Role Permissions give administrators control over what each user role can see, access, edit, and do throughout Shape.
Instead of configuring permissions one user at a time, permissions are assigned by role. When you update a permission for a role, the change applies to users assigned to that role.
For example, you can use Role Permissions to:
- Control which dashboards users can access
- Hide dashboards entirely and send users directly into their primary working view
- Control access to Shape products and features
- Restrict which profile fields users can edit
- Allow or restrict actions such as manually adding records or performing bulk actions
- Control who can change communication and compliance preferences
- Control access to administrative settings
- Hide certain navigation options for specific roles
This gives you a way to simplify Shape for everyday users while giving managers, directors, and administrators the additional tools they need.
Accessing Role Permissions
Navigate to Settings › Users & Permissions › Role Permissions.
You can also access Role Permissions directly.
The Role Permissions page organizes permissions into several categories:
- Dashboard Views
- Shape Product Access
- User Profile Permissions
- Feature Authorization
- Global Settings Page Access
Use the search bar at the top of the page to quickly locate a specific permission.
Expand a category to view its available permissions and select which roles should have access.
When you are finished, click Save Permissions.
Dashboard Views
Dashboard Views control which dashboards and launchpad views are available to each user role.
If a dashboard is enabled for a role, users with that role can access it. If it is disabled, that dashboard will not be available to those users.
This is useful for organizations that want different roles to have different starting experiences in Shape.
Bypassing Dashboards Entirely
You do not have to give a role access to a dashboard.
If you prefer users to skip the Launchpad and dashboards entirely, you can remove access to all Dashboard Views for that role.
When no dashboard is available, users can go directly to their first prioritized working view instead.
This is often a good configuration for users whose primary job is to immediately begin working records rather than reviewing dashboards.
For example, a sales user might log in and go directly to a prioritized lead or transfer list instead of landing on a dashboard first.
Shape Product Access
Shape Product Access controls which Shape products and major product areas are available to each role.
Use this section when your organization has Shape functionality that certain users do not need.
Removing access can help simplify the interface by keeping users focused on the products that are relevant to their job.
ShapeAI Access
ShapeAI access can also be controlled through Role Permissions.
When ShapeAI access is disabled for a role, the ShapeAI option is hidden for users with that role, including its sidebar access.
This allows organizations to make ShapeAI available only to the teams or roles that should use it.
User Profile Permissions
User Profile Permissions control which elements of a user’s profile they are allowed to edit.
This is useful when administrators want to maintain control over certain user information rather than allowing every user to modify all of their own settings.
Depending on your system configuration, this can include profile information used throughout Shape for communication, routing, branding, integrations, or other functionality.
If you do not want users changing a particular profile setting themselves, restrict the applicable permission for their role.
Feature Authorization
Feature Authorization controls what users are allowed to actually do within Shape.
This is different from simply controlling whether a user can see a page.
Feature Authorization can govern actions such as:
- Manually adding records
- Performing bulk actions
- Changing certain communication preferences
- Accessing specific navigation features
- Using other protected functionality
This section is particularly important when you want users to work within Shape while limiting higher-impact actions to managers or administrators.
Manually Adding Records
The Manually Add Records permission controls whether a role can manually create new records.
By default, user roles may be allowed to manually add records.
If this permission is disabled for a role, users with that role cannot use the applicable + or Add controls to manually create records.
This is useful for organizations where records should only enter Shape through approved sources such as:
- Lead providers
- Imports
- Integrations
- APIs
- Automated distribution
- Corporate teams
Users can continue working the records they have access to without manually creating additional records.
Communication and Compliance Permissions
Shape also provides role-level controls over who can remove certain communication and compliance restrictions from a record.
These permissions deserve special attention because changing them can affect whether a contact is eligible to receive future communications.
Feature Authorization can include permissions for:
- Do Not Contact Opt-In
- Do Not Call Opt-In
- Texting Opt-In
- Email Unsubscribe Opt-In
- 1:1 or TCPA Consent Opt-In
By default, these permissions should be limited to Admin and Director-level roles.
Turning Restrictions On vs. Removing Them
There is an important distinction between applying a communication restriction and removing one.
Users can apply applicable opt-out or Do Not Contact preferences when needed.
However, once a preference such as DNC, Do Not Call, Text Opt-Out, or Email Unsubscribe has been enabled, only roles with the corresponding Feature Authorization permission can remove or reverse that selection.
For example, if a contact is marked Do Not Call, a standard user can see that preference but cannot simply turn it off unless their role has specifically been granted permission to do so.
This allows organizations to protect compliance-related preferences while still giving authorized personnel a way to manage legitimate opt-in changes when appropriate.
Navigation and Industry-Specific Permissions
Some Feature Authorization permissions may only appear when they apply to your Shape configuration or industry template.
For example, insurance configurations can control whether particular roles can see the Policies menu in the top navigation.
If Policies access is enabled for a role, the Policies navigation option is available to that role.
If it is disabled, the Policies option is hidden.
Other industry-specific permissions may appear depending on the products and workflows configured for your organization.
Global Settings Page Access
Global Settings Page Access controls which administrative settings pages each role can access.
This is one of the most important sections to review carefully.
Giving a role access to a Global Settings page means users with that role may be able to manage settings that affect the organization as a whole, not just their individual account.
Depending on the permission, this can include areas related to:
- Users and permissions
- Sales and marketing
- Phone settings
- Custom configuration
- Apps and integrations
- Templates and resources
- System preferences
- Account management
We recommend limiting global settings access based on each role’s actual administrative responsibilities.
