Data Visibility: who sees which accounts
Set the default record-level visibility for users, and how permission groups override it.
Data visibility
Admin Console → Users & Access → Data Visibility sets the *default* record-level visibility for users whose permission group doesn't specify its own scope. Three options:
- All Accounts (default) — everyone sees the whole book.
- Assigned Accounts Only — a user sees accounts where they're the primary CSM or an active account-team member.
- Primary CSM Only — only accounts a user directly owns.
Precedence
A permission group's own Data Access scope (Own / Team roll-up / All) overrides this default. Admins and super-admins always see all accounts regardless of the policy. The setting applies consistently to lists, searches, and what the AI can read.
Tip
Use the tenant default for the common case, and set an explicit scope on a permission group only where a team needs something different.
Related: *Permission groups explained* · *Users and the management hierarchy*
More in Admin & Security
- Permission groups explained
- Users and the management hierarchy
- Custom objects and Account Profile tabs
- Audit log
- Importing data
- API keys, the Developer API & MCP
- Connectors & the Data Hub
- Picklists: editing dropdown values
- Layouts & Forms: personalizing the workspace
- Catalogs: Features, Milestones, Products & Event Types
- Trash: restoring deleted records
- Company profile & currency