Advanced Permissions builds layers of access around groups of users, so people reach the records they need without seeing everything else.
Available on Professional and Enterprise. Other plans use Simple Permissions.
On this page:
- Records, objects, and what happens when you switch it on
- The four permission types
- How profiles and roles interact
- Planning
- Managing users
- Configuring roles
- Troubleshooting record access
Records, objects, and what happens when you switch it on
Records are individual items: a contact record for one person, an organization record for one company. Objects are the kinds of record: tasks, contacts, leads, and so on.
⚠️ Enabling Advanced Permissions closes access down to almost nothing. Records become visible only to their owners, their assignees, and administrators until you build the permission layers back up. Plan the structure before switching it on.
Insightly checks permissions on every page view and shows only the objects, records, links, and actions that user is allowed. Because entire tabs disappear when a profile lacks read permission, the effect is not only security but a navigation bar with less irrelevant material in it.
The four permission types
| Type | Controls | Tied to |
|---|---|---|
| Profiles | Which objects a user can see and change, covering read, create, edit, and delete | Objects |
| Organization-Wide Sharing | The default sharing level per object: Public opens it to everyone, Private restricts it to owners, assignees, the role hierarchy, and sharing rules | Record ownership |
| Roles | Which records a user can see through a sharing hierarchy, so a manager sees their reports’ records | Record ownership |
| Sharing Rules | Exceptions to roles, widening visibility across or up the hierarchy | Record ownership |
Moving from Private in organization-wide sharing, through roles, to sharing rules opens access progressively to more records for more users.
How profiles and roles interact
A profile is what someone does in the CRM. A role is whose records they can see through the access hierarchy. They apply together, and the more restrictive one wins.
The source’s worked example: a user sits in the Chief role at the top of the hierarchy, which would let them see the records of everyone below them. They are also on the Contractor profile, which has no access to leads or opportunities. The result is that they see no leads or opportunities at all, and neither tab appears in their navigation bar.
Any user and any record can be checked to see why something is or is not visible.
ℹ️ Profiles and roles do not need to mirror your org chart. This is about record access, not job titles. Custom profiles may not be needed at all, depending on how you want to manage access.
Planning
Five questions, each mapping to one setting:
| Question | Setting |
|---|---|
| Should all users reach every record of an object, or only a subset owned by certain users? | Organization-Wide Sharing |
| If a subset, whose records can they see down through the hierarchy? | Roles |
| Whose records can they see across or up the hierarchy? | Sharing Rules |
| Should a user reach every object, or only some? | Profiles |
| Should a user create, edit, or delete those objects? | Profiles |
Expect to add roles, profiles, and sharing rules as the business grows and new responsibilities appear.
Managing users
Roles, sharing rules, and profiles are all managed from System Settings > Permissions.
Assign a user to a role at System Settings > Permissions > Roles, clicking Assign beside the role. Assign a profile at System Settings > Permissions > Profiles, clicking Assign beside the profile. Profiles control which objects users can see, which fields they can see through Page Layouts, and whether they can create, edit, or delete records.
Two further permissions live on the System Settings > Users page:
- Administrators see all records, change system settings and permissions, and reach billing pages to update card details or view invoices.
- Export Permissions let a user export any records they can view.
⚠️ Advanced Permissions do not apply to administrators. Roles, sharing rules, and profiles are all bypassed for anyone with administrator rights, so administrator count is itself a permissions decision.
Account Owner exists on every paid plan and is the person who receives invoices by email. They can be any type of user and always reach billing pages. Change the account owner from Billing & Account > Account Owner.
Configuring roles
Roles are the first step in letting users see records belonging to other users.
- Go to System Settings > Permissions.
- Select the Roles tab and click Add Role.
- Enter a name describing the role’s position in the hierarchy.
- Select the role this one reports to. Skip on your first role.
- Click Save to reach the user assignment page.
- Filter with All Users with No Role or another option, or search for a specific user.
- Click a user’s name and then the right arrow to assign them.
- Click Save.
The role then appears in the hierarchy, viewable as a table or a tree through the View As options.
⚠️ A user can hold only one role. Assigning someone who already has a role removes them from it and reassigns them, without a separate warning.
Sharing List Views and Dashboards by role
List Views and Dashboards can be shared with yourself only, the whole account, or a specific role or sub-role. Sharing to a role targets the relevant stakeholders instead of everyone.
⚠️ Sharing with a role includes every subordinate role, and those users can see and edit the record. This option only exists on accounts with Advanced Permissions enabled.
Troubleshooting record access
Once Advanced Permissions is running, users see only what their profiles and roles allow. When someone cannot reach a record they need, or can reach one they should not, check their profile and role at System Settings > Permissions and compare them against the record.
Compare the user’s role to the record owner’s role in the hierarchy, and the record type to the user’s profile permissions. Working through each layer separately narrows down which one is responsible.