A user does not need access to the Settings area simply because they need to use a feature controlled by those settings.
Other Permission Settings in Shape
Role Permissions are only one part of Shape’s access-control system.
Shape separates certain permissions into their own settings pages because they control different aspects of the CRM.
Record Visibility by Role
Record Visibility by Role determines which records a user can see.
For example, a role can be configured to see:
- Assigned Records Only
- All Records
- Team Records, where applicable
- Assigned Records plus applicable referral partner records
Visibility can also vary by record type.
Shape separately provides visibility controls for areas such as Master Search and the shared communication inbox.
For complete instructions, see the Record Visibility by Role guide.
Record Assignment Permissions
Record Assignment Permissions determine which roles are allowed to assign or reassign records.
You can also use these settings to control how many records a role can assign within a day.
Access Record Assignment Permissions.
Report Access Permissions
Report Access Permissions determine which reports each role can access.
This allows administrators to make operational, performance, distribution, or other reports available only to the appropriate roles.
Report permissions include supported reports such as Contact Assignment & Distribution, allowing organizations to control access to assignment and distribution reporting separately from general CRM permissions.
Access Report Access Permissions.
Understanding the Different Permission Types
A simple way to think about Shape’s permission settings is:
| Setting | Controls |
|---|---|
| Dashboard Views | Which dashboards and launchpad views a role can access |
| Shape Product Access | Which Shape products and major product features a role can use |
| User Profile Permissions | What users can edit within their own profiles |
| Feature Authorization | What actions and functionality a role is authorized to use |
| Global Settings Page Access | Which organization-wide settings a role can manage |
| Record Visibility by Role | Which CRM records a role can see |
| Record Assignment Permissions | Who can assign or reassign records |
| Report Access Permissions | Which reports a role can access |
This distinction is important.
For example, giving someone permission to view a record does not necessarily mean they should be able to reassign it, and allowing someone to use a feature does not necessarily mean they should be able to change the global settings for that feature.
Recommended Permission Strategy
For most organizations, it is helpful to start with the minimum access each role needs to do its job and add permissions intentionally.
Standard Users
Standard users generally need access to their day-to-day working views, records, communication tools, and other features required for their role.
They typically do not need broad Global Settings access or the ability to reverse compliance-related opt-outs.
Managers
Managers may need broader record visibility, reporting, assignment capabilities, bulk actions, or team-level functionality.
They still may not need organization-wide administrative settings.
Directors
Directors often require broader operational permissions and may be authorized to manage protected functionality such as communication opt-in settings.
Admins
Admins generally have the broadest access and are responsible for organization-wide configuration.
Your exact setup can differ. Shape’s role-based controls are designed so you can configure permissions around your organization’s responsibilities rather than forcing every company into the same structure.
Frequently Asked Questions
Do I have to configure permissions separately for every user?+
No. Role Permissions apply to the role.
If you change a permission for the User role, users assigned that role receive the corresponding access. This makes it much easier to maintain consistent permissions as your team grows.
Can I remove access to every dashboard?+
Yes. Dashboard access can be removed so users bypass dashboards and go directly to their first prioritized working view.
This is a useful setup for teams that want users to begin working immediately after logging in.
Can I prevent users from manually creating records?+
Yes. Disable Manually Add Records under Feature Authorization for the applicable role.
The applicable Add or + controls will no longer be available for that role.
Can I prevent a user from changing their own profile settings?+
Yes. Use User Profile Permissions to control which supported profile elements a role can edit.
Can standard users mark someone as Do Not Call or opted out?+
Users can apply applicable restrictions. The more sensitive permission is the ability to remove or reverse an existing restriction.
Can I prevent standard users from removing DNC or communication opt-outs?+
Yes. The applicable Feature Authorization permissions control which roles can reverse those settings.
By default, these permissions should be limited to Admins and Directors. You can grant additional roles access when your organization’s policies allow it.
Does changing an opt-in permission automatically change a contact’s consent?+
No. The role permission determines whether the user is authorized to change the setting. It does not itself change any contact’s communication preferences.
Can I hide ShapeAI from certain roles?+
Yes. If ShapeAI access is removed through Role Permissions, ShapeAI is hidden from users with that role.
Can I hide Policies from certain users?+
Yes, for applicable insurance configurations. Policies navigation visibility can be controlled by role. If the permission is disabled, the Policies menu is hidden for that role.
Can Role Permissions control which records a user sees?+
Not directly.
Use Record Visibility by Role for record-level visibility. Role Permissions control access and functionality, while Record Visibility determines which records a user can see. Shape supports different visibility rules by role and record type.
Can I control who is allowed to assign records?+
Yes. Use Record Assignment Permissions to determine which roles can assign records and configure applicable daily assignment limits.
Can I control which reports users see?+
Yes. Use Report Access Permissions to control report availability by role.
What is the difference between Feature Authorization and Global Settings Page Access?+
Feature Authorization determines whether a role can perform a particular action or use particular functionality.
Global Settings Page Access determines whether the role can access and manage organization-wide configuration pages.
Someone may need permission to use a feature without needing permission to configure it for the entire organization.
What happens when I change a role permission?+
The permission applies to users assigned to that role. You do not need to update each user individually.
Should everyone have access to Global Settings?+
Usually, no.
Global Settings can affect other users and organization-wide behavior, so those permissions should generally be limited to roles responsible for administering the system.