Zoho CRM's Default Data Sharing Process Explained

Default Data Sharing Process

By default, access to records in Zoho CRM is set to Private, meaning only a record's owner and their superiors in the role hierarchy can see it. Data Sharing Rules let you extend access beyond that default to other roles and groups, without opening up the whole module.

The four access levels

  • Private. Only the record owner and their superior can view the record.
  • Public Read Only. Users can view others' records but cannot modify or delete them.
  • Public Read/Write. Users can view and modify others' records but cannot delete them.
  • Public Read/Write/Delete. Users can view, modify, and delete others' records.

How this interacts with Data Sharing Rules

If a module's organisation-wide default is set to any of the Public options, everyone already has that level of access, and Role Hierarchy and Sharing Rules have no further effect, since there's nothing left to restrict or extend. Sharing Rules only become meaningful when a module is set to Private, since that's the only setting where Role Hierarchy and additional Sharing Rules actually apply.

Important: Sharing Rules can only extend access beyond the organisation-wide default. They cannot be used to restrict access below it. If you need tighter visibility, set a more restrictive organisation-wide default, such as Private, and then grant specific exceptions through Sharing Rules, rather than trying to lock things down with a rule on a module that's already Public.

The "Superiors Allowed" option

When you grant a role or group access to records via a Sharing Rule, you can also tick Superiors Allowed, which extends that same access to the superiors of the role receiving it. This is useful when a manager needs to see whatever their team has been granted visibility into. Leave it unticked if you want the access limited strictly to the named role or group.

A few related points worth knowing

  • In Import History, records belonging to you and your subordinates are always shown, regardless of sharing settings.
  • Attachments, Notes, and Competitors on a record follow the visibility of that record itself, so if you can see the record, you can see these too.
  • Forecasts are always private, regardless of your module-level data sharing settings.
Need help? 1 Cloud Consultants can help you design a data sharing structure that gives the right people the right visibility, without over-exposing sensitive records. Book a discovery call with 1 Cloud Consultants.