How access works
Privileges
A privilege is permission to do one thing to one kind of record. Its name is the kind of record, an underscore and the action:
contact_read: see contacts, in lists, search, reports and on their own page.contact_write: create contacts and change them. This includes importing, cloning, bulk editing, editing a field in place, and adding comments.contact_delete: move contacts to the trash.
The kinds of record are listed below. Besides records, there are privileges for dashboards, integrations, workflows, saved reports and the default values of a workspace.
Roles
A role is a named set of privileges. You give roles to members, and a member can have several.
- Predefined roles come with BunnyCRM and cannot be changed:
- one for each privilege, such as
invoice_read; - one for each area and action, such as
marketing_readorsales_write, which cover every kind of record of that area; everything_read,everything_writeandeverything_delete;workspace_admin, which holds everything.
- one for each privilege, such as
- Custom roles are roles a workspace admin builds for the workspace, for example a sales assistant who may read and write orders and customers.
Writing and deleting always include reading: you cannot change what you cannot see.
Who is a workspace admin
These people can use every page and are never turned away:
- the owners and admins of the workspace;
- anyone who holds the
workspace_adminrole; - system administrators of BunnyCRM.
New members
A member who joins a workspace has no role. Until a workspace admin gives them one they see a short notice on the dashboard and can use only what is their own: notes, bookmarks, expenses, action items, life events, My drive, notifications and their preferences.
When it applies
Roles are checked in a workspace once it has been switched on for it. Until then every member can use every page, and the lists below show what each page will need. Pages built on several kinds of record, such as search, counts, the dashboard, the trash, comments and favorites, simply leave out the records you may not read. They do not fail.
If you try something your roles do not allow, BunnyCRM tells you which privilege is missing. Ask a workspace admin to give you a role that has it.
Giving roles to members
Workspace admins manage roles under Settings, then Roles & Privileges:
- Predefined roles lists the built-in roles. They are read-only.
- Custom roles lets you build a role on a grid of record kind by Read, Write and Delete. Ticking Write or Delete also ticks Read, and unticking Read clears the others. Ticks for an area or for Everything select all of its kinds at once.
- Members shows each member of the workspace. Open one to see their roles, add or remove roles, and save.
You cannot remove your own admin role, so a workspace is never left without someone who can give roles. A custom role cannot be deleted while someone still holds it.
The sign-in app's user profile lists its own roles, not these. Give BunnyCRM roles on this page.
Pages
In the tables, record read means the read privilege of the kind of record the page is about, for example invoice_read for the invoices pages. Where a page works with a particular record kind, the privilege is named.
Pages anyone can open
| Page | Address | You need |
|---|---|---|
| Home | / |
Nothing, and no sign-in. |
| Documentation | /docs |
Nothing, and no sign-in. |
| A workspace's public social page, and one post of it | /v1/social/<name> and /v1/social/<name>/<post> |
Nothing, and no sign-in. The workspace has to have published it. |
| The BunnyCRM bunny | /bunnycrm |
Nothing. |
| Invoice designer | /v1/invoice/designer |
Nothing to design and download an invoice. Opening a saved invoice needs invoice_read, saving one needs invoice_write. |
Your own things
These pages work with what only you created. No role is needed.
| Page | Address |
|---|---|
| Notes | /v1/notes |
| Bookmarks | /v1/bookmarks |
| Expenses | /v1/expenses |
| Action items, recurring action items and life events | /v1/mobjs/<kind>/... for action_item, recurring_action_item, life_event |
| Calendar | /v1/calendar |
| Lifeline | /v1/lifeline |
| My drive and its file editors | /v1/my-drive, /v1/my-drive/<kind>/create and /edit/<id> |
| Notifications | /v1/notifications |
| Personal preferences | /settings/personal-preferences |
| User settings and your default values | /user-settings, /user-settings/default-values |
Around the whole workspace
These need any role: they are not about one kind of record, or they show only what you may read.
