Profiles control what a user can do with a record: read, create, edit, or delete, set per record type.
On this page:
- How profiles work
- Administrative permissions
- Assigning a Page Layout to a profile
- Deleting a role or profile
How profiles work
A profile grants levels of access by record type. Users read, create, edit, or delete according to the profile they’re assigned. Some permissions depend on others; a profile cannot edit Contacts unless it can also read them. Two additional settings, Read All and Modify All, override all roles and sharing rules: Read All lets a user read every record of a type regardless of role or sharing rules, and Modify All lets a user create, edit, or delete every record of that type regardless of role or sharing rules.
Profiles also cover Tickets and Knowledge Articles for accounts using Insightly Service. If a user without a Service license has Read All and Modify All set, they can reach those records through the Related tab of records they’re linked to. Without those permissions, they only see Tickets and Knowledge Articles they own.
Configuring a profile
Set the permitted actions per record type. This is where you limit a user’s ability to change or remove records without restricting what they can see, which roles handle separately.
Administrative permissions
Separate from record-level permissions, a profile can also be granted Administrative Permissions: categories like managing users, security, automation, and integrations, each with its own checkbox.
Granting any Administrative Permission adds the System Settings menu option to that profile’s User menu. Options the profile isn’t permitted to manage still appear in System Settings, but attempting to open one redirects back to the main System Settings page with a “You do not have permission to access this system setting” message.
ℹ️ Manage Interface Customization is the one exception: it’s not covered by the System Settings redirect behavior, since it governs menu options within Insightly objects rather than System Settings itself. A profile with Manage Interface Customization but not Manage Data Definitions can handle layout rules, custom buttons, and page layouts, but can’t create, edit, or delete objects or fields.
Assigning a Page Layout to a profile
Profiles determine which Page Layout a user sees, so different teams can view the same object arranged for their needs. An accountant might see a billing layout while a project manager sees specifications.
Deleting a role or profile
⚠️ These deletions are permanent. Go to System Settings > Permissions to delete an unused role or profile.