Our User Roles article covers how to build and assign roles. This article covers the exceptions and edge cases that don't behave the way the main article implies — negative permission flags, System Admin exceptions, and multi-lot access.
Questions this answers
- "How do I add a new salesperson and limit them to only their own leads and deals?"
- "If I set the 'Assigned To' field on a lead to a specific salesperson, does that stop everyone else on my team from seeing that lead or that deal?"
- "I set my sales reps up with roles on the commission tab — sales rep, F&I, closer. Does that control what each of them can see?"
- "I turned on 'Prevent Editing Closed Deal' for our finance manager's role thinking I was giving her more control, and now she has less access than before. Why would checking a permission box take something away instead of adding it?"
- "I turned on 'Access only to Current Lots Contacts' for a role, but our System Admin account is still only seeing that one lot's contacts. Shouldn't the admin see everything regardless?"
- "I gave one of our managers Full access to deals at our other location so she could work from either lot, but when she's logged in at our main lot and pulls up the other lot's deals, everything shows as view-only. Isn't Full access supposed to mean Full everywhere she's allowed?"
- "I deactivated one of our lots temporarily, and now our System Admin account can't do anything there either. I thought Admins had access to everything no matter what?"
Assigning a sales rep is not the same as restricting what they can see
These are two different things, and it's worth separating them before you go looking for a setting.
Assigning people to a deal does work. On a deal's Commission tab you can name the users who participated and the role each played — Rep, F&I, Closer, Store Manager, General Manager, Collector, or Other. That drives commission calculation, credit for the sale, and reporting. On a lead or contact, the Assigned To field does the same job, and it is stamped automatically to whoever creates a new prospect.
What assignment does not do is hide the record from anybody else. Any user whose role has View access or higher to Contacts or Deals at a lot can see every lead, prospect, and deal at that lot, whoever is assigned. The Collector and Assigned To boxes on the search screens are ordinary filters: a sales rep can clear one, or pick a different name in it, and immediately see everyone else's records. Saving a favourite search with a name pre-filled doesn't change that either — the filter is still theirs to change.
So if your goal is "this rep should only ever see their own deals," that isn't configurable today. It's a feature request to AutoManager, not a setting to hunt for. What you can do instead:
- Restrict what they see on a record, rather than which records. Role permissions do enforce hiding cost, pack, wholesale figures, the recap, and the commissions tab — see the negative flags below.
- Hide wholesale deals from the deal list entirely with the wholesale permission. This is the one place a deal list is genuinely filtered for the user and cannot be undone by them — but it filters by sale type, not by who the deal belongs to.
- Limit them to one lot. Lot scoping is enforced, so a rep assigned to a single lot cannot see another lot's records.
- Use assignment for reporting, not for privacy: assign the Rep on the Commission tab, then run the commission and sales reports by user.
Two places per-user visibility is enforced
Don't over-generalise from the above — DeskManager Online does enforce "only mine" in two specific places:
- Tasks. If a user's role does not grant Task – view others, their task list is restricted to tasks assigned to them and they cannot widen it.
- Saved reports. A report definition saved with User scope is visible only to the user who saved it.
Neither of these extends to deals, leads, contacts, or inventory.
Negative permission flags: checking the box can take access away
Most permissions in Setup > Organization > Roles work the way the User Roles article describes: checking a box grants access. A small set of permissions work backwards — checking them restricts what the role can do:
- Prevent Editing Closed Deal
- Hide Wholesale
- Hide Commissions Tab
- Hide Attachments Tab
- Prevent Report Save & Close
If you check Prevent Editing Closed Deal on a role thinking you're granting more control, you're actually locking that role out of editing deals once they're closed. This is the opposite of the "checking a box allows access" rule described for the rest of the Roles page, so it's easy to get backwards — double-check any permission with wording like "Prevent" or "Hide" before assuming checking it opens something up.
Permissions your System Admin role does not override
The built-in Admin system role bypasses almost every permission check, but two situations are exceptions:
- Access only to Current Lots Contacts. If this restriction is turned on for a role, it still applies to a System Admin user holding that role — the admin bypass is deliberately skipped for this one setting. Turning it on for a role means everyone in that role, admins included, only sees contacts tied to whichever lot they're currently working in.
- A deactivated lot. If a lot's status isn't Active, a System Admin gets no access there (or, for the "negative" flags above, full access to the restriction itself) just like any other user. Reactivating the lot restores the admin's access — being an Admin does not let you work in a lot that's been turned off.
Full/Edit access to another lot still shows as View-only
Granting a role Full or Edit access at a lot other than the one a user is currently working in does not mean they get full edit rights the moment they pull up that other lot's records. Unless a separate cross-lot allowance is turned on for that access check, the system automatically caps access to View-only the instant the record's lot isn't the user's current lot — even if their role says Full there. This exists so a screen that defaults to "the current lot" can't accidentally edit another lot's data.
Two more things worth knowing:
- Even with the cross-lot allowance on, it only lifts the View-only cap — it doesn't make a search or list pull in records from multiple lots at once. The query stays scoped to whichever lot you're looking at; to actually work in the other lot's data, the user still has to switch lots.
- Role assignment is per (user, lot) pair with no inheritance and no "apply to all lots" shortcut. A user can be "Sales Manager" in Lot A and have no role at all in Lot B — zero access at Lot B even though their account is active. A role needing to apply everywhere must be checked in every lot.
When to contact support
- You believe a salesperson saw records they shouldn't have and suspect it isn't the "Assigned To" attribution behavior described above.
- A role's access doesn't match what's checked on the Roles page after confirming it's assigned in the correct lot(s).
- A lot shows as deactivated and you don't know why, or reactivating it doesn't restore expected access.
For login/account issues (no lots assigned, invite or password reset problems), see Fixing Login Problems: No Lots Assigned, Invites and Password Resets instead.
Comments
0 comments
Article is closed for comments.