Roles and permissions

BunnyCRM lets a workspace decide who may see, change and delete what. This page explains how that works and lists every page of the app with what you need to use it.

How access works

Privileges

A privilege is permission to do one thing to one kind of record. Its name is the kind of record, an underscore and the action:

  • contact_read: see contacts, in lists, search, reports and on their own page.
  • contact_write: create contacts and change them. This includes importing, cloning, bulk editing, editing a field in place, and adding comments.
  • contact_delete: move contacts to the trash.

The kinds of record are listed below. Besides records, there are privileges for dashboards, integrations, workflows, saved reports and the default values of a workspace.

Roles

A role is a named set of privileges. You give roles to members, and a member can have several.

  • Predefined roles come with BunnyCRM and cannot be changed:
    • one for each privilege, such as invoice_read;
    • one for each area and action, such as marketing_read or sales_write, which cover every kind of record of that area;
    • everything_read, everything_write and everything_delete;
    • workspace_admin, which holds everything.
  • Custom roles are roles a workspace admin builds for the workspace, for example a sales assistant who may read and write orders and customers.

Writing and deleting always include reading: you cannot change what you cannot see.

Who is a workspace admin

These people can use every page and are never turned away:

  • the owners and admins of the workspace;
  • anyone who holds the workspace_admin role;
  • system administrators of BunnyCRM.

New members

A member who joins a workspace has no role. Until a workspace admin gives them one they see a short notice on the dashboard and can use only what is their own: notes, bookmarks, expenses, action items, life events, My drive, notifications and their preferences.

When it applies

Roles are checked in a workspace once it has been switched on for it. Until then every member can use every page, and the lists below show what each page will need. Pages built on several kinds of record, such as search, counts, the dashboard, the trash, comments and favorites, simply leave out the records you may not read. They do not fail.

If you try something your roles do not allow, BunnyCRM tells you which privilege is missing. Ask a workspace admin to give you a role that has it.

Giving roles to members

Workspace admins manage roles under Settings, then Roles & Privileges:

  1. Predefined roles lists the built-in roles. They are read-only.
  2. Custom roles lets you build a role on a grid of record kind by Read, Write and Delete. Ticking Write or Delete also ticks Read, and unticking Read clears the others. Ticks for an area or for Everything select all of its kinds at once.
  3. Members shows each member of the workspace. Open one to see their roles, add or remove roles, and save.

You cannot remove your own admin role, so a workspace is never left without someone who can give roles. A custom role cannot be deleted while someone still holds it.

The sign-in app's user profile lists its own roles, not these. Give BunnyCRM roles on this page.

Pages

In the tables, record read means the read privilege of the kind of record the page is about, for example invoice_read for the invoices pages. Where a page works with a particular record kind, the privilege is named.

Pages anyone can open

Page Address You need
Home / Nothing, and no sign-in.
Documentation /docs Nothing, and no sign-in.
A workspace's public social page, and one post of it /v1/social/<name> and /v1/social/<name>/<post> Nothing, and no sign-in. The workspace has to have published it.
The BunnyCRM bunny /bunnycrm Nothing.
Invoice designer /v1/invoice/designer Nothing to design and download an invoice. Opening a saved invoice needs invoice_read, saving one needs invoice_write.

Your own things

These pages work with what only you created. No role is needed.

Page Address
Notes /v1/notes
Bookmarks /v1/bookmarks
Expenses /v1/expenses
Action items, recurring action items and life events /v1/mobjs/<kind>/... for action_item, recurring_action_item, life_event
Calendar /v1/calendar
Lifeline /v1/lifeline
My drive and its file editors /v1/my-drive, /v1/my-drive/<kind>/create and /edit/<id>
Notifications /v1/notifications
Personal preferences /settings/personal-preferences
User settings and your default values /user-settings, /user-settings/default-values

Around the whole workspace

These need any role: they are not about one kind of record, or they show only what you may read.

