Skip to content

Organization and permissions overview ​

Learn about the platform's organization management and permission control design and core capabilities.

Business value ​

In enterprise applications, a sound Org Structure, granular permissions, and a robust security foundation protect core business data and support efficient collaboration across departments. The platform provides flexible Org Structure configuration and multi-level data and function-level isolation. This helps you maximize operational efficiency while maintaining security.

Core capabilities ​

The platform provides the following organization and permissions management areas:

Management areaCore capabilitiesBusiness value
Organization managementMaintain multi-level departments and employee accounts, and enable multi-organization management.Map reporting relationships and establish the administrative foundation for employee ownership.
Function permissionsUse role-based access control (RBAC) to assign menu and operation permissions by business role and management role.Ensure that employees can use only the function buttons required for their responsibilities.
Data permissionsControl basic data permissions, department data permissions, data sharing rules, related teams, and temporary permissions.Control record-level and field-level visibility and protect customer asset privacy.

Core use cases ​

1. Function permission isolation ​

Employees in an enterprise have different responsibilities, such as sales, customer service, and finance:

  • Sales representatives can view and use business modules such as Sales Lead, accounts, and opportunities. They cannot modify system configuration.
  • Customer service specialists focus on ticket follow-up and customer service. They cannot access sensitive information such as sales forecasts and contract amounts.
  • System administrators have the highest management permissions. They manage object customization, process design, and security policy configuration.

2. Multi-level data visibility control ​

  • Owner restrictions: Sales representatives can access and edit only the account records they own.
  • Department-level sharing: Sales managers can view and manage business data for their departments and all subordinate departments. Peer departments remain isolated by default.
  • Cross-functional sharing: In cross-region collaboration, configure sharing rules to share customer data for a specific region with an after-sales support team in another region.