Published at: 2026-09-17
Data permissions
Data Permissions
Overview
BI data permissions inherit from CRM business data permissions. General subjects have the same data scope as CRM business lists. Special subjects (the personnel subject and the department subject) have their own control logic. Understanding these differences helps you configure permissions accurately and answer user questions.
Core Mechanism
Core objects and related objects:
- Core object: Visible data permissions match CRM business permissions. They equal the data scope shown on the object list page.
- Related object: If you can see the core object’s data, you can view the related object’s data in the chart. When you click to view the related object’s details, the related object’s own data permissions apply.
For child-object subjects (such as the Order Product subject), data permissions follow the parent object. If you can see an order, you can see its order product data.
Report admin privilege: Report admins can view all object data in charts. Data permissions do not restrict them.
Data Permission Scopes
| Scope | Description |
|---|---|
| Owned by Me | Data owned by the current user |
| Owned by My Subordinates | Data owned by the current user’s subordinates |
| Owned by Departments I Manage | Data belonging to departments managed by the current user and their sub-departments |
| Shared With Me | Data granted to the current user through permission sharing |
| All | All of the above scopes |
Special Subjects
Some subjects have special data permission rules:
- Personnel subject: The data permission control logic is special. The Shared With Me scope takes the intersection of multiple indicators.
- Department subject: Mainly applies to roles with broader permissions, such as department heads and management.
- Account Pool and lead pools: You must create reports using specific templates.
Before You Begin
[!IMPORTANT] - Role permissions: You need CRM admin permissions. - Scope of impact: Data permission configuration affects both CRM business lists and BI analysis.
General Subject Data Permissions
General subjects (such as the account subject) have the same data permissions as CRM business data permissions. No extra configuration is needed in BI.
| Scope | Data Range |
|---|---|
| Owned by Me | Data owned by the current user |
| Owned by My Subordinates | Data owned by subordinates |
| Owned by Departments I Manage | Data whose assigned department is a department managed by the current user or its sub-departments |
| Shared With Me | Data shared with the current user through all sharing methods |
| All | All of the above |

To adjust data permissions, go to Setup > Role Permission Management > Manage Data Permissions.
Special Subject Data Permissions
Personnel Subject
The personnel subject has a special data permission control logic:
| Scope | Description |
|---|---|
| Myself | Data owned by the current user |
| My subordinates | Data owned by subordinates |
| Owned by Departments I Manage | Data whose data owner’s primary department is a department managed by the current user or its sub-departments |
| Shared With Me | Counts only data shared by source. With multiple indicators, takes the intersection of the shared scopes across the indicator objects |
| All | All of the above |
[!WARNING] The personnel subject’s Shared With Me scope takes the intersection of multiple indicators. If the shared data scopes of the indicators have no intersection, none of the indicators is visible.

Sharing Intersection Example
An admin shares the opportunities of the North China region, and the orders and payments of the South China region, with Amy. Amy selects Shared With Me in a personnel subject chart and sees no data. Reason: the intersection of the shared scopes for opportunities, orders, and payments is empty.
If the admin instead shares the opportunities of the Shenzhen branch with Amy, the intersection of the three objects’ shared scopes is the Shenzhen branch. Amy can now select Shared With Me and view all indicator data for the Shenzhen branch.
[!NOTE] Sharing a personnel object’s data does not grant access to all business data associated with that person. It only grants access to that person’s goal values and completion values.
Department Subject
The department subject applies to roles with broader permissions:
| Role | Visible Data |
|---|---|
| Report admin, CRM admin | All department data |
| Department head | Data of departments I manage |
| Department assistant | Data of departments I assist |
| Regular employee | Data shared based on the assigned department |
Account Pool and Lead Pool Data Permissions
To analyze data in an Account Pool or lead pool, create reports using specific templates:
- Account Pool Statistics: Create a report with this template. Data permissions match the Account Pool list page. The Visibility of the Affiliated Account Pool filter also matches the list page.

- Lead Summary by Lead Pool: The processing logic is the same as for the Account Pool.

How to Verify
- Log in as employees with different roles.
- View the same public chart.
- Compare the visible data scopes across roles.
- If the data scope is unexpected, check the role’s data permission configuration.
Notes
- Report admins can view all object data in charts.
- Data permission changes take effect globally. They affect both CRM business lists and BI charts.
- For related objects, indicator values are visible in the chart, but viewing details uses the related object’s own data permissions.