Page Address You need
Dashboard /dashboard Any role. Counts and recent items show only the kinds you may read. With no role you see a notice instead.
Chat /chat Any role.
Favorites /v1/favorites Any role. Shows favorites of the kinds you may read. Adding one needs record read.
Choose a workspace /workspace/set Nothing beyond signing in.
Usage /usage Any role.
Packages /packages Any role to see the plans. Changing the plan needs a workspace admin.
AI assistant /v1/ai Any role. What the assistant does for you needs what you would need to do it yourself: record read to list, record write to create or change.
API playground /v1/api-playground Any role. It sends requests with the API key you paste, so it can do what that key's user may do.
Workspace admin tools /workspace_admin Any role. It links to the trash.

Search and data tools

Page Address You need
Search /search Any role.
Search by keyword /search/by-keyword Any role. Results are only the kinds you may read.
Search by id /search/by-id Record read.
Search by tags /search/tags Any role.
Advanced search /search/advanced Record read of the kind you search. Saved searches show only for kinds you may read.
Data /v1/data Any role.
Duplicate finder /v1/data/duplicates Record read to look for duplicates. Merging needs record write and record delete.
Import and its saved templates /import, /import/templates/<id> Record write of the kind you import.
Export and its saved templates /export, /export/templates/<id> Record read of the kind you export.
The Warren (trash) /trash_bin Any role. Lists the kinds you may read. Restoring needs record write.
Activity logs /v1/activity_logs (also /activity_logs) Any role. Shows the history of the kinds you may read.
Add an activity log entry /v1/activity_logs/create Record write of the kind it is about.
Address map /v1/map address_read

Working with records

Every kind of record has the same set of pages under /v1/mobjs/<kind>/.... They follow the privileges of that kind.

Page Address You need
List, home page, dashboard, board and Gantt chart /v1/mobjs/<kind>/list, /home, /dashboard, /kanban, /gantt Record read
A record, and its read-only view /v1/mobjs/<kind>/<id>, /ro-view Record read. Editing a field in place needs record write. Adding a comment needs record write.
Create a record, create many, and edit many /v1/mobjs/<kind>/create, /bulk_create, /bulk_update Record write
Delete a record, or many buttons on the list and record pages Record delete
Clone a record button on the record page Record write
Copy a record as another kind button on the record page Record read of the original and record write of the other kind
Chart creation /v1/mobjs/chart_creation Record read of the kind charted

Personal kinds (notes, action items and so on) need no privilege.

Marketing

Page Address You need
Contacts home /v1/contact/custom-home contact_read
Sales funnel /v1/funnel opportunity_read
Opportunity journeys /v1/opportunity/journeys opportunity_read
Opportunity stage graphs /v1/opportunity/graphs/stage opportunity_read
Closing a deal, or engaging its contact buttons on an opportunity opportunity_write
Campaign wizard /v1/campaign/compose campaign_write and opportunity_write (it creates the deals), and contact_read
Campaign pipelines /v1/campaign/pipelines campaign_read and opportunity_read
Write and send a message /v1/activity/compose activity_write, and contact_read to choose a contact
Social media posts /v1/social social_media_post_read
Segments /v1/segments, /v1/segments/<id> saved_report_read; saving or deleting one needs saved_report_write or saved_report_delete
Projects home and status graphs /v1/project/custom-home, /v1/project/graphs/status project_read

Sales

Page Address You need
Invoices home /v1/invoice/custom-home invoice_read
Invoice designer with a saved invoice /v1/invoice/designer/<id> invoice_read to open it, invoice_write to save it
Send an invoice /v1/invoice/send/<id> invoice_write: sending emails the invoice and marks it sent
Orders home /v1/order/custom-home order_read, and the order's items and payments need order_item_read and payment_read
Creating an invoice from an order button on an order order_write and invoice_write
Payments home /v1/payment/custom-home payment_read
Payment designer /v1/payment/designer payment_write
Refunding a payment, running a recurring payment buttons on a payment payment_write
Products home /v1/product/custom-home product_read
Inventory home /v1/inventory/custom-home inventory_read. Stock movements and transfers need inventory_write.

