Permissions & Access Control
Category: Administration
Access Level: Organization Admins & Owners
Overview
Permissions define what users can see and do in D4D. Proper access control ensures security, accountability, and organizational efficiency.
Understanding Roles
Role Hierarchy
Organization Roles (Highest to Lowest):
- Owner - Full access, billing, can't be removed
- Admin - Full access except billing
- Manager - Team management, reports
- Team Lead - Team-level management
- Member - Standard user features
- Viewer - Read-only access
Inheritance:
- Higher roles include all lower role permissions
- Example: Admin can do everything Manager can do
- Owner is the exception (billing access)
Role Permissions Matrix
Owner
Can Do:
- ✅ Everything Admins can do
- ✅ Access billing and subscription
- ✅ Add/remove seats
- ✅ Upgrade/downgrade plan
- ✅ Cancel subscription
- ✅ Transfer ownership
- ✅ Delete organization
- ✅ View invoice history
- ✅ Update payment methods
Limitations:
- ❌ None (full access)
Notes:
- Only one Owner per organization
- Owner can transfer ownership to another Admin
- Owner cannot be removed by others
Admin
Can Do:
- ✅ Manage all organization settings (except billing)
- ✅ Add/remove/edit members
- ✅ Create/edit/delete teams
- ✅ Assign roles (including Admin)
- ✅ Access all organization data
- ✅ View all reports and analytics
- ✅ Manage integrations
- ✅ Configure gamification settings
- ✅ Create organization competitions
- ✅ Manage territories
- ✅ View audit logs
- ✅ Export organization data
- ✅ Manage privacy settings
- ✅ Configure lead policies
Limitations:
- ❌ Can't access billing/subscription
- ❌ Can't remove Owner
- ❌ Can't delete organization
Notes:
- Multiple Admins allowed
- Full administrative control
- Trusted role for leadership
Manager
Can Do:
- ✅ View organization-level reports
- ✅ Manage assigned teams (create, edit members)
- ✅ Assign Team Leads
- ✅ View all team data
- ✅ Create team competitions
- ✅ Assign territories to teams
- ✅ View member analytics
- ✅ Export team reports
- ✅ Manage team settings
- ✅ View organization leaderboards
Limitations:
- ❌ Can't manage organization settings
- ❌ Can't add/remove members from organization
- ❌ Can't change member roles (except to Team Lead within their teams)
- ❌ Can't access billing
- ❌ Can't manage integrations
- ❌ Can't configure organization-wide policies
- ❌ Can't delete teams they don't manage
- ❌ Can't view audit logs
Notes:
- Department managers in large orgs
- Team supervisors
- Can manage multiple teams
Team Lead
Can Do:
- ✅ Manage their team members (add, remove, within existing org members)
- ✅ Assign territories within team
- ✅ View team analytics
- ✅ Create team goals
- ✅ Manage team calendar
- ✅ Lead team chat
- ✅ Assign leads within team
- ✅ View team leaderboards
- ✅ Export team reports
- ✅ Manage team settings (limited)
Limitations:
- ❌ Can't change member roles
- ❌ Can't add new members to organization
- ❌ Can't access organization settings
- ❌ Can't manage other teams
- ❌ Can't create organization-wide competitions
- ❌ Can't manage integrations
- ❌ Can't view organization-wide analytics (only their team)
- ❌ Can't assign organization territories
Notes:
- Manages one team
- Frontline leadership
- Focused on team performance
Member
Can Do:
- ✅ Capture leads
- ✅ Manage own leads
- ✅ View own analytics
- ✅ Participate in gamification
- ✅ Join teams
- ✅ Use all standard features (map, routes, offline, etc.)
