Permissions & Access Control Guide

Permissions & Access Control

Category: Administration
Access Level: Organization Admins & Owners


Overview

Permissions define what users can see and do in D4D. Proper access control ensures security, accountability, and organizational efficiency.


Understanding Roles

Role Hierarchy

Organization Roles (Highest to Lowest):

  1. Owner - Full access, billing, can't be removed
  2. Admin - Full access except billing
  3. Manager - Team management, reports
  4. Team Lead - Team-level management
  5. Member - Standard user features
  6. Viewer - Read-only access

Inheritance:

  • Higher roles include all lower role permissions
  • Example: Admin can do everything Manager can do
  • Owner is the exception (billing access)

Role Permissions Matrix

Owner

Can Do:

  • ✅ Everything Admins can do
  • ✅ Access billing and subscription
  • ✅ Add/remove seats
  • ✅ Upgrade/downgrade plan
  • ✅ Cancel subscription
  • ✅ Transfer ownership
  • ✅ Delete organization
  • ✅ View invoice history
  • ✅ Update payment methods

Limitations:

  • ❌ None (full access)

Notes:

  • Only one Owner per organization
  • Owner can transfer ownership to another Admin
  • Owner cannot be removed by others

Admin

Can Do:

  • ✅ Manage all organization settings (except billing)
  • ✅ Add/remove/edit members
  • ✅ Create/edit/delete teams
  • ✅ Assign roles (including Admin)
  • ✅ Access all organization data
  • ✅ View all reports and analytics
  • ✅ Manage integrations
  • ✅ Configure gamification settings
  • ✅ Create organization competitions
  • ✅ Manage territories
  • ✅ View audit logs
  • ✅ Export organization data
  • ✅ Manage privacy settings
  • ✅ Configure lead policies

Limitations:

  • ❌ Can't access billing/subscription
  • ❌ Can't remove Owner
  • ❌ Can't delete organization

Notes:

  • Multiple Admins allowed
  • Full administrative control
  • Trusted role for leadership

Manager

Can Do:

  • ✅ View organization-level reports
  • ✅ Manage assigned teams (create, edit members)
  • ✅ Assign Team Leads
  • ✅ View all team data
  • ✅ Create team competitions
  • ✅ Assign territories to teams
  • ✅ View member analytics
  • ✅ Export team reports
  • ✅ Manage team settings
  • ✅ View organization leaderboards

Limitations:

  • ❌ Can't manage organization settings
  • ❌ Can't add/remove members from organization
  • ❌ Can't change member roles (except to Team Lead within their teams)
  • ❌ Can't access billing
  • ❌ Can't manage integrations
  • ❌ Can't configure organization-wide policies
  • ❌ Can't delete teams they don't manage
  • ❌ Can't view audit logs

Notes:

  • Department managers in large orgs
  • Team supervisors
  • Can manage multiple teams

Team Lead

Can Do:

  • ✅ Manage their team members (add, remove, within existing org members)
  • ✅ Assign territories within team
  • ✅ View team analytics
  • ✅ Create team goals
  • ✅ Manage team calendar
  • ✅ Lead team chat
  • ✅ Assign leads within team
  • ✅ View team leaderboards
  • ✅ Export team reports
  • ✅ Manage team settings (limited)

Limitations:

  • ❌ Can't change member roles
  • ❌ Can't add new members to organization
  • ❌ Can't access organization settings
  • ❌ Can't manage other teams
  • ❌ Can't create organization-wide competitions
  • ❌ Can't manage integrations
  • ❌ Can't view organization-wide analytics (only their team)
  • ❌ Can't assign organization territories

Notes:

  • Manages one team
  • Frontline leadership
  • Focused on team performance

Member

Can Do:

  • ✅ Capture leads
  • ✅ Manage own leads
  • ✅ View own analytics
  • ✅ Participate in gamification
  • ✅ Join teams
  • ✅ Use all standard features (map, routes, offline, etc.)
  • ✅ View team leaderboards
  • ✅ Participate in competitions
  • ✅ Use social features
  • ✅ Export own data

Limitations:

  • ❌ Can't manage other members
  • ❌ Can't view others' leads (unless shared)
  • ❌ Can't access organization settings
  • ❌ Can't manage teams
  • ❌ Can't assign territories
  • ❌ Can't view organization-wide analytics
  • ❌ Can't create competitions
  • ❌ Can't manage integrations

Notes:

  • Standard user role
  • Most users are Members
  • Full feature access for personal use

Viewer

Can Do:

  • ✅ View dashboards (limited)
  • ✅ View reports (read-only)
  • ✅ View leaderboards
  • ✅ View organization analytics (if permitted)
  • ✅ View team analytics (if on team)
  • ✅ Export reports (read-only data)

Limitations:

