Users, Roles & Permissions
Access granted per object, with reading, changing, deleting and sharing as separate decisions, plus queue ownership for shared work and de-provisioning that takes effect immediately.
Illustrative UI only. Data and individuals shown are fictitious; any resemblance to real persons or data is coincidental.
Granted per object, not globally
A role grants reading, creating, editing, deleting and sharing separately, per record type, so least privilege is the natural shape of a role, not something achieved with workarounds.
Seeing and changing are separate
View-all and modify-all are independent grants, per object. "Can see the whole book" never silently implies "can change the whole book."
Ownership doesn't have to be a person
Records can be owned by a queue the whole team works: a real lead pool with members and rules, not a dummy user whose password everyone happens to know.
Access ends immediately
De-provisioning a user cuts their sessions on every server the moment it lands, not at their next login, and not whenever a cache happens to expire.
Why we like this one
The test of an access model is the discipline it imposes on its own house. The website's machine account runs least-privilege here: it can create a lead, and it cannot read the book. When a platform treats its own integrations with that much suspicion, and cuts a departed user's sessions everywhere the moment they're de-provisioned, the grants you give people actually mean something.
Book a demo ➝