Menu
Articles in this section
- Permissions & Users: FAQ
- SSO/SAML: FAQ
- Simple vs Advanced Permissions
- Advanced Permissions Guide
- Advanced Permissions: Organization-Wide Sharing
- Advanced Permissions: Profiles
- Advanced Permissions: Roles
- Advanced Permissions: Sharing Rules
- How to create a team
- Granting or removing export permissions
Permissions: administrative & granular
Who can administer the account, how administrative power can be split into scopes, and what visibility new records get by default.
On this page:
Granting administrator permissions
ℹ️ Make at least two trusted users administrators, so account management does not depend on one person. Making everyone an administrator is not advisable.
Making a user an administrator allows them to:
- Access and change system settings (add new users, create custom fields, and so on).
- View, edit, or delete any record, regardless of permissions and visibility settings.
- Access and change billing settings.
- Cancel and delete your account.
- Make other users administrators.
If a user has just been added, they need to complete their registration before you can make these changes. You can tell whether you’re an administrator by looking for System Settings in your profile menu; only administrators see this option.
When you’re using Advanced Permissions, assigning an administrator to a profile revokes their administrative privileges. Removing those privileges using the steps below makes them a Standard User.
To make a user an administrator:
- Go to the System Settings > Users page.
- Click on a user’s name.
- Click Edit User.
- Select Administrator from the Profile dropdown.
- Click Save User Details.
Granular administrative permissions
Rather than one all-or-nothing administrator role, administrative privileges are structured into specific scopes matching different roles within an organization, so someone can administer part of the account without full control.
If a user’s profile does not have permission to manage certain system settings, those options are still visible to them. Any attempt to access the setting redirects them to the main system settings page with the notification “You do not have permission to access this system setting.”
The permissions below apply to sections of System Settings, with the exception of ‘Manage Interface Customization,’ which relates to menu options within Insightly objects. A profile with ‘Manage Interface Customization’ but without ‘Manage Data Definitions’ cannot edit, create, or delete objects or fields, but can manage layout rules, custom buttons, and page layouts for each object.
The ‘Administrator’ profile includes all the permissions below, which lets administrators create custom profiles with specific administrative privileges. Any profile with an administrative permission displays the ‘System Settings’ menu option in the User menu. The Administrative Permissions are available under System Settings > Security > Profiles.
CRM Profile Administrative Permissions
- Manage Users: Manage Users and Queues
- Manage Security: Manage Permissions, Roles, Profiles, Sharing Rules, SAML and SCIM Configuration
- Manage Data Definitions: Manage Objects, Fields, Field Dependencies, Validation Rules, Custom Apps, Data Export
- Manage Data Administration: Manage Categories, Lead Statuses, Lead Sources, Lead Conversion, Opportunity Conversion, Opportunity States, Pipelines, Document Templates, Relationships
- Manage Automation: Manage Workflow Automation, Approval Processes, Lambda Functions, Activity Sets, Lead Assignment Rules
- Manage Interface Customizations: Manage Layout Assignments, Layout Rules, Custom Buttons, Search Layouts, Page Layouts
- Manage Product Settings: Manage Company Settings, Leads, Products, Pricebooks and Quotes, Inline Editing, Social Profiles, Custom Branding, Email Tracking
- Manage AppConnect: Manage AppConnect users and settings
- Manage Sandboxes: Manage Sandbox provisioning, users, and settings
- Manage Integrations: Manage Insightly pre-built integrations
Marketing Profile Administrative Permissions
- Manage Users: Manage Users
- Manage Security: Manage Permissions, Roles, Profiles, Sharing Rules, SAML and SCIM Configuration
- Manage Data Definitions: Manage Objects, Fields, Field Dependencies, Validation Rules
- Manage Interface Customizations: Manage Layout Assignments, Layout Rules, Custom Buttons, Search Layouts, Page Layouts
- Manage Data Administration: Manage Prospect Profiles, Prospect Scoring, Tracked Custom Events, Unsubscribe Page, List Management Page
- Manage Automation: Manage Lambda Functions
- Manage Product Settings: Manage Company Settings, Transactional Emails, Inline Editing, Custom Branding, CRM Connector, Form Features, Default Email Sender, Domain Management
- Manage AppConnect: Manage AppConnect users and settings
- Manage Sandboxes: Manage Sandbox provisioning
- Manage Integrations: Manage Insightly pre-built integrations
Service Profile Administrative Permissions
- Manage Users: Manage Users and Queues
- Manage Security: Manage Permissions, Roles, Profiles, Sharing Rules, SAML and SCIM Configuration
- Manage Data Definitions: Manage Objects, Fields, Field Dependencies, Validation Rules
- Manage Interface Customizations: Manage Layout Assignments, Layout Rules, Custom Buttons, Search Layouts, Page Layouts
- Manage Data Administration: Manage Ticket Types, SLA Policies, Schedules, Brands, Languages, Email Templates
- Manage Portals: Manage Customer Portal Websites
- Manage Automation: Manage Ticket Automation, CSAT Surveys, Shared Macros, Lambda Functions
- Manage Product Settings: Manage Company Settings, Inline Editing, Custom Branding, Web To Ticket, Email Settings, Email Blocklist
- Manage AppConnect: Manage AppConnect users and settings
- Manage Sandboxes: Manage Sandbox provisioning
Default item visibility
Under Simple Permissions, each user sets a visibility permission when creating or editing a record. Default Item Visibility controls what that setting starts as, which determines what happens when users leave it untouched. These settings do not appear if your account is set to Advanced Permissions. Each user can still set their own default visibility for new emails or new tasks and events from User Settings.
To configure Default Item Visibility:
- Go to System Settings > Permissions.
- Click Default Item Visibility.
- Click the radio buttons for each record type to select Everyone or Creator Only.
- Click Save.
This does not affect existing records; it only changes the default selection when creating new records, and users can still change the visibility as they create or edit a record.
- Everyone allows all other users on the account to view the record.
- Creator Only limits visibility to the person who creates the item, the person assigned to the item, and administrators.
Related to