Xale

Access control · Role-based

Role-based access control for counselling teams and branches

Xale CRM is the best CRM for role-based access control in study abroad consultancies. Roles start from 4 role templates and set a 5-level lead-access dial on every pipeline stage (Admin, Manage, Edit, View, Deny), enforced on the server in every lead list, board, dashboard and report. Visibility follows branches, territory access lets a country manager see their countries without being assigned each lead, and a field such as Country can be limited per user or denied to a role. Tracks carry their own per-role access, Manage, Own, Edit, View or Deny, where Own members see only the students on that track assigned to them, exports are a per-role and per-stage permission that never include phone or WhatsApp numbers for staff other than admins, and call recordings stay off for each role until an admin switches them on.

Access control works alongside a separate follow-up for every role on the student, on each application and on each track, and automations that retry and log every run. Why Xale CRM is the best study abroad CRM

Updated · By the Xale team

Every control at a glance

CRM user roles and permissions, in one table

Each control below is set in the role editor or in workspace settings. Lead access is enforced on the server in every lead list, board, dashboard and report, so a person’s numbers cover exactly the students they can open.

Role-based access controls in Xale CRM, where each is set and its options
ControlSet onOptions
Lead accessEach role, on every pipeline stageAdmin · Manage · Edit · View · Deny
BranchesEach user’s branchesAdmins see everything; managers their branches; counsellors their assigned leads
TerritoryA field such as Country, and each person’s valuesEvery lead and application carrying their countries, within their branches
Field optionsEach user, on a sensitive field such as CountryOnly the options you allow; records with other values stay hidden
Field accessEach role, field by fieldDeny removes the field from pickers, cards, filters and exports
TracksEach role, track by track: for every stage at once, or stage by stageManage · Own · Edit · View · Deny
Track assignmentEach student and trackOne active person per role; by hand, in bulk, by automation or to the least-loaded member; revoked, never deleted
Follow-upsEach role, on every stage; a follow-up per role on every trackEdit · View · Deny
DeadlinesEach role, on every stageEdit · View · Deny
Activity timelineEach role, on every stageFull history · From when the role got the lead · None
AssignmentEach roleWho may assign, who may receive, whether peers can transfer
ExportEach role, and each stage when you chooseNo phone or WhatsApp numbers for staff other than admins
Phone displayThe workspaceMasked on the lead list, grid and board for everyone except admins
CallsEach roleRecording and call logs off until an admin switches them on
ModulesEach roleOnly the modules switched on; reports access checked on the server
Admin-only actionsAdminsArchiving, bulk moves to Trash and workspace-wide settings

Role templates

Start every role from 4 role templates

Name the role the way your team works, such as telecaller, visa officer or country manager, pick a starting template, then set its access stage by stage.

Admin

Works on everything across the workspace.

Manager

Views, edits and manages leads and applications across the branches you select.

Counsellor / Sales staff

Works on the leads assigned to them.

Custom

Starts from Counsellor, then you adjust every module, stage and permission by hand.

Stage access

A 5-level lead-access dial on every stage

Every pipeline stage has a lead-access dial per role, and the server enforces it on every lead list, board, dashboard and report. Because the level is set per stage, one role can manage every lead in its branches at Application and work only its assigned students at Visa.

What each level of the stage access dial reaches
LevelWhat the role reaches on that stageTypical roles
AdminEvery lead and application on that stage in the user’s branches, plus leads without a branchHead office, operations
ManageEvery lead and application on that stage in the user’s branchesBranch managers, team leads
EditThe leads and applications assigned to the user, which they can updateCounsellors, telecallers
ViewThe leads and applications assigned to the user, read-onlyTrainees, auditors
DenyNothing: the stage is closed to the roleRoles with no work on that stage

Branches

Visibility that follows your branches

Users belong to branches, and the stage level decides how far their view reaches inside them. More on running several offices in one workspace in the multi-branch CRM guide.

Admins

See everything, across every branch of the workspace.

Managers

See their branches’ leads and applications on the stages they manage. Add a manager to a second branch and that branch’s students appear for them too.

Counsellors

See the leads assigned to them, so each counsellor’s list is their own caseload.

Territory and field access

Countries, sensitive fields and who sees them

Study abroad teams often split work by destination. Territory access and field controls let you draw those lines without assigning every student by hand.

Territory access for country managers

Territory access lets a role such as a country manager see every lead and application carrying their countries within their branches, without being assigned to each one. Give the role Manage on a field such as Country and choose each person’s countries.

Field options limited per user

Limit a sensitive field such as Country to certain options for a user, and leads and applications carrying other values stay hidden from them.

