Help / Security, privacy & your data / Who can see what: capabilities, not roles

Who can see what: capabilities, not roles

Concept1 min
In one sentenceEvery member holds a list of capabilities granted by the modules that are on, plus a read scope for deals - their own, their team's, or the whole book.

Capabilities, not roles

Headway has no preset roles. Each thing a person can do - read deals, advance one, log a hold, log time, move a candidate - is a capability, and every guarded action checks a capability, never a role name. Switching a module on under Admin › Modules grants its capabilities to every member; off takes them away and keeps the data. Admins hold two no module carries: workspace.write, which puts Admin in the module switcher, and deal.delete. The workspace switcher labels each membership Admin, Member or Guest.

Read scope

For deals, the capability also carries a reach. "Everyone sees" under Admin › General is the floor: The whole book (the default), Their team's deals, or Their own deals. On Admin › Roles & members, each person's "Sees:" line shows their reach; an admin can grant a wider one, never a narrower one. Team reach comes from Admin › Teams: a person sees deals owned by their team and every team beneath it, plus their own; someone in no team sees only their own. Today, Pipeline, search and the Forecast all narrow with it.

Recruit limits by client instead: an admin ticks the clients a person may recruit for. A guest - invited from an email domain nobody in the workspace shares - sees no clients in Recruit until an admin ticks some.

Did this answer it? Not quite - tell us