A server-side scope decision made before any data is read, not a UI filter. The response tells the panel which scope it got ('all', 'team' or 'own'), and the panel adapts — a rep on 'own' scope never even renders the leaderboard or group-compare sections.
Also called: reps only see their own leads · sales manager visibility · who can see analytics
- 1Admin or tenant owner → org-wide.
- 2Anyone else → the effective lead-visibility scope is looked up; 'team' resolves to a configured id set that already includes self, 'own' resolves to self only.
- 3A team or own scope with no identities fails closed to a sentinel id that matches nothing.
- 4Requested rep ids are intersected with the allowed set, so a crafted request can never widen access.
- 5crew_lead and worker roles get a 403 outright.
The route header spells it out — it 'enforces its OWN per-rep lead visibility (it does NOT route through /api/db)'. The underlying visibility module states the failure mode: 'Fails CLOSED: any lookup error degrades to "own" (the most restrictive non-admin scope), never to "all".'
- Reporting endpoints are a classic back door around record-level permissions.
- A lookup failure that defaulted open would leak the whole book.
See it on your own jobs
Twenty minutes, your numbers, no slide deck. We’ll build one of your real buildings in front of you and send you the estimate link at the end — yours to keep either way.
or keep browsing features →