Knowledge
KnowledgeBase

Understanding the Role Hierarchy: How Data Visibility Works

What is a role?#

A role controls record-level visibility — it determines which contacts, leads, deals, and other records each user can see. Roles are arranged in a hierarchy that mirrors your organisation's reporting structure. A user higher in the hierarchy can see records owned by every user below them in the same branch.

ℹ️
Role vs Profile: A Role controls visibility (whose records can I see?). A Profile controls permissions (what can I do with those records — create, edit, delete?). Every user needs both a role and a profile.

How the hierarchy works#

Picture your org chart. Every position becomes a role, and each role sits below its manager's role:

CEO / Owner                  ← Level 0 (top)
 └── Sales Manager           ← Level 1
       ├── Sales Rep (North) ← Level 2
       └── Sales Rep (South) ← Level 2
 └── Marketing Manager       ← Level 1
       └── Marketing Exec    ← Level 2

Users higher in the tree (lower level number) can see records owned by everyone below them in the same branch. The CEO sees everything. The Sales Manager sees their own records plus those of both Sales Reps. A Sales Rep sees only their own.

💡
Hierarchy visibility only flows downward within the same branch. Sales Manager cannot see Marketing Manager's records and vice versa. Use Sharing Rules to open access across separate branches.

What is a Parent Role?#

When you create a new role, you select a Parent Role — the role that sits directly above it in the hierarchy. This one selection is all that is needed to place the role correctly in the tree.

  • Top-level role (e.g. CEO): leave Parent Role empty — select "No Parent (Top Level)"
  • Sales Manager: select CEO as parent
  • Sales Representative: select Sales Manager as parent
💡
Build your hierarchy top-down. Create the CEO role first, then manager roles, then individual contributor roles. A parent must exist before you can assign it to a child role.
⚠️
The system prevents two types of invalid parent assignments: self-parenting (a role cannot be its own parent) and circular hierarchies (a role cannot be set as the parent of one of its own ancestors).

Hierarchy Level#

Every role has a Hierarchy Level — a number that shows how deep the role sits in the tree. It is calculated automatically when you save a role:

  • A role with no parent gets the level you specify (default: 0)
  • A role with a parent gets the parent's level + 1
Role Parent Role Hierarchy Level Can see records owned by CEO None 0 Everyone in the entire CRM Sales Manager CEO 1 Themselves + all Sales Representatives Sales Representative Sales Manager 2 Only records assigned to themselves

The lower the hierarchy level number, the higher the authority. The system determines who is a "superior" by comparing hierarchy levels: a user whose role has a lower hierarchy level outranks a user with a higher hierarchy level — within the same branch.

ℹ️
You can see each role's level in the Level column on the Roles list page. You do not need to set it manually — it updates automatically whenever you change a role's parent.

System roles#

When a new organisation is created, AI Engage CRM automatically creates a Super Admin role. This is a system role and cannot be deleted or renamed. It sits at the top of the hierarchy and is assigned to the account owner by default.

⚠️
System roles are protected. You can create additional roles beneath Super Admin, but you cannot delete or modify the system role itself.

Rules and restrictions#

  • Cannot delete a role with child roles — reassign or delete the child roles first
  • Cannot delete a role with assigned users — reassign the users to a different role first
  • Cannot delete a system role — system roles are created by the platform and are protected
  • One role per user — a user can only hold one role at a time; update their role in Settings → Users if their position changes

How parent roles connect to Sharing Rules#

Sharing Rules have an optional setting called Allow Superiors. When this is turned on, any user whose role has a lower hierarchy level (i.e. higher authority) than the rule's target role automatically gets access too — without being explicitly listed in the sharing rule. This lets senior users see cross-branch records when a rule grants access to their subordinates.

Once you have created your role hierarchy and assigned users to roles, data visibility is enforced automatically. No extra configuration is needed — users see only the records they should, based on where they sit in the tree.

Ready to implement this?

OpenAI Engage and apply what you just learned to your own workspace.

Open AI Engage CRM