Knowledge
KnowledgeBase

Understanding Profile Permissions: What Every Setting Controls

A Profile in AI Engage CRM controls exactly what each user can see and do. Every profile has two independent layers of permissions that work together:

  • Module Permissions — controls which records a user can access, and what actions they can take on those records.

  • Feature Permissions — controls access to specific system features like Reports, Dashboards, Workflows, and Settings sections.

💡
Both layers must be configured. A user could have full module access but still be blocked from a feature — or vice versa — if only one layer is set up.

Part 1: Module Permissions#

The Module Permissions table lists every active module in your CRM (Contacts, Deals, Tasks, Campaigns, etc.). For each module, you configure six independent permissions:

Part 1: Module Permissions

View — access level dropdown#

Controls which records the user can see in this module. Choose from:

  • All — the user sees every record in the module, regardless of owner.

  • Team — the user sees only records owned by members of their team.

  • Own — the user sees only records they personally own.

  • None — the module is completely hidden from this user.

View — access level dropdown
💡
The View level acts as the base filter for all other permissions. If View is set to Own, the user can only Edit or Delete records they own — even if Edit is set to All.

Edit — access level dropdown#

Controls which records this user can update. Uses the same four levels as View: All / Team / Own / None. Setting Edit to None makes all records open in read-only mode.

Delete — access level dropdown#

Controls which records this user can permanently delete. Uses All / Team / Own / None. Deleted records are hard to recover — set Delete to None for most users and restrict it to admins or senior managers only.

Create — checkbox#

When ticked, the user can add new records to this module (the + New button appears). When unticked, they cannot create new records.

Export — checkbox#

When ticked, the user can download records from this module as a CSV or Excel file. Turn this off for roles that should not take data out of the system.

Import — checkbox#

When ticked, the user can bulk-import records into this module via a spreadsheet. Typically limited to admins and data managers.

💡
Recommended defaults for most staff:
View = Team,
Edit = Own
Create = ✅
Delete = None
Export = ☐
Import = ✅.

Only Admin profiles should have Delete access or Export/Import rights.


Part 2: Feature Permissions#

Feature Permissions are individual system capabilities, each controlled by an on/off checkbox. They are organised into groups. Below are the most commonly used permissions; depending on your plan and edition your CRM may show additional groups such as Marketing, Web Forms, Inbox & Channels, Automation, and Integrations.

Part 2: Feature Permissions

📊 Report Management#

  • Read Only Reports — View saved reports and run them in preview mode. Cannot create, edit, delete, share, or manage templates.

  • Manage Reports — Create, edit, delete, share, and manage report templates. Implies read access.

  • Export Reports — Download report results as CSV / Excel.

💡
Give most managers Read Only Reports. Only give Manage Reports to the person responsible for building and maintaining the report library.

📋 Dashboard Management#

  • Read-Only Dashboards — View dashboards and their components. Cannot create, edit, share, favourite, or manage components.

  • Manage Dashboards — Create, edit, delete, share, favourite, and manage components on dashboards. Implies read access.

  • Export Dashboards — Export dashboard data and components.

👤 User & Access#

  • User Management — Manage users, create, edit, and delete user accounts.

  • Role Management — Manage roles and role hierarchy.

  • Team Management — Manage teams and team members.

  • Sharing Rules — Configure data sharing rules.

💡
Only Admin profiles should have User & Access permissions enabled. These controls let someone invite new users, change roles, and modify who sees what across your entire CRM.

📦 Modules#

  • Module Customization — Create, edit, and delete modules, and customize their fields and layouts. This one permission controls everything in Modules & Fields.

💡
Module Customization is the permission to grant for building your CRM — it lets someone add custom fields, rearrange layouts, and create or delete modules. Grant it only to admins. (An older Module Management permission has been retired and is no longer used.)

⚙️ Workflows#

  • Workflow Management — Create and manage workflows and automations.

How the two layers interact#

Think of Module Permissions as the data gate and Feature Permissions as the tool gate:

  • A user with View = None on Contacts cannot see any contact records — regardless of feature permissions.

  • A user with Manage Reports = off cannot open the report builder — even if their module view access is full.

  • An Admin profile typically has all module permissions set to All and all feature permissions enabled.

  • A Sales Rep profile typically has Contacts/Deals/Tasks set to Team view, with only Read Only Reports and Read Only Dashboards enabled — no User & Access, no Module Customization.

💡
Changes to a profile take effect immediately for every user assigned to it — there is no publish step. If you need to test a permission change without affecting live users, create a test profile first, assign it to a test user, verify, then apply it to the real profile.

Ready to implement this?

OpenAI Engage and apply what you just learned to your own workspace.

Open AI Engage CRM