00
Days
:
00
Hours
:
00
Minute
:
00
Second

Permission Manager

The Permission Manager gives you precise control over which WordPress users can access GemCRM features. Rather than granting full admin access just so someone can manage contacts or send campaigns, you can assign only the specific permissions they actually need.

Note: This feature requires GemCRM Pro. If Pro is not active, the Permission Manager tab will display an upgrade prompt instead.

How It Works

GemCRM operates its own permission layer on top of standard WordPress roles:

  • WordPress Administrators (manage_options) automatically have full access to every GemCRM feature. They do not appear in the Permission Manager and cannot be restricted.
  • All other users — Editors, Authors, Subscribers, or any custom role — have no GemCRM access by default. You grant access one permission at a time using this tool.
  • Permissions are granular. For example, you can allow someone to view contacts without letting them delete records, or allow them to send campaigns without exposing plugin settings.

Getting to the Permission Manager

  1. In the WordPress sidebar, navigate to GemCRM → Settings.
  1. Click the Permission Manager tab from the left settings menu.
Permission Manager

The User List

The main screen displays all non-admin WordPress users with one or more GemCRM permissions, along with their name, email address, and the total number of permissions granted.

Permission Manager Setting

Adding a User

  1. Click Add New User (top-right button).
  1. Type at least 2 characters of the user’s name or email in the search box.
  1. GemCRM will search all WordPress users on your site and display matching results.
  1. Click the user’s name to open their permission editor.
Ad User

Important: Only existing WordPress users can be added. If the person does not yet have a WordPress account, create one first via Users → Add New in WordPress.

Removing All Permissions

Click the Actions (···) icon next to a user in the list and select Remove. This action removes all of the user’s permissions at once, instantly blocking access to all GemCRM screens and APIs. 

Editing a User’s Permissions

Click a user’s name to open the edit view. At the top, you’ll see their name, email address, and the total number of permissions currently granted (for example, 37 permissions). 

Below that, permissions are organized into groups (Contacts, Lists, Tags, etc.). Each permission has a toggle — turn it on to grant access, turn it off to revoke it. Changes save instantly — there is no separate Save button.

Auto-Grant Behavior

Within groups like Contacts and Campaigns, a base “View” permission exists alongside action-level permissions such as Create, Update, and Delete. GemCRM enforces a logical rule: if a user can create, update, or delete records, they must also be able to view them.

When you grant any sub-permission (e.g., Create Contacts), the base View Contacts permission is automatically granted, and its toggle becomes locked. It will display the label:

— Auto-granted. Remove all sub-permissions to revoke.

To disable View access for a group, first revoke all sub-permissions within that group.

Permission Reference

Contacts

Manage CRM contacts and their data

Contacts

Lists

Manage contact lists

Lists

Tags

Manage contact tags

Tags

Labels

Manage campaign labels

Labels

Campaigns

Manage email campaigns and their actions

Campaigns

Single-Permission Features

Companies

Manage company records

Companies

Import

Import contacts and data

Import

Dashboard

View analytics and reporting

Dashboard

Webhooks

Manage outgoing webhook integrations

Webhooks

Bulk Actions

Perform bulk operations on records

Bulk Actions

Subscription Forms

Manage opt-in forms

Subscription Forms

Settings

Access general plugin settings

Settings

⚠ The Settings permission grants full read and write access to general plugin settings, including email provider credentials and the Permission Manager itself. Only grant this to users you fully trust 

Pro & Addon Permissions

The following permissions are only visible when GemCRM Pro is active. Permissions marked with an addon also require that specific addon to be installed and activated.

Deals

Manage deal pipeline, stages, notes, and tasks

Deals

Manage tracking smart links

Smart Links

Advance Filter

Use advanced contact filtering

Advance Filter

Tag Mapping

Map WordPress roles to tags

Tag Mapping

Common Role Configurations

Here are recommended permission sets for typical team roles. Adjust them to fit your specific workflow.

Content / Campaign Manager

Grant: View, Create, Update Campaigns · Manage Actions · Manage Subscribers · View Contacts

Contact Data Manager

Grant: View, Create, Update Contacts · View Lists · View Tags · Import Data

Read-Only Team Member

Grant: View Contacts · View Campaigns · View Dashboard

Full CRM User (Non-Admin)

Grant: Grant all permissions except Manage Settings, unless they need to modify plugin configuration.

Troubleshooting

A user cannot see GemCRM in the WordPress menu

The GemCRM menu appears only for users who have at least one permission. Open their profile in the Permission Manager and enable at least one permission, such as View Dashboard.

A user sees a “You do not have permission” error inside GemCRM

The specific feature they attempted to use requires a permission that has not been granted. Open their profile in the Permission Manager and enable the relevant permission.

The Permission Manager tab is not visible

This tab requires GemCRM Pro. Activate your Pro license under GemCRM → Settings → License.

A toggle appears grayed out and cannot be turned off

The permission has been auto-granted because a sub-permission depends on it. First, revoke all sub-permissions in that group (e.g., Create, Update, and Delete Contacts), and the View toggle will unlock automatically.

I removed all permissions for a user, but they can still access GemCRM

Check whether the user’s WordPress role is Administrator. Administrators bypass the Permission Manager entirely and always retain full access.