Users & Access
Roles: deciding what someone can do
How roles work, how they combine with tribes, and how to hand out access without giving everyone everything.
Last updated September 2, 2026
A role is a named bundle of permissions. People are given roles rather than individual permissions, so access is consistent and a change to the role reaches everyone who holds it.
Two things decide what someone sees
| Their roles | Their tribes |
|---|---|
| What they are allowed to do. | Which tribes they can do it in. |
| Set on the user. | Set by adding them to a tribe. |
Handing out access well
- Build roles around jobs — a rep, a tribe manager, a marketer — not around individuals.
- Start narrow. It is easy to add a permission when someone asks and awkward to take one away.
- Keep full access rare. It should be a decision, not a default.
- Guard the exports. Permissions that let data leave the building deserve their own thought.
What tribe administrators can switch on
A tribe can also control what its own team members are allowed to do — whether they may log in at all, edit their profile, reach the CRM or the network store, or edit website pages. Those switches sit alongside roles rather than replacing them.
When someone leaves
Detach them from the organisation. Before you do, reassign their contacts, companies, opportunities and open tasks — none of those move on their own, and work owned by a departed account is easy to lose sight of.
