Roles and permissions
Goal. Understand what each CRM role can do and how permissions determine the screens and actions available to each person.
Prerequisites. None to consult this reference. Changing roles or permissions requires the Administrator role; the procedure is described in the "Settings" category, article "Team and access".
The three roles
| Role | Scope |
|---|---|
| "Administrator" | Full access. The only role that sees "Settings" and manages the team, integrations, backups and the licence. Its permissions cannot be reduced. |
| "Operator" | Works cases from start to finish: clients, cases, money, contracts, appointments, inbox, advertising and reports, according to the company's permission template. |
| "Assistant" | Front-line support: clients, appointments and inbox. Does not see amounts and does not manage money, contracts or reports. |
Role names can be customised per company from "Settings" › "Team"; this guide uses the factory names.

Factory permissions
The CRM ships with a permission template for "Operator" and "Assistant". The administrator can adjust it per role and, in addition, grant or remove permissions for a specific person as an exception. The table lists the factory values; the "Administrator" has them all.
| Module | Permission | Operator | Assistant |
|---|---|---|---|
| Clients | View clients | Yes | Yes |
| Clients | Create clients | Yes | Yes |
| Clients | Edit clients | Yes | Yes |
| Clients | Delete clients | No | No |
| Clients | Erase all data for a client | No | No |
| Clients | Import clients | Yes | No |
| Clients | Export clients | No | No |
| Clients | Send the client portal | Yes | No |
| Cases | View cases | Yes | Yes |
| Cases | Create cases | Yes | No |
| Cases | Move cases between stages | Yes | No |
| Cases | Archive cases | Yes | No |
| Cases | Delete cases | No | No |
| Cases | Delete documents | No | No |
| Cases | Stop sharing documents | Yes | No |
| Money | View amounts and balances | Yes | No |
| Money | Record payments | Yes | No |
| Money | Manage payment plans | Yes | No |
| Money | Manage quotes | Yes | No |
| Contracts | Generate contracts | Yes | No |
| Contracts | Send contracts for signature | Yes | No |
| Appointments | View the calendar | Yes | Yes |
| Appointments | Create and manage appointments | Yes | Yes |
| Inbox | View the inbox | Yes | Yes |
| Inbox | Reply to messages | Yes | Yes |
| Inbox | View internal notes | Yes | No |
| Marketing | View advertising | Yes | No |
| Marketing | Manage campaigns | No | No |
| Reports | View reports | Yes | No |
What happens without a permission
- Navigation entries. Screens whose permission is missing are hidden: "Inbox" requires "View the inbox"; "Clients", "View clients"; "Cases", "View cases"; "Quotes", "Manage quotes"; "Payments", "View amounts and balances"; "Reports", "View reports"; "Campaigns", "Manage campaigns"; "Advertising", "View advertising"; "Plans", "Manage payment plans"; "Calendar", "View the calendar". "Contracts", "Documents" and "Tasks" are shown to every role.
- Actions inside a screen. The buttons for actions that are not allowed do not appear and, if the action were attempted another way, the server rejects it with "You don't have permission to perform this action.".
- Amounts. Without "View amounts and balances", prices, balances and totals are not shown anywhere in the CRM.
Troubleshooting
- A colleague sees a screen you do not. Your role, or a personal exception, does not include the permission. Ask an administrator for the change.
- "You don't have permission to perform this action." when saving. The permission was removed after you opened the screen. Reload the page; the action will no longer be available.
- You need an assistant to record payments. The administrator can grant that specific permission as an exception without changing their role, from "Settings" › "Team".

