The Roles and Permissions Matrix: Who Sees What in Your Sales System
Post 24 Sep 2026 CRM securitysales operationsuser permissionsdata governance
Build your sales system's permissions on a two-dimensional matrix: roles down the rows, four operations across the columns — view, edit, export, delete. Handing everyone full access isn't managerial generosity; it's a problem postponed until the day a customer list leaks or a price changes and nobody can say who changed it.
The Common Mistake: One Permission Level for All, Then Endless Exceptions
A small company starts with five people who trust each other, so every screen is open to everyone. Then the team grows, and the gaps get patched with exceptions: "hide margin from the new reps," "block exports for this person." A year later you have thirty exceptions nobody remembers the reason for — and nobody dares remove.
The right starting point is roles, not people. People leave. Roles stay.
The Four Axes Behind Any Permissions Matrix
- View: Can they see the record at all? And can they see every field on it?
- Edit: Can they change the value, or only propose a change?
- Export: Pulling data into a file outside the system — the riskiest axis, and the most frequently overlooked.
- Delete: The default should be no. Replace it with archiving; deletion destroys the audit trail.
Conflating view with export is the single most common setup error. Someone who can see the customer list doesn't need a button that turns it into a spreadsheet on their personal laptop.
Five Typical Roles in a Saudi Sales Team
| Role | Scope |
|---|---|
| Sales rep | Own opportunities and assigned accounts |
| Team supervisor | Team's opportunities, including margin visibility |
| Sales manager | All opportunities, plus discount approval |
| Analyst / reporting owner | Aggregate read access, no individual contact data |
| Finance | Pricing, cost and invoices, no editing of the sales pipeline |
Sensitive Fields
Four fields deserve an explicit decision rather than a default one:
Margin and cost price: Useful for supervisors and managers. Exposing them to reps turns negotiation into internal pressure on price.
Direct contact details: Decision-maker names and numbers are the asset that walks out with a resignation. Make them viewable but restrict exporting.
Government tender documents: Requirement booklets and submitted pricing stay with the bid team and the approver.
Contract attachments: Read access for everyone involved, edit rights for a single owner.
A Ready Matrix You Can Copy and Adapt
| Role | View | Edit | Export | Delete |
|---|---|---|---|---|
| Sales rep | Own records | Own records | Blocked | Blocked |
| Supervisor | Team + margin | Team | By logged request | Blocked |
| Sales manager | All | All | Allowed and logged | Archive only |
| Analyst | Aggregate | No | Aggregate reports | Blocked |
| Finance | Pricing and cost | Financial fields | Allowed | Blocked |
In Effistar this matrix is enforced at the field level, not just the screen level, and every export leaves a record behind.
Edge Cases
- Acting manager: Grant access with an expiry date, not permanent rights everyone forgets about.
- External consultant: Separate account, aggregate visibility, export disabled.
- Departing rep: Cut off export access the day the resignation is submitted, not the last working day — and reassign opportunity ownership before disabling the account.
A Thirty-Minute Quarterly Review
Print three lists: who has export rights, who can see margin, and who hasn't logged in for sixty days. Go through the first line by line, and ask one question about the third: is this account still needed? That half hour saves you a week-long investigation later.