Published at: 2026-09-17

Data permissions


Data Permissions

Overview

BI data permissions inherit from CRM business data permissions. General subjects have the same data scope as CRM business lists. Special subjects (the personnel subject and the department subject) have their own control logic. Understanding these differences helps you configure permissions accurately and answer user questions.

Core Mechanism

Core objects and related objects:
  • Core object: Visible data permissions match CRM business permissions. They equal the data scope shown on the object list page.
  • Related object: If you can see the core object’s data, you can view the related object’s data in the chart. When you click to view the related object’s details, the related object’s own data permissions apply.
For child-object subjects (such as the Order Product subject), data permissions follow the parent object. If you can see an order, you can see its order product data.
Report admin privilege: Report admins can view all object data in charts. Data permissions do not restrict them.

Data Permission Scopes

Scope Description
Owned by Me Data owned by the current user
Owned by My Subordinates Data owned by the current user’s subordinates
Owned by Departments I Manage Data belonging to departments managed by the current user and their sub-departments
Shared With Me Data granted to the current user through permission sharing
All All of the above scopes

Special Subjects

Some subjects have special data permission rules:
  • Personnel subject: The data permission control logic is special. The Shared With Me scope takes the intersection of multiple indicators.
  • Department subject: Mainly applies to roles with broader permissions, such as department heads and management.
  • Account Pool and lead pools: You must create reports using specific templates.

Before You Begin

[!IMPORTANT] - Role permissions: You need CRM admin permissions. - Scope of impact: Data permission configuration affects both CRM business lists and BI analysis.

General Subject Data Permissions

General subjects (such as the account subject) have the same data permissions as CRM business data permissions. No extra configuration is needed in BI.
Scope Data Range
Owned by Me Data owned by the current user
Owned by My Subordinates Data owned by subordinates
Owned by Departments I Manage Data whose assigned department is a department managed by the current user or its sub-departments
Shared With Me Data shared with the current user through all sharing methods
All All of the above
General subject data permission scope settings
To adjust data permissions, go to Setup > Role Permission Management > Manage Data Permissions.

Special Subject Data Permissions

Personnel Subject

The personnel subject has a special data permission control logic:
Scope Description
Myself Data owned by the current user
My subordinates Data owned by subordinates
Owned by Departments I Manage Data whose data owner’s primary department is a department managed by the current user or its sub-departments
Shared With Me Counts only data shared by source. With multiple indicators, takes the intersection of the shared scopes across the indicator objects
All All of the above
[!WARNING] The personnel subject’s Shared With Me scope takes the intersection of multiple indicators. If the shared data scopes of the indicators have no intersection, none of the indicators is visible.
Personnel subject data permission example
Sharing Intersection Example
An admin shares the opportunities of the North China region, and the orders and payments of the South China region, with Amy. Amy selects Shared With Me in a personnel subject chart and sees no data. Reason: the intersection of the shared scopes for opportunities, orders, and payments is empty.
If the admin instead shares the opportunities of the Shenzhen branch with Amy, the intersection of the three objects’ shared scopes is the Shenzhen branch. Amy can now select Shared With Me and view all indicator data for the Shenzhen branch.
[!NOTE] Sharing a personnel object’s data does not grant access to all business data associated with that person. It only grants access to that person’s goal values and completion values.

Department Subject

The department subject applies to roles with broader permissions:
Role Visible Data
Report admin, CRM admin All department data
Department head Data of departments I manage
Department assistant Data of departments I assist
Regular employee Data shared based on the assigned department

Account Pool and Lead Pool Data Permissions

To analyze data in an Account Pool or lead pool, create reports using specific templates:
  • Account Pool Statistics: Create a report with this template. Data permissions match the Account Pool list page. The Visibility of the Affiliated Account Pool filter also matches the list page.
Account Pool Statistics template
  • Lead Summary by Lead Pool: The processing logic is the same as for the Account Pool.
Lead Summary by Lead Pool template

How to Verify

  1. Log in as employees with different roles.
  2. View the same public chart.
  3. Compare the visible data scopes across roles.
  4. If the data scope is unexpected, check the role’s data permission configuration.

Notes

  • Report admins can view all object data in charts.
  • Data permission changes take effect globally. They affect both CRM business lists and BI charts.
  • For related objects, indicator values are visible in the chart, but viewing details uses the related object’s own data permissions.
Submit Feedback