Published at: 2026-09-17

External roles and data permissions overview


Application scope, external roles, and data permissions work together to determine which Partner Connect features a partner user can access, which records they can view, and which actions they can perform.

Permission layers

  • External access scope: Determines which downstream enterprises or connected contacts can access an application.
  • Role and edit permissions: Determine object operations and field-level access.
  • Record types and layouts: Determine which object record types and page layouts partner users work with.
  • Data scope: Determines which records users can view and edit.
  • Data sharing: Determines read and write sharing between downstream roles.

Data scope options

The source documentation lists five object data scopes: Private, Company Read Only, Company Read/Write, Public Read Only, and Public Read/Write.

How access is evaluated

A partner user must first be included in the application’s external access scope and assigned an external role. The user can access a business entry only after that role has the required object, field, and data scope permissions.

Related topics

Submit Feedback