Permissions: roles, permission sets and the access check
How access fits together, how to apply a bundle of permissions to a whole department or team, and how to see exactly what one person can do and why.
Access is built from three layers, and Settings, then Permissions is the one place to see and change all of them.
- Roles are presets that cover most people.
- Permission sets are reusable bundles you can apply to a person, a whole department or a CRM team.
- Per-person overrides are the rare exceptions on top.
Roles
The Roles view lists every capability in plain language with a tick for each role that has it. Rows marked Sensitive expose cost, pay or private data and stay with admins unless you deliberately hand them out. Give someone the closest role first; reach for a set or an override only for what the role does not cover.
Permission sets
- Open Settings, then Permissions, and choose Permission sets.
- Create a set. Name it for the job it does, for example Bookkeeping or Media buyers, and tick the capabilities it should carry.
- Under Where each set applies, click Assign and tick departments, CRM teams, or individual people.
- Save. Everyone in a ticked department or team gets the set immediately.
Assigning a set to a department is the easiest way to give a new hire the right access: add them to the department and they inherit it.
Access check
Not sure what someone can actually do? Choose Access check, pick the person, and you get the full list of capabilities they hold with the reason next to each one: their role, a permission set and the department or team it came through, or a per-person grant. Grey rows are not held. From a person's page in Team, admins can jump straight to their access check.
Questions
Can a permission set take access away?
No. A set only adds. A capability revoked for a specific person stays revoked whatever sets they are in.
What happens when someone leaves a department?
They lose any set assigned to that department on their next page load. Nothing else about their account changes.
Is every change recorded?
Yes. Changes to sets and their assignments appear in the audit log with who made them and when.