Access and Roles
Access to the CRM is built from three things: a login that can reach the workspace, one or more CRM sections, and the CRM permissions that say what you can do inside them. All three are set on the user record, and all three can be granted through a user group.
Login (CRM)
Section titled “Login (CRM)”A user’s access type controls which interfaces they can sign in to. Login (Backend) and Login (CRM) are granted independently, so you can create CRM-only staff, backend-only staff, or people who use both.
CRM-only users get their own account area for password changes, two-factor setup and API keys, so a login challenge never bounces them into an interface they cannot use. See Account security.
Saving a Login (CRM) user who holds the Sales, Customer Services or Credit Control section also checks that they hold at least one CRM permission. If they do not, the platform suggests a role group rather than saving someone into an empty workspace. Billing-only users are exempt, because the Billing section runs entirely on backend permissions.
The four CRM sections
Section titled “The four CRM sections”Sections decide which wing of the workspace a person works in. They are set per user, and per dealer, and are capped by the Enabled CRM Sections setting for the platform or that dealer. Nobody can hold a section the platform has not switched on.
| Section | What it opens |
|---|---|
| Sales | Sales Home, the pipeline, deals, proposals, renewals, sequences, campaigns and the sales side of Go Live |
| Customer Services | Customer Services Home, Cases, Complaints, Confirmations, correspondence and the email queue |
| Credit Control | Credit Control Home, chasing, the Chase Run, credit limits, SMS types and the recovery reporting |
| Billing | Billing Home, invoices, payments, payment methods, credit requests and bringing deals live |
There is also a Base section, which grants the shared customer, record and product screens that the other sections build on.
Signing in takes you to the dashboard of your primary section. If you hold more than one, the others appear as further groups in the menu.
CRM permissions
Section titled “CRM permissions”Alongside the sections sits a family of CRM permissions, each granted at the usual levels of See, View Details, Add, Edit and Delete.
| Permission | Governs |
|---|---|
| CRM Deals | Deals, deal activity, leads and the enquiry inbox |
| CRM Proposals | Proposals, approval, sending and acceptance |
| CRM Deal Items | Pre-sale numbers, services and features on a deal |
| CRM Deal Activity | The deal timeline |
| CRM Chasing | Chase cases, chase items and payment arrangements |
| CRM Chase Activity | Chase holds, activity, reviews, approvals and communication attempts |
| CRM Packages | Packages and usage profiles |
| CRM Sequences | Sequences, steps and enrolments |
| CRM Cases | Cases and their threads |
| CRM Stock Numbers | The stock number inventory |
| CRM Campaigns | Campaigns and bulk correspondence sends |
| CRM Email Queue | The CRM email send queue |
| CRM Team Queues | Team-wide rather than personal queues, per section |
| Confirmations of Instructions | Confirmations and their approvals |
| CRM Case Sending | Sending customer-visible case replies, per section |
| CRM Credit Requests | Raising credits, goodwill gestures and refunds |
| CRM Complaints | The Ofcom complaints register |
Several permissions carry extra capability bits on top of the five levels. The ones that change day-to-day work most are:
- View Others’ Deals and Edit Others’ Deals on CRM Deals, which open the owner picker beyond your own name.
- Manual Usage Rates on CRM Deals, which allows hand-keyed usage figures on a deal.
- Approve Proposal, Send Without Approval and Accept on Customer’s Behalf on CRM Proposals.
- Run Chase Sends and Approve Chase Actions on CRM Chasing.
- Run Sequence Sends on CRM Sequences.
- Send Campaign Correspondence on CRM Campaigns.
- Approve Confirmation, Send Without Approval and Accept on Customer’s Behalf on Confirmations of Instructions.
Two permissions that work per section
Section titled “Two permissions that work per section”CRM Team Queues and CRM Case Sending are not granted at a level. Instead you tick the sections each applies to.
CRM Team Queues decides whether a person sees their own work or the whole team’s. Without it the Showing picker does not appear at all and every queue is quietly limited to their own customers and cases. This is the single most common reason somebody reports “missing” work, so grant it deliberately.
CRM Case Sending decides whether a person’s case replies go to the customer or are held as drafts. Without it for a section, every reply they write in that section is saved as a draft for a colleague to review and send, and the button on the case page relabels itself to say so. It is how you let a trainee, or an AI assistant working through the API, draft replies safely.
The ready-made role groups
Section titled “The ready-made role groups”Four supplied groups cover the usual shapes. Three are complete roles; the fourth is an overlay you add on top of one of them.
- Sales - the full salesperson role: the sales CRM permissions, day-to-day backend permissions for customers, numbers, features and correspondence, and the Sales reports. It carries no chasing rights and cannot accept on a customer’s behalf.
- Credit Control - chasing, chase activity and cases, including Run Chase Sends.
- Customer Services - cases, plus read-only campaigns and email queue.
- CRM Manager - an overlay, not a role. It grants deletes, the capability bits (Approve Chase Actions, Accept on Behalf and the rest) and all four team-queue bits, but no See or View Details of its own. Combine it with one of the three base groups; on its own it opens nothing.
The Billing group deliberately gains no CRM permissions, because the Billing section runs on the ordinary backend invoice, payment and transaction permissions.
Giving somebody the Credit Control CRM section is not the same as putting them in the Credit Control user group. The section opens the wing of the workspace; the group grants the permissions and the customer form’s Credit Control fields.
Which fields appear
Section titled “Which fields appear”The workspace has its own column in Form Fields: Display (CRM) and Edit (CRM). Set them to trim a record down to what an operator needs on a busy screen, without touching what the backend shows. Where they are not set, the CRM falls back to your normal Display and Edit settings.
This is how the invoice, payment and customer lists in the workspace decide their columns, so a field you hide here disappears from the list, the CSV export and the menu badge together.
Related pages
Section titled “Related pages”- User Management for creating the user and choosing the access type.
- User Groups for granting these permissions to a group rather than one person.
- Packages and tiers for what your CRM package includes, which is a separate question from what a person is permitted to do.