  • ❌ Can't capture leads
  • ❌ Can't participate in gamification
  • ❌ Can't create/edit any data
  • ❌ Can't use map features
  • ❌ Can't manage anything
  • ❌ Can't participate in competitions (view only)
  • ❌ Can't use social features
  • ❌ Can't access settings

Notes:

  • For stakeholders who need visibility but not active use
  • Executives, investors, observers
  • Minimal seat cost (typically half price)

Permission Categories

Lead Permissions

ActionOwnerAdminManagerTeam LeadMemberViewer
Capture leads
View own leads
View team leads🔶🔶
View all org leads
Edit own leads
Edit team leads
Delete own leads
Delete team leads
Export leads🔶
Assign leads

🔶 = Depends on organization settings

Team Permissions

ActionOwnerAdminManagerTeam LeadMemberViewer
Create teams
Edit all teams
Edit assigned teams🔶
Delete teams🔶
Add members to team
Remove members from team
Assign Team Lead
View team analytics🔶🔶
Create team goals

🔶 = Limited (own team only or with permissions)

Analytics Permissions

ActionOwnerAdminManagerTeam LeadMemberViewer
View own analytics
View team analytics🔶🔶
View org analytics🔶
Export own data
Export team data🔶
Export org data🔶
Create custom reports
Schedule reports🔶

🔶 = Depends on organization settings

Settings Permissions

ActionOwnerAdminManagerTeam LeadMemberViewer
Org settings
Billing
Team settings🔶
Integrations
Lead policies
Gamification settings
Privacy settings
User settings (own)

🔶 = Own team only


Assigning Roles

How to Assign Roles

Organization Admin/Owner:

  1. Settings → Organization → Members
  2. Find member
  3. Click "Edit" (pencil icon)
  4. Select new role from dropdown
  5. Confirm (especially for Admin role)
  6. Save

Bulk Role Assignment:

  1. Settings → Organization → Members
  2. Select multiple members (checkboxes)
  3. "Bulk Actions" → "Change Role"
  4. Select new role
  5. Confirm
  6. Apply

Role Change Notifications

User Notified When:

  • Role upgraded (promoted)
  • Role downgraded (demoted)
  • Role removed (back to Member)

Notification Includes:

  • New role
  • Who made change
  • Effective immediately
  • What they can now do (or can't do)

Custom Permissions (Enterprise)

Granular Control

Custom Permission Sets:

  • Create custom roles beyond standard 6
  • Mix and match permissions
  • Role templates for common setups
  • Per-team permission overrides

Example Custom Roles:

  • Analyst: View all analytics, export data, but can't manage anything
  • Territory Manager: Manage territories and assignments only
  • Competition Coordinator: Create and manage competitions only
  • Integrations Specialist: Manage integrations only

Create Custom Role:

  1. Settings → Organization → Roles → "Create Custom Role"
  2. Name role
  3. Select permissions from checklist
  4. Save
  5. Assign to members

Permission Overrides

Override Standard Permissions:

  • Allow specific members extra permissions without full role change
  • Example: Member can view team analytics
  • Temporary overrides (expire after date)

Create Override:

  1. Settings → Organization → Members → Select Member
  2. "Permission Overrides"
  3. Select additional permissions
  4. Set expiration (optional)
  5. Save

Data Access Control

Lead Access

Lead Visibility Rules:

  • Own leads: Always visible (captured by you)
  • Team leads: Visible if on team and team sharing enabled
  • Organization leads: Only Admins and Managers
  • Shared leads: Visible if explicitly shared with you

Configure Lead Sharing:

  1. Settings → Organization → Privacy → Lead Access
  2. Select policy:
    • Private: Members see only own leads
    • Team: Members see team leads
    • Organization: Members see all leads
  3. Save

Analytics Access

Who Sees What:

  • Own analytics: Everyone sees their own
  • Team analytics: Team members, Team Lead, Managers, Admins
  • Org analytics: Managers, Admins, Owners (+ Viewers if permitted)
  • Individual member analytics: That member, their Team Lead, Managers, Admins

Configure:

  1. Settings → Organization → Privacy → Analytics Access
  2. Toggle "Allow members to view team analytics"
  3. Toggle "Allow Viewers to access org analytics"
  4. Save

Territory Access

Territory Assignment

Territory Permissions:

  • Owner/Admin: Manage all territories
  • Manager: Manage assigned territories
  • Team Lead: Assign territories to team members
  • Member: Work assigned territories only
  • Viewer: View territory maps (read-only)

Territory Restrictions:

  • Prevent members from capturing outside assigned territory
  • Warning if capturing outside territory
  • Block if capturing outside territory
  • No restriction (default)

Configure:

  1. Settings → Organization → Territories → Access Control
  2. Select restriction level
  3. Save

Feature Access

Gamification Access

Control Who Participates:

