Permission groups explained
How permission groups gate features and records, and how to create custom groups.
Permission groups
Access is governed by permission groups, not a fixed role field. Configure them in Admin Console → Users & Access → Permission Groups.
What a group controls
- Full Admin — All Access — one toggle that grants everything.
- Data Access — the record-level scope: Own accounts, Team roll-up, or All accounts (overrides the tenant default visibility).
- Default account view — the landing scope a new user first sees.
- Resource Permissions — a Create/Read/Update/Delete matrix over Accounts, Contacts, Actions, Tasks, Success Plans, Renewals, and more (Read is always on).
- Feature Access — pill toggles for each capability and Admin Console section. A granted feature is what makes that section visible; the whole app is one universal structure and a group simply hides the branches a user can't reach.
Assigning and system groups
Assign a group in the Add/Edit user modal. Velsano ships immutable system groups — Admin, Manager, High-Touch CSM, Pool CSM, CS Ops, IT Admin, VP / Read Roll-up, Report Consumer — and you can create custom ones. A user with no group has no access.
Tip
Manager visibility also rolls up automatically through the reporting hierarchy — you don't need to widen a manager's data scope by hand (see *Users and the management hierarchy*).
Related: *Users and the management hierarchy* · *Data Visibility: who sees which accounts*
More in Admin & Security
- Users and the management hierarchy
- Custom objects and Account Profile tabs
- Audit log
- Importing data
- API keys, the Developer API & MCP
- Connectors & the Data Hub
- Data Visibility: who sees which accounts
- Picklists: editing dropdown values
- Layouts & Forms: personalizing the workspace
- Catalogs: Features, Milestones, Products & Event Types
- Trash: restoring deleted records
- Company profile & currency