Roles and permissions

Your staff, the roles they hold, and the two questions every role answers: what somebody may do, and whose records they may do it to.

Most systems only answer the first question. Zenta CRM answers both, because "can see invoices" and "can see everyone's invoices" are very different permissions to give a new salesperson. Both live under the Organisation part of the menu: Staff for the people, Teams for who works with whom, and Roles for what they may do.

Staff

Organisation → Staff: everybody who can sign in to the panel, their role, and when they last did. Organisation → Staff: everybody who can sign in to the panel, their role, and when they last did.

Organisation → Staff lists the people who work in the panel. Each row shows the person's name and email address, their Role, their Job title, whether they are Active or Inactive, and their Last sign in. A yellow Overridden badge beside a role means some of that person's permissions differ from the role's (see Changing one person's permissions) — the first thing anybody auditing access needs to see.

Search by name or email in Search name or email, narrow to Active or Inactive with All statuses, and press Filter; Clear removes both. The count of people on the right follows the filter. Print and Export print or download the list as it is filtered (see Exporting).

The row menu: the profile, the edit dialog, the person's permissions, deactivating and deleting. The row menu: the profile, the edit dialog, the person's permissions, deactivating and deleting.

The menu at the end of a row offers:

ItemWhat it does
View profileOpens the person's profile.
EditOpens the same dialog used to add somebody, filled in.
PermissionsOpens the page where this one person's permissions can differ from their role. Shown to people whose role may edit roles.
Deactivate / ReactivateStops the person signing in, or lets them back in. Not offered on your own row. The workspace owner cannot be deactivated.
DeleteRemoves the person from your team, after a confirmation. Not offered on your own row, nor on the workspace owner's.
An administrator's account is changed only by an administrator. Edit on staff is a manager's permission, not an administrator's. Somebody who is not an administrator can open an administrator's row menu, but editing, deactivating or deleting that account is refused: Only an administrator can change an administrator's account.

Adding and editing a member of staff

Add staff member. You set the password; the person signs in with this address and that password. Add staff member. You set the password; the person signs in with this address and that password.

Press Add staff member. The dialog asks for:

FieldWhat it does
First nameRequired.
Last nameOptional.
Email addressRequired. What they sign in with. Two people in your workspace cannot share one: Someone on your team already uses this address. When somebody who is not an administrator edits another person, the box is read-only (see below).
Phone, Job titleOptional. The job title shows on the list and the profile.
RoleWhat they may do. No role (no access) is allowed, and means exactly that. The list offers Administrator to administrators only.
Password and Confirm passwordRequired for somebody new; at least eight characters. When editing, leave blank to keep the current one. Not shown when somebody who is not an administrator edits another person.
TeamsShown once you have teams (see Teams). Ticking one matters for any role scoped to Their teams.
BioA few lines shown on their profile.
Custom fieldsAny fields you have added for staff appear here.
Active - can sign inOn by default. Off creates the account without letting it sign in yet.

Press Add staff member to create the account, or Save changes when editing. Nothing is emailed to the person: you pass on the address and password yourself. Somebody who would rather choose their own can use Forgot password? on the sign-in page.

On a hosted plan, staff count against it. Where your workspace is on a plan with a staff limit, adding somebody past it is refused with Your plan allows … staff members. Upgrade to add more. Deactivated people still hold their place; delete an account to free it.
Editing somebody. The link under Role opens their permission overrides. Editing somebody. The link under Role opens their permission overrides.

When editing, a link under Role reads Override permissions for this person, or Permissions overridden - review when some already are. It is shown to people whose role may edit roles.

What only an administrator can change

Create and Edit on staff are what the shipped Manager role holds, so they stop short of an administrator's powers. For anybody who is not an administrator:

What they may not change is kept as it was, whatever the browser sends. The dialog is otherwise the same; see Running a team for how it looks to a manager.

A member of staff's profile

A profile: who they are, their headline figures, and what they have done lately. A profile: who they are, their headline figures, and what they have done lately.

Click a name in the list, or View profile. The left side shows the person — job title, role, Active or Terminated — with how many Projects, Clients and Tasks they have, then their Bio (a sentence is written for them when it is empty), email, phone, teams, when they joined and last signed in, their Progress (the share of their tasks completed, and how many are open, done and overdue) and their Projects.

The tabs on the right:

The Tasks tab: open work first, overdue dates in red. The Tasks tab: open work first, overdue dates in red.
A profile shows only what you could open yourself. The projects and tasks on somebody's profile go through your scope for projects and tasks, so looking at a colleague on another team never names work you could not see. The counts at the top use the same lists, so a number and the list under it always agree.

Giving somebody work

Assign: a running project, then any of its open tasks. Assign: a running project, then any of its open tasks.

Assign on a profile opens Assign work to …. It is offered to anybody whose role may edit tasks or edit projects, and is greyed out for somebody who has been terminated.

  1. Project — required. Only projects that are still running, and that you can see, are listed.
  2. Tasks — the project's open tasks, grouped by status, loaded when you pick the project. Tasks already theirs are shown but cannot be chosen. Needs permission to edit tasks.
  3. Add to the project team — on by default; needs permission to edit projects. Somebody already on the team cannot be added again, and the switch says so.

