RBAC Matrix
Who this is for
Section titled “Who this is for”System Managers. Role definitions and their audit trail are platform-security controls, not ordinary workspace settings.
The permission model
Section titled “The permission model”The CRM resolves permissions from user_roles and role_permissions; the legacy profile role array is not the authorization source. Every one of these 27 modules has read, create, edit, delete, manage, and an access level:
leads, cold_contacts, deals, contacts, organizations, vendors, tasks, pipelines, campaigns, influencer, sequences, finance, contracts, reports, chats, meetings, timesheets, compliance, email, files, calendar, projects, settings, integrations, automations, team, and data_exchange.
allpermits eligible records across the module.ownrestricts records to the user’s ownership scope where the record supports it.noneremoves access.deletecontrols destructive record operations.managecontrols sensitive non-CRUD operations such as staffing and time approvals. It is explicit and does not follow fromdelete.
Roles with at least one readable module can enter the CRM shell, including custom roles. The matrix—not an assumed built-in display name—is the default access source.
Guard ladder
Section titled “Guard ladder”User-facing procedures authenticate the Clerk session, require CRM workspace access, then enforce a module/action guard. The guard provides the resolved access level to the procedure, and the procedure must apply it to the requested record.
Role definitions, permission edits, role audit history, business-rule configuration, and meeting-bot configuration are System Manager-only. A Sales, HR, or Operations manager can manage staffing only within their delegated role remit; none can assign platform, leadership, external, or custom roles.
Before you change permissions
Section titled “Before you change permissions”- Identify the specific module and action the person needs.
- Choose
allorowndeliberately; do not useallmerely to solve a single inaccessible record. - Check whether the task is actually a manage operation.
- Review the effect on navigation, command-palette actions, API procedures, and owner-scoped records.
What happens next
Section titled “What happens next”Authorization caches are cleared after role/permission changes. Administrative mutations are recorded in the Audit log after their main database operation commits.
