Published at: 2026-09-17
Multidimensional permission management
Enable multidimensional permission control and configure the dimensions assigned to employees and business data. Use the Form Page to verify Account records.
Overview
💡 Department hierarchies do not cover every matrix-management scenario. Use multidimensional permissions to build vertical dimensions parallel to the Org Structure, such as region, industry, and product lines. The system then determines access by the dimension tree linked to each record.
Before you begin
[!IMPORTANT] - Role permissions: You need System Administrator permissions. - Layout configuration: Dimension fields do not appear on the client automatically. Add them manually to the relevant page layouts.
Procedure
1. Enable and build a multidimensional hierarchy
- Go to Setup > Organization Structure > Multi-dimensional Permissions.
- After the tenant enables this capability, the system provides three primary dimensions:
Territory,Industry, andProduct Line. - Click Edit Applicable Objects, select objects that use the dimension permission calculation, and assign permissions. Examples include
Campaign,Account, andOpportunity. - Click a target dimension tree, such as Territory, to open its details.
- Create dimension nodes in the same way as departments. For example, add East China and North China under a first-level region, then add Shanghai under East China.
2. Set the dimensions assigned to an employee
- Go to Setup > Organization Structure > Departments & Users.
- Select an employee and click Edit.
- In organization relationship attributes, locate the new dimension fields:
- Responsible Territory
- Responsible Industry
- Responsible Product Line
- In the dimension tree, select the nodes assigned to the employee, such as Guangzhou and Shenzhen.
- Click Save.
3. Configure the data dimensions
When a business user creates a record, the user must specify its assigned dimension to trigger permission calculation:
- On the create or edit page, set the object’s dimension field, such as an account’s
Assigned Region, to the corresponding dimension node. - After the record is linked to the dimension, employees responsible for that node or any parent dimension node automatically gain access to the record.
Considerations
- Reporting line does not inherit:
- Access gained through multidimensional management does not automatically pass to the employee’s administrative manager in the primary department.
- Dimension field usage:
- Assigned dimension fields support list filters, criteria-based data sharing rules, and BI report statistics in addition to data isolation.
Verify the result
- Configure the Region dimension and assign Account B to Guangzhou.
- Assign Guangzhou as the responsible region for employee A.
- Sign in as A and confirm that Account B appears in the account list.
- Change A’s responsible region to Shanghai and sign in again. Confirm that Account B is hidden.