Permissions
CRM permissions are defined in crm.permissions.yml and extended dynamically
for each contact type and relationship type bundle.
Grant permissions at Admin > People > Permissions (/admin/people/permissions).
Static permissions
Administration
| Permission | Machine name | Notes |
|---|---|---|
| Administer CRM | administer crm |
Restrict access; full CRM admin |
| Access CRM | access crm |
Portal landing and CRM menu sections |
Contacts (any bundle)
| Permission | Machine name |
|---|---|
| Create any contact | create any crm contact |
| View any contact | view any crm contact |
| View any contact label | view any crm contact label |
| Edit any contact | edit any crm contact |
| Delete any contact | delete any crm contact |
Contact revisions
Revision operations also require access to the contact itself: view for
view all revisions and view revision, update for revert, and delete
for delete revision.
| Permission | Machine name |
|---|---|
| View all contact revisions | view all crm contact revisions |
| View contact revision | view crm contact revision |
| Revert contact revision | revert crm contact revision |
| Delete contact revision | delete crm contact revision |
Mapped contacts (user integration)
| Permission | Machine name |
|---|---|
| View mapped contact | view mapped crm contact |
| Edit mapped contact | edit mapped crm contact |
| Alter user display name | alter crm user display name |
These role permissions are one path to mapped-contact access. The mapping
entity also has grant_* fields that write rows to crm_contact_access
and can allow view, update, or delete on that contact without the
corresponding mapped-contact permission. administer crm still bypasses
all checks. See Hooks.
Search integration (requires Search module)
The following permission is only available when Drupal core Search is enabled.
It is defined by the SearchPermissions callback and absent from the
permissions UI when Search is disabled.
| Permission | Machine name |
|---|---|
| Search contacts | search crm_contact |
Relationships (any bundle)
| Permission | Machine name |
|---|---|
| Create any relationship | create any crm relationship |
| View any relationship | view any crm relationship |
| Edit any relationship | edit any crm relationship |
| Delete any relationship | delete any crm relationship |
Relationship revisions
Revision operations also require access to the relationship itself: view
for view all revisions and view revision, update for revert, and
delete for delete revision.
| Permission | Machine name |
|---|---|
| View all relationship revisions | view all crm relationship revisions |
| View relationship revision | view crm relationship revision |
| Revert relationship revision | revert crm relationship revision |
| Delete relationship revision | delete crm relationship revision |
Bundle-generated permissions
ContactTypePermissions and RelationshipTypePermissions add four permissions
per bundle when a contact type or relationship type exists.
SearchPermissions exposes the search crm_contact permission only when the
Search module is enabled.
Contact type (example: person)
| Pattern | Example |
|---|---|
| Create | create person crm contact |
| View | view any person crm contact |
| View label | view any person crm contact label |
| Edit | edit any person crm contact |
| Delete | delete any person crm contact |
Relationship type (example: employee)
| Pattern | Example |
|---|---|
| Create | create employee crm relationship |
| View | view any employee crm relationship |
| Edit | edit any employee crm relationship |
| Delete | delete any employee crm relationship |
New bundles receive permissions automatically after cache rebuild.
Media on contacts
The contact media field is a primary entity reference to media. Creating or
updating media from the contact form uses Media module permissions for the
types the site allows (for example create image media and view media).
CRM does not grant those permissions itself. Restrict target bundles on the
field if only some media types should be selectable.
Related documentation
- CRM menu —
access crmpermission - User integration — mapped contact permissions
- Contact entity — access control behavior
- Contact method entity — inherits parent contact permissions
- Hooks — grant API and field-mapping exclusions