Published at: 2026-09-17
Interconnection scenario permissions
Interconnection Scenario Permissions
Overview
Interconnection scenarios enable data collaboration between upstream and downstream enterprises, such as brand owners and distributors. Upstream admins can assign BI charts to downstream users for viewing, and the system handles permission conversion automatically. Downstream users see business data without extra configuration, enabling cross-enterprise data insight.
Permission Mechanism
Upstream permissions: When a CRM admin sets up a homepage or portal for a downstream enterprise, they can add charts. The selectable chart scope is limited by the object visibility scope of External Apps.
Special objects not yet supported: personnel, department, business process, approval process, process stage, and behavior points details.
Downstream permissions: When downstream personnel view charts assigned from upstream, they can View Details of charts, filter and drill into data, view detail data, and export charts.
Automatic permission conversion: When a downstream user views a chart, the system converts permissions automatically:
- Object permissions: Follow the object permissions of the downstream user’s role in the downstream enterprise.
- Data permissions: The system switches to the downstream identity automatically and applies the downstream user’s business data permissions in the downstream enterprise.
Permission Conversion Chain
Upstream admin
└→ Selects available charts (limited by the External Apps object visibility scope)
└→ Assigns to the downstream homepage or portal
└→ Downstream user views
├→ Object permissions → follow the downstream role's permissions downstream
└→ Data permissions → automatically switch to downstream identity → follow downstream data permissions
Before You Begin
[!IMPORTANT] - Role permissions: You need CRM admin permissions in the upstream system. - Prerequisite configuration: External Apps and the upstream-downstream relationship have been set up.
Upstream: Assign Charts
- Log in to the upstream system as a CRM admin.
- Open the downstream homepage or portal configuration page.
- Click Add Chart.
- Select the target chart from the chart list.
- Add the chart to the homepage layout.
- Save the configuration.
Chart Selection Scope
Selectable charts are limited as follows:
- The chart’s core analysis object must be an object visible to External Apps.
- Different External Apps have different visible object scopes, so the selectable chart scopes differ.
- Objects not yet supported: personnel, department, business process, approval process, process stage, and behavior points details.
Downstream: Automatic Permission Conversion
Object Permission Conversion
When a downstream user views a chart, object permissions follow the downstream role’s permission configuration in the downstream enterprise. The logic matches upstream object permission control, but the downstream business configuration takes precedence.
Data Permission Conversion
The system switches the upstream identity to the downstream identity automatically. When a downstream user views a chart, data permissions follow the downstream user’s business data permissions in the downstream enterprise. The logic matches upstream data permissions.
Upstream admins do not need to configure BI permissions separately for downstream users. Permission conversion is completed automatically by the system.
Operations Available to Downstream Users
Downstream users with assigned charts can:
- View Details of charts.
- Filter chart data.
- Drill down into more granular data.
- View detail data.
- Export chart data.
Downstream users cannot perform management operations such as Edit, Delete, or Share.
Notes
- Different External Apps offer different selectable chart scopes. Confirm the scope when assigning.
- Permission conversion runs automatically. No extra configuration is needed.
- Downstream users are limited to View Details, filtering, drilling down, viewing detail data, and exporting.