Menu
Articles in this section
- Permissions & Users: FAQ
- SSO/SAML: FAQ
- Simple vs Advanced Permissions
- Advanced Permissions Guide
- Advanced Permissions: Organization-Wide Sharing
- Advanced Permissions: Profiles
- Advanced Permissions: Roles
- Advanced Permissions: Sharing Rules
- How to create a team
- Granting or removing export permissions
Permissions & Users: FAQ
Questions that come up before, or instead of, reading the Advanced Permissions Guide and the other permissions and user-management pages.
Simple vs Advanced Permissions
What is the difference between Simple and Advanced Permissions?
Simple Permissions sets visibility per record as it's created or edited, with two user types. Advanced Permissions layers profiles, roles, sharing rules, and organization-wide sharing to determine access. See Simple vs Advanced Permissions.
What happens the moment I switch on Advanced Permissions?
Access closes down to almost nothing. Records become visible only to their owners, assignees, and administrators until you build the permission layers back up. Plan your profiles, roles, and sharing rules before switching it on. See Advanced Permissions Guide.
Can I switch back to Simple Permissions once I've switched?
Yes. Switching back is always possible, and changes made under either system are saved, so going back and forth isn't destructive. See Simple vs Advanced Permissions.
How Advanced Permissions works
What are profiles, roles, sharing rules, and organization-wide sharing, and how do they fit together?
Profiles control which objects a user can see and change. Organization-wide sharing sets the default sharing level per object, public or private. Roles control which records a user can see through the sharing hierarchy. Sharing rules extend visibility sideways, between roles that aren't in the same hierarchy branch. See Advanced Permissions Guide, The four permission types.
How do roles decide who sees what?
Roles only take effect once organization-wide sharing is set to private. Roles higher in the hierarchy can then view items owned by or assigned to roles beneath them. People in the same role don't see each other's records unless a sharing rule is added, which can lead to accidental duplicate records. See Advanced Permissions: Roles.
What do Read All and Modify All do on a profile?
They override roles and sharing rules. Read All lets a user read every record of a type regardless of role or sharing rules. Some profile permissions depend on others; a profile can't edit a record type unless it can also read it. See Advanced Permissions: Profiles.
What is the difference between Private and Public organization-wide sharing?
Private limits access to owners, assignees, and anyone reached through the role hierarchy or a sharing rule. Public gives every user with Read permission on that object access to every record of that type, and it switches off roles and sharing rules for that object entirely. See Advanced Permissions: Organization-Wide Sharing.
Why would I need a sharing rule if I already have roles?
A role hierarchy only shares upward. Sharing rules are how you share sideways, between roles at the same level or in unrelated branches, such as letting two manager roles see each other's records. See Advanced Permissions: Sharing Rules.
Can I delete a role or profile once I no longer need it?
Yes, from System Settings > Permissions, but the deletion is permanent. See Advanced Permissions: Profiles.
Users, licenses, and teams
How do I add a user?
Before adding users, work out where your data currently lives and how your team will be structured, since both affect how you'll want permissions set up. See Managing Users.
A user's invitation expired or never arrived. What do I do?
Send a new one from System Settings > Users. If a user receives no notifications, password resets, or invitations at all, the messages are most likely being blocked before delivery rather than not being sent. See Managing Users, Invitation problems.
Someone is leaving temporarily. Should I delete them or remove their license?
Remove their license. That disables access without requiring you to reassign what they were responsible for, which makes it the right tool for someone temporarily leaving rather than departing for good. See Managing Users, Licenses.
Why does a user also show up as a contact?
Adding a user creates an Insightly contact for them automatically, though system users have special contact records that behave differently from ordinary contacts. See Managing Users.
What can a read-only user do?
Read-only is an Enterprise-only seat type. They can receive notifications, comment and @mention, view dashboards, run saved reports, and create and save list views. They cannot update permissions, be an administrator, or create, edit, or delete records. See Read-Only Users.
How do I create a team?
Go to System Settings > Teams, enter the team name, and add it. Add members from the Team Members link next to the team's name. See How to create a team.
Administrators
What can an administrator do that other users can't?
Access and change system settings, view, edit, or delete any record regardless of permissions, and access and change billing. Make at least two trusted users administrators so account management doesn't depend on one person; making everyone an administrator isn't advisable. See Permissions: administrative & granular.
Can someone administer part of the account without full administrator access?
Yes, through granular administrative permissions, which structure admin privileges into specific scopes rather than one all-or-nothing role. See Permissions: administrative & granular.
Visibility and export
How do I control who can see a specific record?
On Simple Permissions, use the Visibility Permissions setting when creating or editing the record; its starting value comes from Default Item Visibility. Tasks and events use a simpler Public or Private version of the same setting. See How to set visibility permissions on a record.
What does Default Item Visibility control?
What a record's visibility setting starts as under Simple Permissions, which determines what happens if a user leaves it untouched. It doesn't appear on Advanced Permissions accounts. See Permissions: administrative & granular.
How do I stop a user from exporting data?
Go to System Settings > Users, click the user's name, click Edit User, and uncheck Export Permissions. Users are always limited to exporting only the records they can already see. See Granting or removing export permissions.