- ✅ View team leaderboards
- ✅ Participate in competitions
- ✅ Use social features
- ✅ Export own data
Limitations:
- ❌ Can't manage other members
- ❌ Can't view others' leads (unless shared)
- ❌ Can't access organization settings
- ❌ Can't manage teams
- ❌ Can't assign territories
- ❌ Can't view organization-wide analytics
- ❌ Can't create competitions
- ❌ Can't manage integrations
Notes:
- Standard user role
- Most users are Members
- Full feature access for personal use
Viewer
Can Do:
- ✅ View dashboards (limited)
- ✅ View reports (read-only)
- ✅ View leaderboards
- ✅ View organization analytics (if permitted)
- ✅ View team analytics (if on team)
- ✅ Export reports (read-only data)
Limitations:
- ❌ Can't capture leads
- ❌ Can't participate in gamification
- ❌ Can't create/edit any data
- ❌ Can't use map features
- ❌ Can't manage anything
- ❌ Can't participate in competitions (view only)
- ❌ Can't use social features
- ❌ Can't access settings
Notes:
- For stakeholders who need visibility but not active use
- Executives, investors, observers
- Minimal seat cost (typically half price)
Permission Categories
Lead Permissions
| Action | Owner | Admin | Manager | Team Lead | Member | Viewer |
|---|---|---|---|---|---|---|
| Capture leads | ✅ | ✅ | ✅ | ✅ | ✅ | ❌ |
| View own leads | ✅ | ✅ | ✅ | ✅ | ✅ | ❌ |
| View team leads | ✅ | ✅ | ✅ | ✅ | 🔶 | 🔶 |
| View all org leads | ✅ | ✅ | ✅ | ❌ | ❌ | ❌ |
| Edit own leads | ✅ | ✅ | ✅ | ✅ | ✅ | ❌ |
| Edit team leads | ✅ | ✅ | ✅ | ✅ | ❌ | ❌ |
| Delete own leads | ✅ | ✅ | ✅ | ✅ | ✅ | ❌ |
| Delete team leads | ✅ | ✅ | ✅ | ✅ | ❌ | ❌ |
| Export leads | ✅ | ✅ | ✅ | ✅ | ✅ | 🔶 |
| Assign leads | ✅ | ✅ | ✅ | ✅ | ❌ | ❌ |
🔶 = Depends on organization settings
Team Permissions
| Action | Owner | Admin | Manager | Team Lead | Member | Viewer |
|---|---|---|---|---|---|---|
| Create teams | ✅ | ✅ | ❌ | ❌ | ❌ | ❌ |
| Edit all teams | ✅ | ✅ | ❌ | ❌ | ❌ | ❌ |
| Edit assigned teams | ✅ | ✅ | ✅ | 🔶 | ❌ | ❌ |
| Delete teams | ✅ | ✅ | 🔶 | ❌ | ❌ | ❌ |
| Add members to team | ✅ | ✅ | ✅ | ✅ | ❌ | ❌ |
| Remove members from team | ✅ | ✅ | ✅ | ✅ | ❌ | ❌ |
| Assign Team Lead | ✅ | ✅ | ✅ | ❌ | ❌ | ❌ |
| View team analytics | ✅ | ✅ | ✅ | ✅ | 🔶 | 🔶 |
| Create team goals | ✅ | ✅ | ✅ | ✅ | ❌ | ❌ |
🔶 = Limited (own team only or with permissions)
Analytics Permissions
| Action | Owner | Admin | Manager | Team Lead | Member | Viewer |
|---|---|---|---|---|---|---|
| View own analytics | ✅ | ✅ | ✅ | ✅ | ✅ | ❌ |
| View team analytics | ✅ | ✅ | ✅ | ✅ | 🔶 | 🔶 |
| View org analytics | ✅ | ✅ | ✅ | ❌ | ❌ | 🔶 |
| Export own data | ✅ | ✅ | ✅ | ✅ | ✅ | ❌ |
| Export team data | ✅ | ✅ | ✅ | ✅ | ❌ | 🔶 |
| Export org data | ✅ | ✅ | ✅ | ❌ | ❌ | 🔶 |
| Create custom reports | ✅ | ✅ | ✅ | ✅ | ✅ | ❌ |
| Schedule reports | ✅ | ✅ | ✅ | ✅ | 🔶 | ❌ |
🔶 = Depends on organization settings
Settings Permissions
| Action | Owner | Admin | Manager | Team Lead | Member | Viewer |
|---|---|---|---|---|---|---|
| Org settings | ✅ | ✅ | ❌ | ❌ | ❌ | ❌ |
| Billing | ✅ | ❌ | ❌ | ❌ | ❌ | ❌ |
| Team settings | ✅ | ✅ | ✅ | 🔶 | ❌ | ❌ |
| Integrations | ✅ | ✅ | ❌ | ❌ | ❌ | ❌ |
| Lead policies | ✅ | ✅ | ❌ | ❌ | ❌ | ❌ |
| Gamification settings | ✅ | ✅ | ❌ | ❌ | ❌ | ❌ |
| Privacy settings | ✅ | ✅ | ❌ | ❌ | ❌ | ❌ |
| User settings (own) | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ |
🔶 = Own team only
Assigning Roles
How to Assign Roles
Organization Admin/Owner:
- Settings → Organization → Members
- Find member
- Click "Edit" (pencil icon)
- Select new role from dropdown
- Confirm (especially for Admin role)
- Save
Bulk Role Assignment:
- Settings → Organization → Members
- Select multiple members (checkboxes)