Press Assign. The person gets a notification for every task they are given, and one for joining the project. Anybody given a task on a project is added to its team whether or not the switch was on — otherwise a role that only shows their projects would hide the very project their new tasks sit in. Choose at least one task or the team switch, or the dialog asks you to.

Deactivating, terminating and deleting

Deactivate on the list and Terminate on the profile are the same switch. After a confirmation the person can no longer sign in, and if they are signed in at that moment they are signed out on their next click. Their records and history are kept. Reactivate or Reinstate lets them back in with their existing role. You cannot deactivate yourself, and the workspace owner cannot be deactivated: The account owner cannot be deactivated.

Delete removes the person from your team. Use it for an account that should not exist at all; for somebody who has left, deactivating keeps their name on what they did. You cannot delete yourself, and the workspace owner's account cannot be deleted by anybody — it is the account of last resort.

Teams

Organisation → Teams: each team with its description and its members, and New team. Organisation → Teams: each team with its description and its members, and New team.

Organisation → Teams. A team is a named group of staff, and it is what every scope called Their teams reads: somebody on that scope sees the work of everybody who shares at least one team with them. A person can be on several teams, or none — and somebody on no team has nobody to share one with, so Their teams shows them only their own work. Announcements, goals and calendar events addressed to one team use the same teams.

The list shows each Team with its description underneath, its Members as initials (hover for the name, or Nobody yet), and at the end of the row to edit it and to remove it.

New team: a name, a description, and a box for each active member of staff. New team: a name, a description, and a box for each active member of staff.

Press New team. The dialog asks for:

FieldWhat it does
NameRequired, up to 191 characters, and unique in the workspace.
DescriptionOptional; shown under the name in the list.
MembersA box for each active member of staff. Tick the people on the team.

Press Add team. opens the same dialog as Edit team, filled in; change it and press Save changes. A person's teams can also be ticked in the Teams boxes of their staff record — both change the same thing.

Edit team: the members already on it are ticked. Edit team: the members already on it are ticked.

removes a team after you confirm (Remove this team? Its people stay; anyone scoped to their teams sees less of their work.). Nobody's account is touched; the people simply have one team fewer, and from then on anybody on a Their teams scope sees less of their former teammates' work.

The screen has its own module in the role editor, Teams, with View, Create, Edit and Delete: View shows the menu item and the list, and each of the others its button. The shipped Manager role holds View, Create and Edit, so a manager makes and changes teams but does not remove them.

Abilities

Organisation → Roles. A role is a list of modules — leads, invoices, tasks, staff, settings — and for each one, some combination of:

AbilityMeans
ViewOpen the screen and read records.
CreateAdd new records.
EditChange existing ones.
DeleteRemove them.
ExportDownload the list as a spreadsheet.
ApproveLeave only: grant or refuse somebody's request.
SendCampaigns only: put a campaign in front of its lists.
SignSign for the business only: countersign a document on the business's behalf.

Not every module has every ability; the editor shows only the boxes that mean something for that module. AI assistance has its own three — Use the AI features, Use the assistant and Write agents (see AI assistance).

Approve and Send are separate from Edit on purpose. Correcting a typo in a leave request must not also mean being able to grant it, and writing a campaign must not also mean being able to email every customer with it.

Scope

And for each module, which records those abilities apply to — the dropdown at the end of each row:

ScopeMeans
All recordsEvery record in the workspace.
Their teamsRecords owned by anyone on the same team. Teams are made under Organisation → Teams.
Assigned to themOnly records the person is assigned to.
Their clientsRecords belonging to customers the person manages: customers whose Account owner they are, or where they are Also on the account. The same rule on every kind of record.
Their own recordsOnly records the person created or owns.
No accessThe module is hidden entirely.

Each module offers only the scopes that make sense for it: payments, items and settings are all or nothing, while projects and tasks offer all six.

The staff list seen by an Employee: their teams, and nobody else. The staff list seen by an Employee: their teams, and nobody else.

Narrower still: restrictions

Some modules take a third, optional limit, under a collapsed line below their boxes. The scope still decides whose records they are; a restriction narrows that further and never widens it. Nothing ticked means no limit.

An example

A salesperson might have:

They have full control of their own pipeline, can see the invoices of customers they manage, and cannot see the company's numbers.

Scope is enforced in the database query, not in the interface. A record outside somebody's scope is not hidden from the page — it is never fetched. Guessing its address returns the same "not found" as anything else that does not exist for them.

Roles

Organisation → Roles: each role, how many modules it reaches and how many people hold it. Organisation → Roles: each role, how many modules it reaches and how many people hold it.

The list shows each role with its description, how many Modules it reaches (Everything for the administrator role) and how many People hold it. The administrator role carries a Full access badge; the other roles every workspace starts with carry System.

