People
Teams and access
Roles, sharing and classification — in plain words.
Updated
Three layers that stack. You always use the first; the other two arrive switched off, because an access layer that switches itself on would change who sees what — in the one place where nothing may move by itself.
Roles (RBAC)
A role is a name and a permission set — a "bookkeeper" who issues invoices and never sees the pipeline. Settings → Access. Per module, view or edit can be granted to a team or a person, and the "own records only" scope holds in every list, search, export and picker. Unassigned records are visible to everyone.
Sharing (DAC)
Share one record with a person or a team. A share always widens and never narrows: it is added to what the owner rule allows. With both a team and a personal share, the stronger one counts — being told twice cannot take access away.
Classification (MAC)
A record carries a classification, a person a clearance, and clearance below classification is refused — even when a share says otherwise, and even for the record's own owner. That is the difference between mandatory access control and a coloured label. Administrators are the one exception.
The owner and admin roles cannot be edited into a corner: the form refuses, so a company cannot lock itself out of the screen that would undo it.