Published at: 2026-09-17

Organization and permissions overview


Learn about the platform’s organization management and permission control design and core capabilities.

Business value

In enterprise applications, a sound Org Structure, granular permissions, and a robust security foundation protect core business data and support efficient collaboration across departments. The platform provides flexible Org Structure configuration and multi-level data and function-level isolation. This helps you maximize operational efficiency while maintaining security.

Core capabilities

The platform provides the following organization and permissions management areas:
Management area Core capabilities Business value
Organization management Maintain multi-level departments and employee accounts, and enable multi-organization management. Map reporting relationships and establish the administrative foundation for employee ownership.
Function permissions Use role-based access control (RBAC) to assign menu and operation permissions by business role and management role. Ensure that employees can use only the function buttons required for their responsibilities.
Data permissions Control basic data permissions, department data permissions, data sharing rules, related teams, and temporary permissions. Control record-level and field-level visibility and protect customer asset privacy.

Core use cases

1. Function permission isolation

Employees in an enterprise have different responsibilities, such as sales, customer service, and finance:
  • Sales representatives can view and use business modules such as Sales Lead, accounts, and opportunities. They cannot modify system configuration.
  • Customer service specialists focus on ticket follow-up and customer service. They cannot access sensitive information such as sales forecasts and contract amounts.
  • System administrators have the highest management permissions. They manage object customization, process design, and security policy configuration.

2. Multi-level data visibility control

  • Owner restrictions: Sales representatives can access and edit only the account records they own.
  • Department-level sharing: Sales managers can view and manage business data for their departments and all subordinate departments. Peer departments remain isolated by default.
  • Cross-functional sharing: In cross-region collaboration, configure sharing rules to share customer data for a specific region with an after-sales support team in another region.

Related topics

Submit Feedback