HelpUser Guide • 3 min read

Customer Portal Module - Roles & Permissions

Customer Portal Module - Roles & Permissions

Customer Portal Module - Roles & Permissions

The CRM Portal module has two distinct sets of roles: internal roles for your own team, and portal roles for your customers. This article covers all 7 roles, what each one can do, and how they differ.

The CRM Portal module has two distinct sets of roles: internal roles for your own team, and portal roles for your customers. This article covers all 7 roles, what each one can do, and how they differ.

Quick reference: all roles at a glance

RoleTypeIntended for
CRM AdminInternalFull CRM administrator — manages customers, files, topics, and portal configuration
CRM AgentInternalWorking agent — creates and manages files and topics across all customers
CRM ViewerInternalRead-only staff — can view and comment but not create or edit
CRM Portal AdminCustomerCustomer's portal administrator — manages their company's users, files, and topics
CRM Portal RepresentativeCustomerStandard customer contact — can raise topics and upload files
CRM Portal BillingCustomerFinance contact — read-only access, with visibility into invoices
CRM Portal Read OnlyCustomerView-only customer contact
Key difference between internal and CRM Portal roles: Internal users (CRM Admin, Agent, Viewer) can see data across all customers. CRM Portal users can only ever see their own company's data.

Internal Roles

Internal roles are for your own team managing customer relationships. They have access to data across all customer accounts.

CRM Admin

The full CRM administrator. CRM Admins have unrestricted access across all customers — they can manage customer records, create and edit files and topics, delete and restore content, import data, manage portal users and roles, and configure CRM and portal settings.

CRM Agent

The working agent role for day-to-day customer management. Agents can view, create, edit, comment on, and export files and topics across all customers. They cannot delete content, import data, or access portal configuration.

CRM Viewer

A read-only role for staff who need visibility without making changes. Viewers can browse files and topics across all customers, comment, export, and flag content — but cannot create or edit anything.

Permissions overview

CapabilityCRM AdminCRM AgentCRM Viewer
Manage customers (create/edit/delete)
View files & topics (all customers)
Create files & topics
Edit files & topics
Delete / restore files & topics
Import files & topics
Comment on files & topics
Export files & topics
Flag files & topics
Manage file categories
Manage portal users
Manage portal roles
Manage CRM / portal settings

CRM Portal Roles (for Customers)

CRM Portal roles are for your customers logging into their portal. All portal users are restricted to their own company's data — they can never see another company's files, topics, or users.

CRM Portal Admin

The most powerful customer-facing role. The Portal Admin manages their company's presence in the portal — they can invite and manage other portal users, assign roles, upload and edit files across the account, create and manage topics, and comment. They can only delete files and topics they created themselves.

CRM Portal Representative

The standard customer contact. Representatives can create topics, upload files, and comment — making them the main point of contact for day-to-day communication. They can edit or delete only files and topics they created themselves. They do not have access to invoices.

CRM Portal Billing

Designed for finance contacts. Billing users have read-only access and can only see files in the invoices category. They cannot upload files, create topics, or leave comments.

CRM Portal Read Only

A view-only role for users who need to stay informed without making any changes. Read Only users can browse files (excluding invoices) and view topics, but cannot upload, comment, edit, or delete anything.

Permissions overview

CapabilityPortal AdminRepresentativeBillingRead Only
View files✅ (excl. invoices)✅ (invoices only)✅ (excl. invoices)
Upload files
Edit files✅ (own files only)
Delete files✅ (own files only)
View topics
Create topics
Edit topics✅ (own topics only)
Delete topics✅ (own topics only)
Comment on files & topics
Manage portal users
Manage portal roles
View portal settings

Key Rules

For internal roles:

  • CRM Admin is the only internal role that can manage customer records, delete content, or configure the portal.
  • CRM Agent and CRM Viewer both have full visibility across all customers — the difference is that Agents can create and edit, while Viewers cannot.
  • All three internal roles can view and search the internal user directory.

For CRM Portal roles:

  • Invoices are restricted by role: Billing users see invoices only; Representatives and Read Only users see everything except invoices; Portal Admins see all files.
  • "Own only" means the user can only edit or delete records they personally created — not records created by colleagues in the same company.
  • All portal data is scoped to the user's own company — no portal user can ever view or interact with another company's data.

Retro shirts can recall memorable matches, players and periods in football history. For a season-based comparison, Lionel Messi jerseycamiseta de Lionel Messi) identifies the team or player linked to the design. Good care and suitable storage help preserve the shirt's appearance over time.