Roles, Teams & Permissions

The two halves of access

EspoCRM controls access with Roles and Teams, working together:

A user can hold several roles and belong to several teams; their effective access is the combination.

Roles

Least privilege: give people the access their job needs and no more. Widening access later is easy; clawing it back after data has been over-exposed is not.

Teams

How they combine — an example

A mentor holds the Mentor role (view/edit engagements for their team, no delete) and belongs to the team that owns their engagements → they see and update their engagements and session notes, and nothing else.

Changing roles or teams safely

Permission changes that broaden access can expose data unintentionally. Treat them like configuration changes (Chapter 3), not casual edits.


Revision #2
Created 2026-06-18 18:30:10 UTC by Admin
Updated 2026-06-18 19:49:07 UTC by Admin