- "Bulk Actions" → "Change Role"
- Select new role
- Confirm
- Apply
Role Change Notifications
User Notified When:
- Role upgraded (promoted)
- Role downgraded (demoted)
- Role removed (back to Member)
Notification Includes:
- New role
- Who made change
- Effective immediately
- What they can now do (or can't do)
Custom Permissions (Enterprise)
Granular Control
Custom Permission Sets:
- Create custom roles beyond standard 6
- Mix and match permissions
- Role templates for common setups
- Per-team permission overrides
Example Custom Roles:
- Analyst: View all analytics, export data, but can't manage anything
- Territory Manager: Manage territories and assignments only
- Competition Coordinator: Create and manage competitions only
- Integrations Specialist: Manage integrations only
Create Custom Role:
- Settings → Organization → Roles → "Create Custom Role"
- Name role
- Select permissions from checklist
- Save
- Assign to members
Permission Overrides
Override Standard Permissions:
- Allow specific members extra permissions without full role change
- Example: Member can view team analytics
- Temporary overrides (expire after date)
Create Override:
- Settings → Organization → Members → Select Member
- "Permission Overrides"
- Select additional permissions
- Set expiration (optional)
- Save
Data Access Control
Lead Access
Lead Visibility Rules:
- Own leads: Always visible (captured by you)
- Team leads: Visible if on team and team sharing enabled
- Organization leads: Only Admins and Managers
- Shared leads: Visible if explicitly shared with you
Configure Lead Sharing:
- Settings → Organization → Privacy → Lead Access
- Select policy:
- Private: Members see only own leads
- Team: Members see team leads
- Organization: Members see all leads
- Save
Analytics Access
Who Sees What:
- Own analytics: Everyone sees their own
- Team analytics: Team members, Team Lead, Managers, Admins
- Org analytics: Managers, Admins, Owners (+ Viewers if permitted)
- Individual member analytics: That member, their Team Lead, Managers, Admins
Configure:
- Settings → Organization → Privacy → Analytics Access
- Toggle "Allow members to view team analytics"
- Toggle "Allow Viewers to access org analytics"
- Save
Territory Access
Territory Assignment
Territory Permissions:
- Owner/Admin: Manage all territories
- Manager: Manage assigned territories
- Team Lead: Assign territories to team members
- Member: Work assigned territories only
- Viewer: View territory maps (read-only)
Territory Restrictions:
- Prevent members from capturing outside assigned territory
- Warning if capturing outside territory
- Block if capturing outside territory
- No restriction (default)
Configure:
- Settings → Organization → Territories → Access Control
- Select restriction level
- Save
Feature Access
Gamification Access
Control Who Participates:
- Enable/disable gamification per member
- Exclude specific members from leaderboards
- Disable badges for individuals
- Opt-out of competitions
Why Disable:
- Member prefers no competition
- Role doesn't require gamification (Viewer, Admin)
- Focus on quality over quantity
Configure:
- Settings → Organization → Gamification → Member Access
- Select members to exclude
- Save
Integration Access
Who Can Connect Integrations:
- Owner, Admin only (default)
- Managers (optional)
- Members (not recommended)
Why Restrict:
- Security concerns
- Accidental disconnections
- Data integrity
Audit & Compliance
Audit Logs
Track All Actions:
- Member logins
- Role changes
- Data exports
- Setting changes
- Lead captures/edits/deletes
- Permission overrides
Access Audit Logs:
- Settings → Organization → Compliance → Audit Logs
- Filter by:
- Date range
- User
- Action type
- Resource (leads, teams, settings)
- Export log (CSV)
Retention:
- Standard: 90 days
- Professional: 1 year
- Enterprise: 7 years (compliance requirement)
Data Access Logs
Track Data Access:
- Who viewed what leads
- Who exported data
- Who viewed analytics
- When and from where (IP)
Use Cases:
- Security investigations
- Compliance audits
- Inappropriate access detection
Access:
- Settings → Organization → Compliance → Data Access Logs
- Search by member or resource
- View access history
- Export if needed
Security Features
Two-Factor Authentication (2FA)
Require 2FA:
- Organization-wide requirement
- For specific roles only (Owner, Admin, Manager)
- Optional but encouraged
Configure:
- Settings → Organization → Security → Two-Factor Auth
- Select requirement level
- Grace period for setup (7 days default)
- Enforce
Member Setup:
- Settings → Account → Security → Enable 2FA
- Scan QR code with authenticator app
- Enter verification code
- Save backup codes
Session Management
Session Controls:
- Session timeout (15 min to 24 hours)
- Concurrent session limit (1-5 devices)
- Auto-logout on browser close
- Remember device (30 days)
Configure:
- Settings → Organization → Security → Sessions
- Set timeout duration
- Set device limit
- Save
IP Restrictions (Enterprise)
Whitelist IP Addresses:
- Restrict access to specific IPs
- Office network only
- VPN required
- Exceptions for mobile
Configure:
- Settings → Organization → Security → IP Restrictions
- Add allowed IP addresses/ranges
- Set exceptions (Admins always allowed?)
- Save
Best Practices
🔐 Security Best Practices
Role Assignment:
- Principle of least privilege - Give minimum necessary permissions
- Regular reviews - Quarterly review role assignments
- Remove when not needed - Downgrade roles when job changes
- Limited Admins - Only trusted leadership
- No shared accounts - Each person has their own account
Access Control:
- Require 2FA - Especially for Admins
- Monitor audit logs - Regular review for anomalies
- Limit data exports - Control who can export
- Territory restrictions - Prevent unauthorized captures
- Session timeouts - Balance security and convenience
👥 Organizational Structure
Team Hierarchy:
- Clear reporting - Each team has Team Lead, rolls up to Manager
- Appropriate roles - Match role to responsibility
- Don't over-admin - Too many Admins creates confusion
- Empower Team Leads - Give them necessary permissions
- Support Members - Don't restrict unnecessarily
Troubleshooting
User Can't Access Feature
Symptoms: "You don't have permission" error
Solutions:
- Check role - Do they have right role?
- Check custom permissions - Any overrides?
- Check feature settings - Feature disabled org-wide?
- Check team assignment - Trying to access different team?
- Contact Admin - May need role change
Can't Change Role
Symptoms: Can't assign new role to user
Solutions:
- Check your permissions - Can you assign that role?
- Can't change Owner - Only Owner can transfer ownership
- Seat limits - New role requires seat?
- Already assigned - User already has role
- Refresh page - Try again
Data Not Visible
Symptoms: Expected data not showing
Solutions:
- Check data access settings - Lead sharing enabled?
- Check team assignment - Are you on same team?
- Check role - Do you have permission to view?
- Check filters - Accidental filter hiding data?
- Contact Admin - May need access granted
Related Guides
- Organization Management - Managing your organization
- Teams - Team management
- Privacy Features - Privacy settings