Three scopes per person: own leads only (the default when no policy exists), selected reps (a sales manager over a chosen subset), or all leads. Admins and the owner always see everything and need no policy row. The restriction is applied at the data proxy, so a restricted user can never read another rep's leads regardless of what their browser asks for.
Also called: rep can only see their own leads · sales manager view · lead privacy · stop reps poaching
- 1Scope is resolved server-side and cached briefly per user
- 2It fails closed — any lookup error degrades to own-leads-only, never to all
- 3The board asks for its own scope purely so it can hide a toggle that would do nothing; the enforcement is elsewhere
- 4Team scope stores both user ids and their emails, so an assignment made before a rep's id exists still resolves
- 5Supplier, team and contractor records are exempt, because those are not leads
- 6Reassignment routes apply the same restriction, so a rep cannot reassign leads their scope hides
A rep who can read the whole company's book can walk out with it. Each rep now sees only their own leads by default, a manager can be granted a chosen set of reps or everything, and the rule is enforced on the server at the single point all data passes through — a restricted user cannot read another rep's leads no matter what their browser asks for. It fails closed: any error looking up a scope degrades to own-leads-only, never to everything, and a user matching neither an id nor an email matches no leads rather than all of them. Scope changes save one rep at a time, so narrowing someone's access is never silent.
- Client-side-only privacy that any browser can bypass
- All-or-nothing visibility with no manager tier
- An error opening up access instead of closing it
See it on your own jobs
Twenty minutes, your numbers, no slide deck. We’ll build one of your real buildings in front of you and send you the estimate link at the end — yours to keep either way.
or keep browsing features →