Skip to content

System and permissions

How roles and permissions work

Three layers decide who sees what in MetoCRM: the role, the group-manager flag and the assignment. "Manager" in a role name grants nothing alone.

Last updated:

Where to find it

UsersRoles

"What can this user see?" is never answered by a single setting in MetoCRM. Three independent layers decide it together: the user's role, the manager flag on their group membership, and the assignment made on the record itself. When a consultant cannot see a patient, the cause is usually one of the last two — not the role.

The most common mistake is giving someone a "Sales Team Manager" role and expecting them to see the whole team's patients. The word "manager" in a role name grants no extra visibility. Department-wide visibility comes from the manager flag on that user's group membership.

Before you start

  • You need the Admin role to open the role and permission screens.
  • Decide which group the user belongs to before assigning a role — see how to create a user group.

Step by step

  1. Open Users → Roles from the left-hand menu. Every role defined in the system is listed here with the permissions attached to it.
  2. When you create or edit a user, pick the right role in the Role field. A role decides which screens the user can open — not which records they can see.
  3. Add the user to a user group. Group membership on its own grants no visibility; a plain member sees only the records personally assigned to them.
  4. For department-wide visibility, tick the group manager flag on that user's group row. Seeing every patient, conversation and quote in the group comes from this flag, and so do lead assignment and group notifications.
  5. Save, then verify: sign in as the user and open a patient they should be able to see. If the change is not visible straight away, the user needs to refresh their session.

Tips and common mistakes

  • Careful The Admin, Moderator and internal Meto Supervisor roles bypass every visibility filter — a user in one of these roles sees every record in the tenant. The only exception is that Moderator cannot reach the audit log.
  • Careful A quote has no visibility rule of its own: seeing a quote is the same thing as seeing its patient. When a consultant cannot open a quote, it is almost always because they have no access to the patient.
  • Tip The Viewer role is read-only — a good fit for a partner who needs to follow the numbers without touching a record.
  • Tip To hide phone numbers and e-mail addresses from certain roles, use data masking rather than cutting permissions. The user keeps working on the patient but never sees the contact details.

Frequently asked questions

I gave a user a manager role but they still cannot see their team's patients. Why?

The word "manager" in a role name grants nothing. The user has to be flagged as a group manager in the sales or operation group those patients belong to. Check that flag on the group row before changing the role.

Does a group member see all of the group's patients?

No. Without the manager flag they see only what is personally assigned to them: records where they are the conversator, the owner, a participant or the coordinator. Group membership alone opens nothing.

A consultant has left. What happens to their patients?

The records stay on the patient; only the personal assignment is lost. Assign the replacement consultant to the patient, or transfer the conversation to them. Group managers keep seeing those records throughout.

Do reports follow the same filter?

Lists apply the same filter as patient visibility. Some reports run tenant-wide, so confirm what a restricted user would actually see before granting them a report screen.

Related modules