Who may do what
2 min read
A role bundles rights and the sight of records. Roles are records themselves, not fixed quantities: you create your own rather than making do with three.
Object times action
The matrix sets every object against its actions: records, fields, automations, partners, invoices and so on, depending on what is booked. What an account has not booked is not in the matrix.
Three rights are not included
Exporting, importing and sending do not sit inside read or write but are granted separately. Being allowed to read records therefore does not already allow handing them out; that is a different act with different consequences.
Sight belongs to the role
The same role states which records it sees: all of them, only assigned ones, or assigned ones plus those with no assignee. This is enforced in the query, not in the display. More under Who sees a record.
The internal name is locked
It is derived from the name and cannot be changed afterwards, because permissions refer to it. The label you may rewrite at any time.
Step by step
- Open Settings, Team, the Roles and rights tab.
- Create a role or open an existing one.
- Set the rights in the matrix.
- Choose the sight of records and save.
Why can a colleague not export although they see everything?
Because exporting is a right of its own and does not sit inside read. See Export.
Can I change a role that came with the account?
You can edit it like any other. If you are unsure, add your own alongside: the starting point then stays intact.
A new right does not show up on existing roles.
Rights are fixed when a role is created. If one is added later it has to be carried over, or an administrator with every checkbox still cannot see the new surface.
What is the difference between a role and a slice?
The role says what someone may do. The slice says on which entities. Both sit on the member, see Team.
Can I delete a role?
Yes, as long as nobody holds it. Otherwise someone would lose access without noticing.