Access#
Actions run as the same user ECA already uses for the model. CRM ECA does not switch accounts. Models that run as anonymous (for example webhooks) should switch user with eca_user before mapping or write actions.
Permission by action#
| Action | Access |
|---|---|
| Load mapped contact | Always allowed |
| Load mapped user | Always allowed |
| Find contact by email | Always allowed |
| Map user to contact | Mapping entity admin permission (administer crm) |
| Ensure contact for user | Mapping entity admin permission |
| Unmap user from contact | Mapping entity admin permission |
| Add email / telephone / address | Update access on the resolved contact |
| Create relationship | CRM create access for the selected relationship type |
Add-method access is forbidden if the contact cannot be resolved at access time.
Mapping failures#
CRM: map user to contact throws when:
- The user or contact cannot be resolved
- The contact is not a person
- A mapping already exists for the user or contact
That is intentional so webhook models can return an error and retry instead of silently skipping.
Unmap throws when no mapping is found. Create relationship throws when CRM validation fails (type constraints, duplicate relationships, and so on).
Conditions and entity queries#
CRM: contacts are related uses an entity query with access checking
enabled. Other conditions only inspect mapping services or contact
method storage and do not apply extra permission checks beyond what
those APIs do.