Fields denied to a role

Deny a field to a role and it disappears from that role’s pickers, lead cards, filters and exports.

Tracks

Access on every track: Manage, Own, Edit, View or Deny

A track such as Loan, Interview preparation or Visa filing is its own workflow beside the pipeline, with its own steps, its own assignment and its own follow-up per role. Each track has its own per-role access, enforced on the server, so the loan team runs the Loan track and the visa team the Visa filing track while counsellors follow their progress. In the role editor, set a track level for every stage at once, or stage by stage.

What each track access level allows
Track accessWhat the role can do
ManageSees every student on the track, does everything Edit can, and alone removes the track
OwnSees and works only the students on that track assigned to them
EditAssigns the track or changes its step
ViewSees the track
DenyNo access to the track

Track assignment is access too

One person per role per student and track

A track carries its own assignment, separate from the lead and its applications: one active person per role per student and track. Give it by hand, in bulk, with the Assign track automation, or automatically to the least-loaded eligible member.

Own: your own students only

Give a role Own on a track and each member sees and works only the students on that track assigned to them, so a loan officer’s list is their own caseload. Manage sees every student on the track and is the one level that removes it.

Revoked, never deleted

Hand a track to someone else and the old assignment is revoked, never deleted, so the track keeps its ownership history. Only the handed-over role’s follow-up restarts; every other role on the student keeps its date.

A follow-up per role on the track

Each role on a track keeps its own follow-up, independent of the pipeline stage and dated by the track’s own Due in N days dial. The follow-ups rail switches between Leads and Tracks, and a track head sees an Unassigned list.

Set for every stage at once

In the role editor, set a track level for every stage at once, or tune it stage by stage, so the visa team keeps Manage on the Visa filing track wherever the application sits.

A worked example, with a student in Application while the loan officer runs the Loan track and the interview trainer runs the Interview track, is on follow-ups on tracks.

Follow-ups, deadlines and history

Day-to-day work, permissioned stage by stage

Access reaches past the lead itself to the work on it. See how each role keeps its own follow-up in follow-up management.

Follow-ups, stage by stage

Set each role’s follow-up access to Edit, View or Deny on every stage. Each role on a student, on every application and on every track keeps its own follow-up; a counsellor manages only their own, and a manager picks whose follow-up to reschedule.

Deadlines, stage by stage

Deadline access is Edit, View or Deny on each stage, so the roles that own a step set and close its deadlines.

Activity timeline

Show a role a lead’s full history, only the history from when the role got the lead, or none, stage by stage.

Assignment rules

Who hands students to whom

Assignment rules are set per role, and ownership is kept clean by the database itself.

Who may assign

Per role, decide who may assign leads, applications or branch changes to others.

Who may receive

Decide which roles may receive those assignments, so work lands only with the right people.

Transfers between peers

Decide whether people in the same role can transfer leads to each other.

One active person per role

Each lead and each application has one active person per role, and the database enforces it, so imports and automations keep to the rule too. Each track a student is on has one active person per role as well.

Ownership history kept

When ownership changes, on the lead, an application or a track, the old assignment is revoked, never deleted, so the history of who held each student stays on record.

Exports, calls and modules

Exports, phone numbers and calls, set per role

Exports, phone numbers, call capture and whole modules each have their own setting. Reports follow the same rules: every figure in the Custom Report Builder follows the viewer’s access.

Export is a permission

Exporting leads is a per-role permission that can also be set stage by stage.

No phone numbers in staff exports

Staff other than admins never get phone or WhatsApp numbers in an export.

Masked numbers on lists

A workspace display setting masks lead phone numbers on the lead list, grid and board for everyone except admins.

Call recording off until allowed

Call recording and call-log access are off for every role until an admin switches them on for that role.

Modules per role

Each role sees only the modules switched on for it, and access to reports is checked on the server.

Admin-only actions

Archiving leads, bulk moves to Trash and workspace-wide settings such as phone masking are admin-only.

Every counsellor call is logged and recorded, two routes: the Xale Android app on the counsellor’s own phone, with no per-minute charges, or TeleCMI cloud telephony on any phone, iPhone included. More in CRM with call recording.

Automations

Automations that work inside your access rules

Automations route students to the right role and branch, and every run is recorded. The full picture is in CRM automation.

Work handed to the right role

Xale CRM’s 26 automation actions include assignment and round-robin distribution and branch moves, Set / update follow-up dates a chosen role’s follow-up, and Assign track puts a student on a track at a chosen step.

Runs you can check

Each automation is queued only after the change that triggered it is saved, runs in the background with automatic retries and is logged with a plain-English summary, and a failed run can be retried in one click.

