Published at: 2026-09-17
Configure data sharing rules
Create and manage data sharing rules to grant horizontal access across departments and dimensions. The Source Type and Custom Filter determine the scope, and Related Teams can receive access.
Overview
💡 Data sharing rules let you grant view or edit access to specified employees, departments, user groups, or roles. Use the record owner, assigned department or organization, or filter criteria as the basis for sharing.
Before you begin
[!IMPORTANT] - Role permissions: You need System Administrator permissions or a management role with Data Permissions Management permissions. - Important restrictions: * You cannot edit or delete an Enabled sharing rule. Disable it before editing its shared permissions or deleting it. * You cannot change a rule type, such as By Owner, after creating the rule.
Procedure
1. Create a data sharing rule
- Go to CRM Platform Management > Data Permission.
- Click the Data Sharing tab, and then click New Sharing Rule.
- In the New Sharing Rule page, configure these parameters:
- Rule type:
- Based on Data Owner: Share data owned by specified employees with the target.
- Based on Belonging Department: Share data assigned to a specified department with the target.
- Based on Belonging Organization: Share data assigned to a specified organization with the target.
- Based on Criteria: Share records that meet custom criteria, such as
Account Level = VIPandStatus = Enabled.
- Rule name (criteria rules only): Enter a recognizable name, such as
Share South China accounts with headquarters support. - Data source (source-based rules only): Select the source employee, department, or organization. For departments, you can select Include Child Organizations and Departments.
- Shared object: Select the business object to share, such as
AccountorOpportunity. - Share with: Select employees, departments, user groups, or roles. For departments, you can select Include Child Organizations and Departments.
- Permission after sharing: Select Read Only or Read/Write.
- Rule type:
- Click Confirm. The system starts an asynchronous permission tree calculation.
Sharing rule considerations
- Activation delay:
- After you enable or disable a sharing rule, especially a criteria rule, permission recalculation usually completes within 2 hours. The actual time depends on the data volume.
- Multi-level inheritance:
- When you share with a department or organization, select Include Child Organizations and Departments if people in its child units must inherit the permission directly.
- Disabled entities:
- A department- or organization-based rule becomes invalid when its source department or organization is disabled.
- Empty data:
- An owner-based rule requires a non-empty owner field. It does not apply to records without an owner.
- Criteria sharing does not apply by default when an account owner or external owner is empty. Contact your account manager to request the corresponding feature flag.
Verify the result
- Create a department-based rule that shares Sales Department 2 accounts with After-sales, with Read Only permission.
- Sign in with a regular After-sales employee account.
- Search the account list for an account owned by Sales Department 2.
- Expected result: You can view the account details, but the Edit button is hidden.