CRM glossary

What is role-based access control (RBAC)?

Role-based access control grants permissions to roles rather than to people, so what someone can see and do follows from the job they hold.

Role-based access control (RBAC), explained

Role-based access control (RBAC) is a way of managing permissions by job rather than by person. You define roles such as sales rep, team manager and administrator, decide what each role can view, create, edit, delete and export, and then give every user a role. When someone joins or changes jobs, you change their role instead of rebuilding their permissions. It also makes reviews easier, because access is explained by role rather than by a list of individual exceptions.

In a CRM, RBAC has two parts. Permissions decide which actions a role can take, such as editing deals or exporting contacts. Data scope decides which records the role applies to: only the user's own records, their team's, or everything. A rep and a manager might have the same permissions but different scopes, so each sees exactly the pipeline they are responsible for.

Keep roles few and named after real jobs, give each the least access it needs, and review them when the team changes. Pair RBAC with an audit log so you can see who did what. DigiPix Flow uses custom roles, each with a data scope of the user's own records, their team's, or everything.

See it working on your own leads

Talk to an expert and we will help you set up your workspace.