Published at: 2026-09-17

Object and field permissions


Object and Field Permissions

Overview

BI object and field permissions inherit directly from the CRM business permission system. Object and field permissions already configured in CRM take effect automatically in BI, with no duplicate configuration. This inheritance keeps your permission policy consistent.

Core Rules

The BI platform inherits CRM business permissions. The objects and fields visible to users in charts match the CRM business side:
  • If you have the view list permission for an object in CRM, you can analyze data based on that object in BI.
  • If you have permission for a field in CRM, you can view that field’s values in BI.

How Missing Permissions Appear

When you lack object permission, you see the following in BI:
  • The object is not selectable when you create a report.
  • When you view a report whose primary business module is that object, you cannot view details.
  • When you view a report that uses that object as an associated module, you cannot see the object’s fields and statistics.
  • When you view the indicator details of a chart, you cannot view any fields.
When you lack field permission, you see the following in BI:
  • The field is not selectable when you configure a report.
  • When you view a report, the field displays as *****.
  • When you view the indicator details of a chart, the field displays as *****.
How missing object permissions appear Unable to view object details Unable to view fields in the associated module Unable to view fields in chart details Field not selectable when configuring a report Field displayed as masked

Before You Begin

[!IMPORTANT] - Role permissions: You need CRM admin permissions. - Scope of impact: Object and field permission changes take effect globally. They affect both CRM business lists and BI analysis.

Configure Object Permissions

BI object permissions inherit from CRM business object permissions. Configure them in CRM object permissions:
  1. Go to Setup > Role Permission Management > Manage Object Permissions.
  2. Select the target role.
  3. Find the object to configure.
  4. Assign permissions such as View List, View Details, New, Edit, and Delete.
  5. Click Save.

Configure Field Permissions

BI field permissions inherit from CRM field permissions. Configure them in CRM field permissions:
  1. Go to Setup > Role Permission Management > Manage Field Permissions.
  2. Select the target role and object.
  3. Find the field to configure.
  4. Assign visible or hidden permission.
  5. Click Save.

Special Objects

The following special objects have no independent object permission control. Their visibility depends on edition capabilities and process definition status:
Object Control Condition
Business Process Instance Enterprise edition includes the business process capability + an enabled process definition
Business Process Task Enterprise edition includes the business process capability + an enabled process definition
Approval Process Instance Enterprise edition includes the approval process capability + an enabled process definition
Approval Process Task Enterprise edition includes the approval process capability + an enabled process definition
Process Stage Enterprise edition includes the Stage Advancement (Pipeline) capability + an enabled process definition
Behavior Points Details Enterprise edition includes the behavior points capability + an enabled process definition
Special object permission configuration page
[!NOTE] BI visibility for the objects above is determined automatically by feature availability. If your enterprise edition includes the corresponding capability and an enabled process definition exists, these objects appear in the BI selection lists automatically.

Common Configuration Scenarios

Scenario 1: A user cannot see an object in charts

  1. Check whether the role has the view list permission for that object in CRM.
  2. If not, assign it to the role in the object permission configuration.
  3. Note: Once assigned, the permission takes effect in both CRM business lists and BI.

Scenario 2: A user cannot see the values of a field

  1. Check whether the role has the visible permission for that field in CRM.
  2. If not, assign it to the role in the field permission configuration.
  3. Without permission, the field displays as ***** in BI.

Scenario 3: A user should be able to select an object for analysis

Make sure the enterprise edition includes the capability the object belongs to, and that a process definition is enabled (if applicable).
Submit Feedback