Published at: 2026-09-17
Organization and permissions overview
Learn about the platform’s organization management and permission control design and core capabilities.
Business value
In enterprise applications, a sound Org Structure, granular permissions, and a robust security foundation protect core business data and support efficient collaboration across departments. The platform provides flexible Org Structure configuration and multi-level data and function-level isolation. This helps you maximize operational efficiency while maintaining security.
Core capabilities
The platform provides the following organization and permissions management areas:
| Management area | Core capabilities | Business value |
|---|---|---|
| Organization management | Maintain multi-level departments and employee accounts, and enable multi-organization management. | Map reporting relationships and establish the administrative foundation for employee ownership. |
| Function permissions | Use role-based access control (RBAC) to assign menu and operation permissions by business role and management role. | Ensure that employees can use only the function buttons required for their responsibilities. |
| Data permissions | Control basic data permissions, department data permissions, data sharing rules, related teams, and temporary permissions. | Control record-level and field-level visibility and protect customer asset privacy. |
Core use cases
1. Function permission isolation
Employees in an enterprise have different responsibilities, such as sales, customer service, and finance:
- Sales representatives can view and use business modules such as Sales Lead, accounts, and opportunities. They cannot modify system configuration.
- Customer service specialists focus on ticket follow-up and customer service. They cannot access sensitive information such as sales forecasts and contract amounts.
- System administrators have the highest management permissions. They manage object customization, process design, and security policy configuration.
2. Multi-level data visibility control
- Owner restrictions: Sales representatives can access and edit only the account records they own.
- Department-level sharing: Sales managers can view and manage business data for their departments and all subordinate departments. Peer departments remain isolated by default.
- Cross-functional sharing: In cross-region collaboration, configure sharing rules to share customer data for a specific region with an after-sales support team in another region.