Who Can See Whose Leads

Each rep sees only their own leads by default; a manager can be granted a chosen set of reps or the whole book — enforced on the server, not in the browser.

What it is

Three scopes per person: own leads only (the default when no policy exists), selected reps (a sales manager over a chosen subset), or all leads. Admins and the owner always see everything and need no policy row. The restriction is applied at the data proxy, so a restricted user can never read another rep's leads regardless of what their browser asks for.

Also called: rep can only see their own leads · sales manager view · lead privacy · stop reps poaching

See it
Who Can See Whose Leads
New lead 2
Marlin Hoover
$44k
Delia Yoder
$22k
Sutter Kline
$44k
Contacted 3
Sutter Kline
$49k
Ronan Petsch
$45k
Estimate 2
Ivy Brubaker
$43k
Gideon Alt
$72k
Sold 4
Marlin Hoover
$64k
Delia Yoder
$52k
Sutter Kline
$65k
The Lead Access settings list: one row per team member with a scope dropdown, admins shown as a non-editable 'Sees all leads' row. Sample data — no customer information appears here.
How it works
  1. 1Scope is resolved server-side and cached briefly per user
  2. 2It fails closed — any lookup error degrades to own-leads-only, never to all
  3. 3The board asks for its own scope purely so it can hide a toggle that would do nothing; the enforcement is elsewhere
  4. 4Team scope stores both user ids and their emails, so an assignment made before a rep's id exists still resolves
  5. 5Supplier, team and contractor records are exempt, because those are not leads
  6. 6Reassignment routes apply the same restriction, so a rep cannot reassign leads their scope hides
Why we built it

A rep who can read the whole company's book can walk out with it. Each rep now sees only their own leads by default, a manager can be granted a chosen set of reps or everything, and the rule is enforced on the server at the single point all data passes through — a restricted user cannot read another rep's leads no matter what their browser asks for. It fails closed: any error looking up a scope degrades to own-leads-only, never to everything, and a user matching neither an id nor an email matches no leads rather than all of them. Scope changes save one rep at a time, so narrowing someone's access is never silent.

The problem
  • Client-side-only privacy that any browser can bypass
  • All-or-nothing visibility with no manager tier
  • An error opening up access instead of closing it
Sound familiar?
What you get
Reps see their book and nobody else's
Managers can be scoped to exactly the reps they run
A failure makes access tighter, never looser

See it on your own jobs

Twenty minutes, your numbers, no slide deck. We’ll build one of your real buildings in front of you and send you the estimate link at the end — yours to keep either way.

or keep browsing features →