Understanding the Role Hierarchy: How Data Visibility Works
What is a role?#
A role controls record-level visibility — it determines which contacts, leads, deals, and other records each user can see. Roles are arranged in a hierarchy that mirrors your organisation's reporting structure. A user higher in the hierarchy can see records owned by every user below them in the same branch.
How the hierarchy works#
Picture your org chart. Every position becomes a role, and each role sits below its manager's role:
CEO / Owner ← Level 0 (top)
└── Sales Manager ← Level 1
├── Sales Rep (North) ← Level 2
└── Sales Rep (South) ← Level 2
└── Marketing Manager ← Level 1
└── Marketing Exec ← Level 2
Users higher in the tree (lower level number) can see records owned by everyone below them in the same branch. The CEO sees everything. The Sales Manager sees their own records plus those of both Sales Reps. A Sales Rep sees only their own.
What is a Parent Role?#
When you create a new role, you select a Parent Role — the role that sits directly above it in the hierarchy. This one selection is all that is needed to place the role correctly in the tree.
- Top-level role (e.g. CEO): leave Parent Role empty — select "No Parent (Top Level)"
- Sales Manager: select CEO as parent
- Sales Representative: select Sales Manager as parent
Hierarchy Level#
Every role has a Hierarchy Level — a number that shows how deep the role sits in the tree. It is calculated automatically when you save a role:
- A role with no parent gets the level you specify (default: 0)
- A role with a parent gets the parent's level + 1
The lower the hierarchy level number, the higher the authority. The system determines who is a "superior" by comparing hierarchy levels: a user whose role has a lower hierarchy level outranks a user with a higher hierarchy level — within the same branch.
System roles#
When a new organisation is created, AI Engage CRM automatically creates a Super Admin role. This is a system role and cannot be deleted or renamed. It sits at the top of the hierarchy and is assigned to the account owner by default.
Rules and restrictions#
- Cannot delete a role with child roles — reassign or delete the child roles first
- Cannot delete a role with assigned users — reassign the users to a different role first
- Cannot delete a system role — system roles are created by the platform and are protected
- One role per user — a user can only hold one role at a time; update their role in Settings → Users if their position changes
How parent roles connect to Sharing Rules#
Sharing Rules have an optional setting called Allow Superiors. When this is turned on, any user whose role has a lower hierarchy level (i.e. higher authority) than the rule's target role automatically gets access too — without being explicitly listed in the sharing rule. This lets senior users see cross-branch records when a rule grants access to their subordinates.
Ready to implement this?
OpenAI Engage and apply what you just learned to your own workspace.
Open AI Engage CRM