Support

Page Address You need
Ticket status graph /v1/support_ticket/graphs/status support_ticket_read
Time logs home /v1/time_log/custom-home time_log_read. Starting, stopping or adding time needs time_log_write.
Support tickets home /v1/support_ticket/custom-home support_ticket_read
Home of any other record type /v1/<type>/custom-home Nothing beyond a selected workspace. A blank page that shows no records.

Content

Page Address You need
Drive and its file editors /v1/drive, /v1/drive/<kind>/create, /edit/<id> companion_file_read to see files, companion_file_write to add or change, companion_file_delete to remove
Uploading a file, and file tiles /v1/companion_file/upload, /tiles, /<kind>/edit/<id> companion_file_write to upload or edit, companion_file_read for the tiles
Documents /v1/document/tiles document_read. Uploading or replacing a document's file needs document_write.
Content page designer /v1/content_page/designer content_page_write
A content page /v1/content/<id> content_page_read

Dashboards and reports

Page Address You need
Dashboards list /v1/dashboard/list dashboard_read
Dashboard builder /v1/dashboard/builder, /v1/dashboard/builder/<id> dashboard_write to build or change one, dashboard_delete to remove one
Reports list /v1/reports/list saved_report_read
Report builder /v1/reports/builder, /v1/reports/builder/<id> saved_report_write to save one, and record read of the kind it reports on

Settings

Page Address You need
Settings /settings Any role
Business profile /settings/business-profile Any role to view. Changing it needs a workspace admin.
Default values of the workspace /settings/default-values workspace_default_values_read to view, workspace_default_values_write to change
Workspace configuration /settings/workspace-configuration Any role to view. Changing the plan, the public page or the object limits needs a workspace admin.
Workspace features /settings/workspace-features Any role to view. Switching a feature on or off needs a workspace admin.
Integrations /v1/integrations integration_read to see them, integration_write to add, change or test one, integration_delete to remove one
Workflows /v1/workflows, /v1/workflows/create, /v1/workflows/<id> workflow_read to see them, workflow_write to create or change one, workflow_delete to remove one
Roles & Privileges /settings/roles-privileges A workspace admin. Others are sent back to Settings.
New role / Edit role /settings/roles-privileges/new, /settings/roles-privileges/edit/<role> A workspace admin. The privilege grid for a custom role.
All roles /settings/roles-privileges/roles A workspace admin. Lists every role; click one to see its privileges.

Things only a workspace admin can do

  • Give roles to members, and build or delete custom roles.
  • Change the business profile.
  • Change the plan, and publish or unpublish the workspace's public page.
  • Change the object limits of the workspace.
  • Switch workspace features on or off, and change the workspace configuration.

System administrators can also look at record counts across all workspaces. That is not available in a workspace.

Privileges by area

Each kind of record has _read, _write and _delete. The role for an area, such as marketing_read, holds that action for every kind in it.

Area Kinds of record
Marketing (marketing) contact, company, address, project, campaign, opportunity, activity, newsletter_subscriber, social_media_post
Sales (sales) customer, order, order_item, order_template, recurring_order, invoice, invoice_item, invoice_template, recurring_invoice, payment, recurring_payment, contract, product, inventory, stock, stock_item, booking, booking_item, booking_template
Support (support) support_ticket, recurring_support_ticket, time_log
Content (content) companion_file, content_page, document
Platform (platform) dashboard, integration, workflow, saved_report, user_group, workspace_default_values

The drive follows companion_file and the document files follow document. Stock movements follow inventory. Personal kinds (notes, action items, recurring action items, life events, bookmarks and expenses) have no privileges: they are always yours alone.

Related