| Page | Address | You need |
|---|---|---|
| Dashboard | /dashboard |
Any role. Counts and recent items show only the kinds you may read. With no role you see a notice instead. |
| Chat | /chat |
Any role. |
| Favorites | /v1/favorites |
Any role. Shows favorites of the kinds you may read. Adding one needs record read. |
| Choose a workspace | /workspace/set |
Nothing beyond signing in. |
| Usage | /usage |
Any role. |
| Packages | /packages |
Any role to see the plans. Changing the plan needs a workspace admin. |
| AI assistant | /v1/ai |
Any role. What the assistant does for you needs what you would need to do it yourself: record read to list, record write to create or change. |
| API playground | /v1/api-playground |
Any role. It sends requests with the API key you paste, so it can do what that key's user may do. |
| Workspace admin tools | /workspace_admin |
Any role. It links to the trash. |
Search and data tools
| Page | Address | You need |
|---|---|---|
| Search | /search |
Any role. |
| Search by keyword | /search/by-keyword |
Any role. Results are only the kinds you may read. |
| Search by id | /search/by-id |
Record read. |
| Search by tags | /search/tags |
Any role. |
| Advanced search | /search/advanced |
Record read of the kind you search. Saved searches show only for kinds you may read. |
| Data | /v1/data |
Any role. |
| Duplicate finder | /v1/data/duplicates |
Record read to look for duplicates. Merging needs record write and record delete. |
| Import and its saved templates | /import, /import/templates/<id> |
Record write of the kind you import. |
| Export and its saved templates | /export, /export/templates/<id> |
Record read of the kind you export. |
| The Warren (trash) | /trash_bin |
Any role. Lists the kinds you may read. Restoring needs record write. |
| Activity logs | /v1/activity_logs (also /activity_logs) |
Any role. Shows the history of the kinds you may read. |
| Add an activity log entry | /v1/activity_logs/create |
Record write of the kind it is about. |
| Address map | /v1/map |
address_read |
Working with records
Every kind of record has the same set of pages under /v1/mobjs/<kind>/.... They follow the privileges of that kind.
| Page | Address | You need |
|---|---|---|
| List, home page, dashboard, board and Gantt chart | /v1/mobjs/<kind>/list, /home, /dashboard, /kanban, /gantt |
Record read |
| A record, and its read-only view | /v1/mobjs/<kind>/<id>, /ro-view |
Record read. Editing a field in place needs record write. Adding a comment needs record write. |
| Create a record, create many, and edit many | /v1/mobjs/<kind>/create, /bulk_create, /bulk_update |
Record write |
| Delete a record, or many | buttons on the list and record pages | Record delete |
| Clone a record | button on the record page | Record write |
| Copy a record as another kind | button on the record page | Record read of the original and record write of the other kind |
| Chart creation | /v1/mobjs/chart_creation |
Record read of the kind charted |
Personal kinds (notes, action items and so on) need no privilege.
Marketing
| Page | Address | You need |
|---|---|---|
| Contacts home | /v1/contact/custom-home |
contact_read |
| Sales funnel | /v1/funnel |
opportunity_read |
| Opportunity journeys | /v1/opportunity/journeys |
opportunity_read |
| Opportunity stage graphs | /v1/opportunity/graphs/stage |
opportunity_read |
| Closing a deal, or engaging its contact | buttons on an opportunity | opportunity_write |
| Campaign wizard | /v1/campaign/compose |
campaign_write and opportunity_write (it creates the deals), and contact_read |
| Campaign pipelines | /v1/campaign/pipelines |
campaign_read and opportunity_read |
| Write and send a message | /v1/activity/compose |
activity_write, and contact_read to choose a contact |
| Social media posts | /v1/social |
social_media_post_read |
| Segments | /v1/segments, /v1/segments/<id> |
saved_report_read; saving or deleting one needs saved_report_write or saved_report_delete |
| Projects home and status graphs | /v1/project/custom-home, /v1/project/graphs/status |
project_read |
Sales
| Page | Address | You need |
|---|---|---|
| Invoices home | /v1/invoice/custom-home |
invoice_read |
| Invoice designer with a saved invoice | /v1/invoice/designer/<id> |
invoice_read to open it, invoice_write to save it |
| Send an invoice | /v1/invoice/send/<id> |
invoice_write: sending emails the invoice and marks it sent |
| Orders home | /v1/order/custom-home |
order_read, and the order's items and payments need order_item_read and payment_read |
| Creating an invoice from an order | button on an order | order_write and invoice_write |
| Payments home | /v1/payment/custom-home |
payment_read |
| Payment designer | /v1/payment/designer |
payment_write |
| Refunding a payment, running a recurring payment | buttons on a payment | payment_write |
| Products home | /v1/product/custom-home |
product_read |
| Inventory home | /v1/inventory/custom-home |
inventory_read. Stock movements and transfers need inventory_write. |
Support
| Page | Address | You need |
|---|---|---|
| Ticket status graph | /v1/support_ticket/graphs/status |
support_ticket_read |
| Time logs home | /v1/time_log/custom-home |
time_log_read. Starting, stopping or adding time needs time_log_write. |
| Support tickets home | /v1/support_ticket/custom-home |
support_ticket_read |
| Home of any other record type | /v1/<type>/custom-home |
Nothing beyond a selected workspace. A blank page that shows no records. |
Content
| Page | Address | You need |
|---|---|---|
| Drive and its file editors | /v1/drive, /v1/drive/<kind>/create, /edit/<id> |
companion_file_read to see files, companion_file_write to add or change, companion_file_delete to remove |
| Uploading a file, and file tiles | /v1/companion_file/upload, /tiles, /<kind>/edit/<id> |
companion_file_write to upload or edit, companion_file_read for the tiles |
| Documents | /v1/document/tiles |
document_read. Uploading or replacing a document's file needs document_write. |
| Content page designer | /v1/content_page/designer |
content_page_write |
| A content page | /v1/content/<id> |
content_page_read |
Dashboards and reports
| Page | Address | You need |
|---|---|---|
| Dashboards list | /v1/dashboard/list |
dashboard_read |
| Dashboard builder | /v1/dashboard/builder, /v1/dashboard/builder/<id> |
dashboard_write to build or change one, dashboard_delete to remove one |
| Reports list | /v1/reports/list |
saved_report_read |
| Report builder | /v1/reports/builder, /v1/reports/builder/<id> |
saved_report_write to save one, and record read of the kind it reports on |
Settings
| Page | Address | You need |
|---|---|---|
| Settings | /settings |
Any role |
| Business profile | /settings/business-profile |
Any role to view. Changing it needs a workspace admin. |
| Default values of the workspace | /settings/default-values |
workspace_default_values_read to view, workspace_default_values_write to change |
| Workspace configuration | /settings/workspace-configuration |
Any role to view. Changing the plan, the public page or the object limits needs a workspace admin. |
| Workspace features | /settings/workspace-features |
Any role to view. Switching a feature on or off needs a workspace admin. |
| Integrations | /v1/integrations |
integration_read to see them, integration_write to add, change or test one, integration_delete to remove one |
| Workflows | /v1/workflows, /v1/workflows/create, /v1/workflows/<id> |
workflow_read to see them, workflow_write to create or change one, workflow_delete to remove one |
| Roles & Privileges | /settings/roles-privileges |
A workspace admin. Others are sent back to Settings. |
| New role / Edit role | /settings/roles-privileges/new, /settings/roles-privileges/edit/<role> |
A workspace admin. The privilege grid for a custom role. |
| All roles | /settings/roles-privileges/roles |
A workspace admin. Lists every role; click one to see its privileges. |
Things only a workspace admin can do
- Give roles to members, and build or delete custom roles.
- Change the business profile.
- Change the plan, and publish or unpublish the workspace's public page.
- Change the object limits of the workspace.
- Switch workspace features on or off, and change the workspace configuration.
System administrators can also look at record counts across all workspaces. That is not available in a workspace.
Privileges by area
Each kind of record has _read, _write and _delete. The role for an area, such as marketing_read, holds that action for every kind in it.
| Area | Kinds of record |
|---|---|
Marketing (marketing) |
contact, company, address, project, campaign, opportunity, activity, newsletter_subscriber, social_media_post |
Sales (sales) |
customer, order, order_item, order_template, recurring_order, invoice, invoice_item, invoice_template, recurring_invoice, payment, recurring_payment, contract, product, inventory, stock, stock_item, booking, booking_item, booking_template |
Support (support) |
support_ticket, recurring_support_ticket, time_log |
Content (content) |
companion_file, content_page, document |
Platform (platform) |
dashboard, integration, workflow, saved_report, user_group, workspace_default_values |
The drive follows companion_file and the document files follow document. Stock movements follow inventory. Personal kinds (notes, action items, recurring action items, life events, bookmarks and expenses) have no privileges: they are always yours alone.