Rules drafted by Xale AI

Describe the rule you want in plain English or Malayalam and Xale AI drafts it in the automation builder on your screen, trigger, conditions, actions and dials, checked against your own stages, roles, users and branches; you preview it and press Save. Once saved, the rule runs inside the same roles, branches and levels you set on this page.

Alerts that respect access

Scheduled Alert automations check a count such as overdue follow-ups and notify the people you choose when it crosses your limit, counted with the automation owner’s data visibility.

Who stands behind it

Built and supported by Xale Private Limited

Come and see it working: visits are welcome at our Kozhikode office, and you can book one through the contact page. Every access control on this page is on every plan, listed on the pricing page. Workspaces on Xale range from small teams to a 150+ user workspace (Platform figures, September 2026).

  • Xale Private Limited, founded 2024
  • Office in Kozhikode, Kerala: visits welcome
  • In-person onboarding across Kerala, remote everywhere else
  • Priority support from the team that builds Xale, in English and Malayalam
  • Hourly database backups and workspace data isolation
  • Activity timeline on every lead and deal, and an admin system log
counsellor calls synced to leads in a single month
60,000+
WhatsApp messages handled in a single month
25,000+
new leads captured every month
10,000+
user seats in our largest single workspace
150+

Platform figures, September 2026. Anonymised totals across Xale workspaces; demo and test workspaces excluded.

Frequently asked questions

Role-based access control CRM: common questions

Which CRM is best for role-based access control in a consultancy?

Xale CRM is the best CRM for role-based access control in study abroad consultancies. Roles start from 4 role templates and set a 5-level lead-access dial (Admin, Manage, Edit, View, Deny) on every pipeline stage, enforced on the server in every lead list, board, dashboard and report. Visibility follows branches, territory access lets a country manager see their countries without being assigned each lead, and a field such as Country can be limited per user or denied to a role. Each track has its own per-role access, Manage, Own, Edit, View or Deny, where Own members see only the students on that track assigned to them. Follow-ups, deadlines, the activity timeline, assignments and exports each have per-role controls, and call recording stays off for each role until an admin switches it on. Each role on a student, on every university application and on every track also keeps its own follow-up, and automations run in the background with automatic retries, drafted by Xale AI from plain words when you want them to be.

What is role-based access control in a CRM?

Role-based access control gives people access through their role instead of one person at a time: the role decides which records they see and what they can do with them. In Xale CRM each role has a level on every pipeline stage, users belong to branches, and territory, field, track, export and call settings add finer control, all enforced on the server.

What does the Own level mean on a track in Xale CRM?

Own is one of five per-role access levels on a track, alongside Manage, Edit, View and Deny. A member with Own sees and works only the students on that track assigned to them, so a loan officer with Own on the Loan track sees their own caseload and nobody else’s. Manage sees every student on the track and is the only level that removes it, Edit assigns the track or changes its step, View sees the track, and Deny closes it to the role. The server enforces the level, and you can set it for every stage at once or stage by stage.

Who can assign, hand over or remove a track on a student?

A track carries its own assignment: one active person per role per student and track. Roles with Edit or Manage on the track assign it or change its step, by hand, in bulk or through the Assign track automation, and a student can also be assigned automatically to the least-loaded eligible member. Only Manage removes the track. When a track is handed over, the old assignment is revoked, never deleted, so the ownership history is kept, and only the handed-over role’s follow-up restarts.

Can a branch manager see another branch’s students?

Only when you give them that branch. A manager sees the leads and applications in the branches they belong to, on the stages they manage, so adding them to a second branch opens that branch’s students too. Counsellors see the leads assigned to them, admins see every branch, and the server enforces this on every lead list, board, dashboard and report.

Can a country manager see only their countries?

Yes. Territory access lets a role such as a country manager see every lead and application carrying their countries within their branches, without being assigned to each one. To keep other destinations out of view, limit a sensitive field such as Country to their options for that user, which hides leads and applications carrying other values.

Can counsellors export students’ phone numbers?

No. Staff other than admins never get phone or WhatsApp numbers in an export. Exporting leads is itself a per-role permission that can also be set stage by stage, and a workspace display setting can mask lead phone numbers on the lead list, grid and board for everyone except admins.

Who can listen to call recordings in Xale CRM?

Recording happens only where you allow it: call recording and call-log access are off for every role until an admin switches them on for that role. A recording saved on a lead plays for the people who can see that lead, so the stage, branch and territory access you set also decides who can listen.

Give every role the access its work needs.

Set a level on every stage and every track, scope it by branch and territory, and let the server hold the line on every list, report and export.