The UTA/Module Security Matrix controls how users interact with records in a UTA/module and its associated entities, defining what each role can view, add, edit, delete, or assign at every data level — Level 1, Level 2, and Level 3.
Rather than giving all users the same access, the UTA/Module Security Matrix lets you tailor permissions by role. For each role, you can configure access independently at each level, so a user might have full access at Level 1 but view-only access at Level 2.
Who: Global administrators
When to Use the UTA/Module Security Matrix
Use the UTA/Module Security Matrix when:
- Different user groups need different levels of access to records within the same UTA/module.
- Some users should only see records they own or are directly assigned to.
- A specific role needs to be denied access to certain record types entirely.
- Setting up a new UTA/module that will be used by multiple roles with different responsibilities.
How the UTA/Module Security Matrix Works
The UTA/Module Security Matrix page is organized into tabs, one for each data level in the UTA/module (Level 1, Level 2, and Level 3, where applicable). Each tab displays the same set of roles, and permissions are configured independently per level.
Only roles selected in the Access Role Settings appear in the matrix. For each role listed, the matrix shows the following column options: Access, Deny, View, Add, Edit, Delete, and Assign. You configure each permission by selecting the appropriate role engagement level (All, Owner, Assigned, Organizations, or Person) for that action.
Role Engagement Access for the UTA/Module Security Matrix
All access in the UTA/Module Security Matrix is role-based. For each permission, you choose which users within a role are subject to the permission using one of the following engagement types:
- All — All users in this role can perform the designated action.
- Owner — Only the user linked to the record through the Owner standard field can perform the action.
- Assigned — Only users assigned to the record via the Assigned standard field, or listed as a contact with this role, can perform the action.
- Person — Only users linked to the record through the Person standard field can perform the action.
- Organizations / Accounts — Only users in this role whose organization is associated with the record as an Account can perform the action. This is an indirect permission: if a company is linked to a project and this option is used, a user from that company holding this role gains access.
- Customer — Only users in this role whose organization is associated with the record as a Customer can perform the action.
- Branch — Only users in this role whose organization is associated with the record as a Branch can perform the action.
Permission Types for the UTA/Module Security Matrix
The following six permission types are available for each role at each data level:
- Deny — Prevents users in this role from accessing the item entirely.
- View — Allows users to view the item.
- Add — Allows users to create a new item.
- Edit — Allows users to modify an existing item.
- Delete — Allows users to remove an existing item.
- Assign — Allows users to assign other contacts to the item.
Security Implications
Global administrator privileges are required to enable the UTA/Module Security Matrix.
Resources
For more information about the UTA/Module Security Matrix, see: