top of page
CodeStringers Logo

HOW TO EXPLORE FIT

See whether we're the right partner — before you commit to anything.

No-Risk Discovery is a short, practical conversation that gets you a clear view of your options — with no obligation to keep working with us.

Zoho CRM Data Sharing Rules, Explained: Granting Access the Hierarchy Can't

  • 10 hours ago
  • 4 min read
Abstract editorial illustration of controlled data access: private record nodes with selective bridges extending access between two teams, cool blue palette.


Data sharing rules in Zoho CRM let you grant specific users access to records they wouldn't otherwise see — extending visibility beyond what the role hierarchy allows, without changing your org chart. They're the exception layer of Zoho's security model: the role hierarchy sets the baseline, and sharing rules open up carefully chosen cross-team access on top of it. Used well, they let you keep data locked down by default and still let the right people collaborate, which is exactly the balance we design as Zoho CRM consultants. This guide explains how they work and where the sharp edges are.


Why bother with tight access at all? Because most breaches aren't sophisticated — Verizon's 2024 report found a human element in 68% of them (Verizon DBIR). The fewer records each person can touch, the smaller the damage when someone clicks the wrong thing. Sharing rules let you start from least privilege and open up only where there's a real reason.


Data sharing rules in Zoho CRM, explained

A data sharing rule grants extra access to records for users in roles, groups, or territories beyond what the hierarchy gives them (Zoho). The critical thing to understand — and the source of most confusion — is direction: rules only ever extend access; they can never restrict it. In Zoho's own words, "you cannot restrict the accessibility set in Organization's default permissions by writing the Sharing Rules. You can only extend the additional data visibility."


That one sentence changes how you think about the whole model. You don't tighten access with sharing rules; you tighten it with the org-wide default, then loosen it, precisely, with rules.


Organization-wide default sharing settings

Every module starts with a baseline visibility level, set at Setup → Users & Permissions → Data Sharing Settings. There are four (Zoho):


Default level

What it means

Private

Only the record owner and their superiors can see the record

Public Read Only

Everyone can view others' records, but not edit or delete

Public Read/Write

Everyone can view and edit, but not delete

Public Read/Write/Delete

Everyone can view, edit, and delete


By default, modules are Private — which is the right instinct for anything sensitive. The pattern that scales best is Private + sharing rules: lock the module down, then grant specific cross-team access where the business genuinely needs it.


How the hierarchy sets the floor, and rules raise it

When a module is Private, only the record owner and the people above them in the role hierarchy can see a record. Everyone else — including peers on other teams — is locked out. A sharing rule is how you open a specific door: "let the Support team see the Sales team's Deals," for example, without making the whole Deals module public.


One option worth knowing is the "Superiors Allowed" setting. When you grant a role access via a rule, ticking Superiors Allowed also extends that access to the superiors of the receiving role — useful when a manager needs to see whatever their team can see.


Owner-based vs. criteria-based rules

Zoho gives you two ways to define who gets the extra access:


  • Owner-based rules share records based on who owns them — e.g., records owned by the West team become visible to the East team.

  • Criteria-based rules share records that match field conditions — e.g., any Deal over $100,000 becomes visible to the finance group, regardless of owner.


Criteria-based rules are the more surgical tool: they let you share exactly the slice of records that matters instead of an entire team's book.


Sharing rules vs. roles vs. territory management

These three mechanisms overlap, so pick by intent:


  • Role hierarchy governs the baseline — visibility by ownership and org position.

  • Data sharing rules are flexible, exception-based extra access outside the hierarchy.

  • Territory management structures access by account characteristics (geography, industry, size), lets users belong to multiple territories, and supports multiple forecasts. Reach for it when your model is characteristic-driven or when maintaining many sharing rules has become a chore.


If you find yourself writing dozens of sharing rules to reproduce a pattern, that's usually a sign the underlying model — roles or territories — needs rethinking, which is the kind of cleanup our Zoho integration and broader business systems consultant work often starts with. It also sits alongside how you've set up assignment rules.


Editions, limits, and setup

Here's the fact that catches people out: data sharing rules are an Enterprise and Ultimate feature only — Free, Standard, and Professional don't include them (Zoho). Enterprise allows up to 25 rules per module (up to 10 criteria-based); Ultimate raises that to 100 per module (up to 15 criteria-based). The org-wide default setting exists more broadly, but the rule-building itself needs Enterprise or above. As always, confirm current limits against Zoho's live comparison page before you design around them.


FAQ

Can data sharing rules restrict access in Zoho CRM? No. Sharing rules only ever extend access beyond the org-wide default and the role hierarchy — they can never take access away. To restrict visibility, set a more restrictive organization-wide default (for example, make the module Private) and then grant exceptions with rules.


What does the "Superiors Allowed" option do? When you share records with a role or group through a rule, enabling Superiors Allowed also gives the superiors of that receiving role access to the same records. Leave it off if you want only the specific role to gain visibility, not everyone above them.


How is sharing a single record different from a sharing rule? A sharing rule applies broadly and automatically to a whole set of records (by owner or criteria). Sharing an individual record — via More Actions → Share — is a one-off grant to specific users, roles, or groups, capped per record. Use rules for repeatable patterns and record sharing for genuine one-offs.


Where to start

Audit your modules' org-wide defaults first. If sensitive modules aren't Private, that's the place to begin — tighten the baseline, then add sharing rules only for the specific cross-team access people actually need. Least privilege first, exceptions second.


If you'd like your sharing model designed so it's secure and not a maintenance headache, book a free Zoho consultation and we'll map your defaults, rules, roles, and territories to how your teams really need to collaborate.


By the CodeStringers Team — Zoho Experts & Custom Software. CodeStringers is a Zoho and custom-software firm writing from work we've actually shipped for clients.

Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating

Subscribe

Recent Posts

bottom of page