No accessThey cannot do this
Records their teams ownOnly records held by a team they are on
All records in their business unitEverything in the unit their team belongs to
Every record in the organizationThe whole workspace

The five actions are Create, View, Edit, Delete, and Reassign (move the record to another team). Reassign is its own right — editing a contact does not let you hide it.

Starting points on Settings → Access → Roles:

  • Baseline — sees records their teams own; cannot change anything
  • Viewer — sees everything in their business unit; cannot change anything
  • Editor — can create and edit records their teams own; can view the business unit; cannot reassign
  • Manager — can view and edit the business unit, including reassign; delete stays on their teams
  • Administrator — every record in the organization
  • Custom — you set every cell

CRM Manager open in the role editor, with Baseline, Viewer, Editor, Manager, Administrator, and Custom starting points

Fine-tune by record type when a starting point is close but not exact. New record types the role does not mention stay at the fallback you pick (usually No access).

The per-record-type grid for CRM Manager: Create, View, Edit, Delete with colour-coded reach

Saving a role shows who will gain or lose access before it commits. The Everyone team can only carry read-only, workspace-wide roles — editing rights go on a real team.

  • Personal — one per person, they cannot leave it. Records kept there are private from teammates (see private records).
  • Everyone — the whole workspace. Read-only roles only.
  • Administrators — built in. Name, members, and roles cannot be changed on the team screen.
  • General — Default — created with the workspace. New records land here unless the person picks another team.

Work teams (Sales, Finance, CRM Viewers) are the ones you create. Add members, attach roles, and — when it matters — see how many records the team already holds before you move them.

Owner is the person responsible for follow-up. Changing Owner does not change who can see the record. Who can see it is the team that holds it. Reassign / Claim on the record header change the person; Change team moves the record. See who can see what and record ownership.