Published at: 2026-09-17
Data permission query tool
Use the data permission query tool to analyze an employee’s access level and permission sources for a record. Select the correct Personnel Type before querying.
Overview
💡 When an employee cannot view an account record or unexpectedly has edit access to an order, administrators do not need to sign in as the employee or audit permission tables manually. The tool traces permissions for a user and a record in one step. It returns the access level, such as Read Only, Read/Write, or No Permission, and all authorization sources, such as roles, department visibility, sharing rules, and Related Teams.
Before you begin
[!IMPORTANT] - Role permissions: You must have System Administrator permissions. - Applicable objects: You can query standard and custom objects that use record-level data permissions.
Procedure
- In Setup, go to CRM Platform Management > Data Maintenance Tools > Data Permission Query Tool.
- Configure the query:
- Person type: Select Internal User.
- User: Search for and select the employee account to analyze, such as
Wang Wu. - Object name: Select the target object, such as
Account. - Business Data: Select the record to analyze, such as
Account A - Shanghai Trading Company.
- Click Query.
- Interpret the result:
- If the user has no permission, the system displays No Permission.
- If the user has permission, the system returns all authorization methods, including the permission level and authorization source.
Expected result
- A query for Wang Wu, who reported no access to Account A, returns No Permission.
- After an administrator adds Wang Wu to Account A’s Related Teams, the query returns Read Only. The authorization source is Related Team Member.