Manage permission groups¶
Create reusable permission groups that decide which accounts your team members can see and what they can do.
A permission group bundles roles — the sets of actions a person can take — with the resource access those actions apply to. How far a user's visibility extends is not set on the group: reach derives from the user's home business unit together with the resource grants. Assigning the same group to many users keeps their access consistent.
Prerequisites
- You are signed in to the Backoffice with a role that grants the Manage permissions permission.
- You have selected the workspace for the firm whose groups you want to manage.
Read the permission groups list¶
Open Permission groups from the left sidebar. Each group appears as a row showing its name, the workspace it belongs to, and how many roles and resources it grants.
Each row has actions to Edit the group, Clone it, or Delete it.
Create a permission group¶
The quickest way to start is from a persona template — a ready-made starting point for a common kind of team member.
- Open Permission groups and click New permission group.
- Choose a starting point:
- Firm Administrator — full control over the firm.
- Sales Rep — work leads and their own accounts, without moving money.
- Account Manager — a sales rep's reach plus monetary approvals and business-unit management.
- Trading Desk — place and modify trades on trading accounts, with read-only access to the rest of the CRM.
- Compliance / Audit — review accounts and communications and reveal protected fields, with no editing.
- Read-only Viewer — look at accounts, brands, and charts, with no changes and no access to protected data.
Each card notes what the persona does and how many roles it grants.
- In the Name field, keep the suggested name or enter your own.
- Click Create.
The new group opens in the editor, where you can fine-tune its roles, resources, and protected-field access. See Edit a permission group.
Note
To build a group from scratch instead, skip the templates and just enter a name. The group is created empty, and you grant its roles and resources on the editor page.
Clone a permission group¶
To reuse an existing group as the basis for a new one, click Clone on its row. A copy is added to the list, which you can then rename and adjust in the editor.
Delete a permission group¶
- Click Delete on the group's row.
- If any users are currently assigned to the group, choose a Replacement group. Those users move to the replacement so no one is left without access.
- Click Delete to confirm.
Warning
A group that users still rely on cannot be removed without naming a replacement — this prevents anyone from suddenly losing the access they need to do their job.