  • Enable/disable gamification per member
  • Exclude specific members from leaderboards
  • Disable badges for individuals
  • Opt-out of competitions

Why Disable:

  • Member prefers no competition
  • Role doesn't require gamification (Viewer, Admin)
  • Focus on quality over quantity

Configure:

  1. Settings → Organization → Gamification → Member Access
  2. Select members to exclude
  3. Save

Integration Access

Who Can Connect Integrations:

  • Owner, Admin only (default)
  • Managers (optional)
  • Members (not recommended)

Why Restrict:

  • Security concerns
  • Accidental disconnections
  • Data integrity

Audit & Compliance

Audit Logs

Track All Actions:

  • Member logins
  • Role changes
  • Data exports
  • Setting changes
  • Lead captures/edits/deletes
  • Permission overrides

Access Audit Logs:

  1. Settings → Organization → Compliance → Audit Logs
  2. Filter by:
    • Date range
    • User
    • Action type
    • Resource (leads, teams, settings)
  3. Export log (CSV)

Retention:

  • Standard: 90 days
  • Professional: 1 year
  • Enterprise: 7 years (compliance requirement)

Data Access Logs

Track Data Access:

  • Who viewed what leads
  • Who exported data
  • Who viewed analytics
  • When and from where (IP)

Use Cases:

  • Security investigations
  • Compliance audits
  • Inappropriate access detection

Access:

  1. Settings → Organization → Compliance → Data Access Logs
  2. Search by member or resource
  3. View access history
  4. Export if needed

Security Features

Two-Factor Authentication (2FA)

Require 2FA:

  • Organization-wide requirement
  • For specific roles only (Owner, Admin, Manager)
  • Optional but encouraged

Configure:

  1. Settings → Organization → Security → Two-Factor Auth
  2. Select requirement level
  3. Grace period for setup (7 days default)
  4. Enforce

Member Setup:

  • Settings → Account → Security → Enable 2FA
  • Scan QR code with authenticator app
  • Enter verification code
  • Save backup codes

Session Management

Session Controls:

  • Session timeout (15 min to 24 hours)
  • Concurrent session limit (1-5 devices)
  • Auto-logout on browser close
  • Remember device (30 days)

Configure:

  1. Settings → Organization → Security → Sessions
  2. Set timeout duration
  3. Set device limit
  4. Save

IP Restrictions (Enterprise)

Whitelist IP Addresses:

  • Restrict access to specific IPs
  • Office network only
  • VPN required
  • Exceptions for mobile

Configure:

  1. Settings → Organization → Security → IP Restrictions
  2. Add allowed IP addresses/ranges
  3. Set exceptions (Admins always allowed?)
  4. Save

Best Practices

🔐 Security Best Practices

Role Assignment:

  1. Principle of least privilege - Give minimum necessary permissions
  2. Regular reviews - Quarterly review role assignments
  3. Remove when not needed - Downgrade roles when job changes
  4. Limited Admins - Only trusted leadership
  5. No shared accounts - Each person has their own account

Access Control:

  1. Require 2FA - Especially for Admins
  2. Monitor audit logs - Regular review for anomalies
  3. Limit data exports - Control who can export
  4. Territory restrictions - Prevent unauthorized captures
  5. Session timeouts - Balance security and convenience

👥 Organizational Structure

Team Hierarchy:

  1. Clear reporting - Each team has Team Lead, rolls up to Manager
  2. Appropriate roles - Match role to responsibility
  3. Don't over-admin - Too many Admins creates confusion
  4. Empower Team Leads - Give them necessary permissions
  5. Support Members - Don't restrict unnecessarily

Troubleshooting

User Can't Access Feature

Symptoms: "You don't have permission" error

Solutions:

  1. Check role - Do they have right role?
  2. Check custom permissions - Any overrides?
  3. Check feature settings - Feature disabled org-wide?
  4. Check team assignment - Trying to access different team?
  5. Contact Admin - May need role change

Can't Change Role

Symptoms: Can't assign new role to user

Solutions:

  1. Check your permissions - Can you assign that role?
  2. Can't change Owner - Only Owner can transfer ownership
  3. Seat limits - New role requires seat?
  4. Already assigned - User already has role
  5. Refresh page - Try again

Data Not Visible

Symptoms: Expected data not showing

Solutions:

  1. Check data access settings - Lead sharing enabled?
  2. Check team assignment - Are you on same team?
  3. Check role - Do you have permission to view?
  4. Check filters - Accidental filter hiding data?
  5. Contact Admin - May need access granted


← Back to Organization | Next: Keyboard Shortcuts →

Was this guide helpful?

New to the strategy behind the product? Read the complete driving for dollars guide on drivingfordollars.pro.