Skip to content

RBAC Matrix

System Managers. Role definitions and their audit trail are platform-security controls, not ordinary workspace settings.

The CRM resolves permissions from user_roles and role_permissions; the legacy profile role array is not the authorization source. Every one of these 27 modules has read, create, edit, delete, manage, and an access level:

leads, cold_contacts, deals, contacts, organizations, vendors, tasks, pipelines, campaigns, influencer, sequences, finance, contracts, reports, chats, meetings, timesheets, compliance, email, files, calendar, projects, settings, integrations, automations, team, and data_exchange.

  • all permits eligible records across the module.
  • own restricts records to the user’s ownership scope where the record supports it.
  • none removes access.
  • delete controls destructive record operations.
  • manage controls sensitive non-CRUD operations such as staffing and time approvals. It is explicit and does not follow from delete.

Roles with at least one readable module can enter the CRM shell, including custom roles. The matrix—not an assumed built-in display name—is the default access source.

User-facing procedures authenticate the Clerk session, require CRM workspace access, then enforce a module/action guard. The guard provides the resolved access level to the procedure, and the procedure must apply it to the requested record.

Role definitions, permission edits, role audit history, business-rule configuration, and meeting-bot configuration are System Manager-only. A Sales, HR, or Operations manager can manage staffing only within their delegated role remit; none can assign platform, leadership, external, or custom roles.

  1. Identify the specific module and action the person needs.
  2. Choose all or own deliberately; do not use all merely to solve a single inaccessible record.
  3. Check whether the task is actually a manage operation.
  4. Review the effect on navigation, command-palette actions, API procedures, and owner-scoped records.

Authorization caches are cleared after role/permission changes. Administrative mutations are recorded in the Audit log after their main database operation commits.