Skip to content
Start free trial

Set up role permissions

Open Settings → Access → Roles. Create a role from a starting point, attach it to a team, and add people to that team. That is the whole setup. You do not type rights onto each user, and you do not use an “own records only” switch — records belong to a team.

CISA’s Cross-Sector Cybersecurity Performance Goals ask organisations to keep privileged work off everyday accounts: “No user accounts always have administrator or super-user privileges” (CISA, CPGs — Separating User and Privileged Accounts). In HARi that means: one or two Administrators, and a Viewer or Editor on the team that does the work.

HARi has three layers you will actually touch:

  1. Administrator or not — administrators manage settings and see every record
  2. Roles — per record type: Create, View, Edit, Delete, Reassign, each with a reach
  3. Teams — people inherit the roles attached to the teams they join

Reach values:

  • No access
  • Records their teams own
  • All records in their business unit
  • Every record in the organization

Reassign is the right to Change team or Make private. It is not included on the Editor starting point.

  1. Go to Settings → Access → Roles.
  2. Click a role (for example CRM Viewer).
  3. Read the starting point, then Fine-tune by record type if you need a cell-by-cell view.

A CRM Viewer typically Views contacts in their business unit and cannot Create, Edit, Delete, or Reassign them. A CRM Manager can change the same types further. Your workspace’s names will match what you created.

  1. Click New role.
  2. Name it in words people will recognise (“Field sales”, not fs_1).
  3. Pick the closest starting point (Baseline, Viewer, Editor, Manager, Administrator, or Custom).
  4. Adjust any record type that should be different.
  5. Tick capabilities you actually need (Export records, Import records, …). Leave Security administration off unless this role manages access.
  6. Click Review and save. Read who will gain or lose access, then confirm.
Record typeCreateViewEditDeleteReassign
ContactsTheir teamsTheir business unitTheir teamsNo accessNo access
CompaniesTheir teamsTheir business unitTheir teamsNo accessNo access
OpportunitiesTheir teamsTheir teamsTheir teamsNo accessNo access
InvoicesNo accessNo accessNo accessNo accessNo access

Roles do nothing until a team carries them:

  1. Go to Settings → Access → Teams.
  2. Open the team (or create one).
  3. Open RolesAdd role.
  4. Add people on Members. You will see what they gain before it commits.

To change one person’s access, move them between teams — do not clone a role per person.

The Everyone team can only carry read-only, workspace-wide roles. Editing rights go on Sales, Finance, or another real team.

  1. Open Settings → Access → Access Inspector, pick the person, and read what they can reach.
  2. Or open a record they should see and click Who can see this?who can see what.
  3. Sign in as them if you still want a walkthrough of the sidebar.

Changes take effect on the next request. If a tab still looks wrong, sign out and back in.