Skip to content
Use caseGovernance and administrationAdvanced

Give each role exactly its access

Permissions, record scopes and analyst question grants — the three dimensions of access, and the order to set them in.

RRRevTech RevOpsRevenue operations team 3 min

The job

“I want to give every role the access it needs and nothing beyond it.”

  • Administrators
  • IT
  • RevOps

Access in a revenue system is unusually sensitive because most of it is commercial rather than technical. Whether a rep can see the whole company’s pipeline or only their own is not a security question so much as a compensation and culture question, and it is one that is much easier to set deliberately at the start than to tighten later.

The part teams miss is that access here has three dimensions, not one. What a role can do, which records it can do it to, and which company-level analyses it can open are set separately, and a role that is correct on the first two can still be wrong on the third.

What it moves

  • Permission adherence
  • Data exposure events

The division of labour

What RevTech does, and where you decide

Agent workApplies the role’s access consistently across every surface, including what work reaches whose queue
Human gateYou define the roles, the scopes and the grants
Workflow KPIPermission adherence

In the product

How to do it

  1. Step 1 of 5

    Start from the built-in roles

    There is a catalogue of roles covering the usual shapes — administrator, revenue operations, finance, seller, sales manager, marketer, marketing leader, customer success, customer success leader, executive and observer. Start from the closest one and adjust rather than building from empty.

  2. Step 2 of 5

    Set the permissions, then the scope

    Permissions say what a role can do. Scope says which records it can do it to on accounts, contacts and deals: none, their own, their team’s, or all. These are separate choices and the second is the one that decides how much of the business each person can see.

  3. Step 3 of 5

    Grant analyst questions explicitly

    Giving a role access to the Analyst opens a question picker, and the set chosen there is what that role can open — in the library, in search and in the assistant’s shortcuts. Company-level analyses are a reporting decision as much as a data one, so this is worth deciding rather than defaulting.

  4. Step 4 of 5

    Assign function alongside role

    A user carries a business function as well as a permission role, and the two are not the same thing. Function influences which prepared work reaches them; role decides what they may open. A user with the right role and the wrong function has correct access and the wrong queue.

  5. Step 5 of 5

    Off-board through archive, not deletion

    Archiving a user preserves the record of what they did, which is the point of having an audit trail at all. Roles can be archived too when a structure changes, and an archived role is excluded from new rule recipients rather than silently continuing to route work.

What to take away

  • Three dimensions: what a role can do, which records, and which analyses.
  • Scope is the commercial decision. Decide it deliberately at the start.
  • Function shapes the queue; role shapes access. Getting one right does not fix the other.
  • Archive rather than delete, or the audit trail loses the person it was about.
Demo

Try the demo.

See agents carry the repeatable work of GTM across sales, marketing, customer success, and RevOps. Every action prepared, reviewed, and recorded. Fictional data, real product.

Explore the demo