Setting permissions on custom object records

Plan requirement

Subscription Suite Growth or higher, Support Professional or higher
Access Admin

Who can read, create and edit records is set per object, and it is worth deciding rather than accepting.

Set them

  1. Open the custom object in Admin Center.
  2. Open its permissions.
  3. Set what each role may do: read, create, update, delete.
  4. Save and check with an agent account.

The usual shape

  • All agents can read. They need the context to answer.
  • A smaller group can edit. Whoever is responsible for the data being right.
  • Almost nobody can delete. Deleting a record breaks the tickets pointing at it.

Read for everyone and edit for few is the configuration most organisations land on, and it is a good default to start from.

Where the data is sensitive

Contract values, renewal dates and commercial terms are not automatically things every agent should see. Where that applies, restrict reading too, and put only what agents need on the card in the context panel.

When another system owns it

Make it read-only for agents. A synced copy that agents can edit produces divergence, and the edit is lost at the next sync anyway, which is worse than not allowing it.

Filtering by brand

Records can be scoped to brands, so a multibrand account can keep one brand's contracts out of another's pickers. Worth doing where the brands are genuinely separate businesses.

See also

Was this article helpful?

0

Still stuck?

Our support team will take a look with you.

Comments

0 comments

Article is closed for comments.