The three roles you start with

RoleWhat it holds
AdministratorEvery permission, always. Unrestricted access to everything.
ManagerRuns the team day to day: staff and teams (view, create, edit), attendance, leave (including approving it), announcements, the timeline and the wiki, AI help and the assistant, the calendar, goals and messages. No customer, sales or delivery modules until you add them.
EmployeeSees their own team and nothing else: the staff of their teams, their own attendance and leave, reading announcements and the wiki, posting to the timeline, AI help and the assistant, the calendar, goals and messages.

None of the three reaches leads, customers, invoices or projects out of the box: what your salespeople or project managers should see is your decision, so make a role for it (or edit these). Manager and Employee can be renamed and re-scoped freely. The administrator role can be renamed, but always holds every permission — editing its map would only be a way to lock the workspace out of its own account. System roles cannot be deleted.

Creating and editing a role

The role editor: a row per module, its abilities, and the scope at the end of the row. The role editor: a row per module, its abilities, and the scope at the end of the row.

New role opens a blank editor; Edit on a row opens that role. On the left, Role name (required, and unique in the workspace) and Description. On the right, Permissions: the modules in their groups, each with its ability boxes, any restrictions, and the scope dropdown. Across the top of the permissions:

Press Create role, or Save changes when editing. Anybody holding the role gets the change on their next click. Opening the administrator role shows only its name and description: This role always has every permission. Only its name and description can be changed.

New read-only role: every View box ticked, outside the Organisation group. New read-only role: every View box ticked, outside the Organisation group.

New read-only role, beside New role, opens the editor with the read-only preset already applied — the quickest start for an auditor or somebody's first week. Nothing is saved until you press Create role.

Cloning and deleting a role

Clone on a row asks Make a copy of the … role, with the same permissions? and opens the copy, named Copy of … (numbered when that is taken). A copy is always an ordinary role, never a system one; a copy of the administrator role holds every permission but can be trimmed, which is the point of making it.

The button deletes a role you made, after a confirmation. A role somebody still holds cannot be deleted — This role is still assigned to … people. Move them to another role first.

Changing one person's permissions

Permissions for one person: their role on the left, the modules on the right, and their recent sign-ins. Permissions for one person: their role on the left, the modules on the right, and their recent sign-ins.

Sometimes one person needs a little more, or a little less, than their role — without making a role just for them. Permissions on a profile or in the staff list opens Permissions for …. It needs permission to edit both staff and roles.

Each module shows what the role gives (Role: View, Create · Their clients, or Role: No access). Switch on Override under a module and its boxes and scope unlock; set them, and press Save permissions.

Two modules overridden: this person may work on every project, whatever their role says. Two modules overridden: this person may work on every project, whatever their role says.

The panel on the left repeats the role and counts the overridden modules. Administrators also see Recent sign-ins: the last ten attempts to sign in to this account, successful or not.

What the dashboard shows each person

The dashboard of somebody on the Employee role: only panels for what the role can read. The dashboard of somebody on the Employee role: only panels for what the role can read.

Every dashboard panel is behind the permission for the thing it summarises, so the dashboard reaches exactly as far as the role does (see Reports and dashboards). The Latest activity panel, like Organisation → Activity itself, needs View on staff with the scope All records: seeing the whole staff, not only your own team (see The activity log).

Customer contacts

A contact at a customer is a different kind of account. They sign in at /portal, never at the staff login, and the two audiences never see each other's screens. What each contact may see is set per contact on the customer record.

Addresses on this page

For reference and for anyone scripting against the panel. Everything here needs somebody signed in to the workspace whose role allows it; anybody else is refused.

MethodAddressWhat it does
GETadmin/staffThe staff list, with q and status filters.
GETadmin/staff/createThe Add staff member dialog.
POSTadmin/staffCreates a member of staff.
GETadmin/staff/{user}A member of staff's profile.
GETadmin/staff/{user}/editThe Edit dialog.
PUTadmin/staff/{user}Saves the Edit dialog.
PATCHadmin/staff/{user}/toggleDeactivates or reactivates (terminates or reinstates) somebody.
DELETEadmin/staff/{user}Deletes a member of staff.
GETadmin/staff/{user}/assignThe Assign work dialog.
GETadmin/staff/{user}/assign/tasksA project's open tasks for that dialog, as JSON (project_id); used by the page itself.
POSTadmin/staff/{user}/assignAssigns the chosen tasks and/or adds the person to the project team.
GETadmin/staff/{user}/permissionsOne person's permission overrides.
PUTadmin/staff/{user}/permissionsSaves them.
GETadmin/teamsOrganisation → Teams: the list of teams and their members.
GETadmin/teams/createThe New team dialog.
POSTadmin/teamsCreates a team with its members.
GETadmin/teams/{team}/editThe Edit team dialog.
PUTadmin/teams/{team}Saves a team's name, description and members.
DELETEadmin/teams/{team}Removes a team; its people stay.
GETadmin/rolesThe list of roles.
GETadmin/roles/createThe editor for a new role; ?preset=read-only opens it with the read-only preset.
POSTadmin/rolesCreates a role.
GETadmin/roles/{role}/editThe editor for an existing role.
PUTadmin/roles/{role}Saves a role.
POSTadmin/roles/{role}/cloneMakes a copy of a role and opens it.
DELETEadmin/roles/{role}Deletes a role nobody holds.