> ## Documentation Index
> Fetch the complete documentation index at: https://docs.gettap.co/llms.txt
> Use this file to discover all available pages before exploring further.

# Department permissions

> Control which profile fields, link types, and CRMs each department can use.

Departments are how you stop a 200-person sales team from editing their job titles to "Chief Vibes Officer" and adding personal Instagram links to a company profile.

<Warning>
  **The default is full access.** A department with no saved restrictions lets its members do everything. Restrictions apply only once you explicitly save them. Creating a department locks nothing down by itself.
</Warning>

## What you can control

Four independent mechanisms. They don't interact — each is evaluated on its own.

<CardGroup cols={2}>
  <Card title="Profile fields" icon="id-card">
    Per field, whether members of this department may edit it. Lock name, title, and company; leave photo and bio open.
  </Card>

  <Card title="Link types" icon="link">
    Per link type, whether members may add or edit it. Allow LinkedIn and email; block personal social accounts.
  </Card>

  <Card title="CRM access" icon="plug">
    Which CRM providers this department can reach. Presence of a grant means access; no grant means no access.
  </Card>

  <Card title="Location features" icon="location-dot">
    A single on/off switch for location capture. Off by default.
  </Card>
</CardGroup>

<Frame caption="A missing rule means the opposite thing on each side">
  <img className="block dark:hidden" alt="Profile fields and link types allow by default when no rule is saved. CRM access denies by default when no grant is saved." src="https://cdn.gettap.co/docs/images/permission-defaults-light.svg" />

  <img className="hidden dark:block" alt="Profile fields and link types allow by default when no rule is saved. CRM access denies by default when no grant is saved." src="https://cdn.gettap.co/docs/images/permission-defaults-dark.svg" />
</Frame>

<Note>
  CRM access is the one that behaves *opposite* to the others. Profile fields and link types are **allow-by-default** — a missing rule means permitted. CRM access is **deny-by-default** — a missing grant means no access.
</Note>

## Setting restrictions

<Frame caption="Each field toggles independently — and every toggle is off until you turn it on">
  ![The department Permissions screen with tabs for About, QR Code, Settings and Links, and a toggle for each field such as Profile Picture, Name, Bio and Job Title.](https://cdn.gettap.co/docs/images/screens/teams-department-permissions.png)
</Frame>

Permissions are grouped into four tabs — **About**, **QR Code**, **Settings**, and **Links** — with a master switch at the top of each that restricts everything in that group at once.

<Steps>
  <Step title="Open the department">
    **Departments** → the department's **⋯** menu → **Edit Department** → **Permissions**.
  </Step>

  <Step title="Set profile field rules">
    Toggle each field between editable and locked. Locked fields still display on the profile — members simply can't change them. Values come from the template or from what an admin set.
  </Step>

  <Step title="Set link type rules">
    Toggle each link type. Blocking a type prevents members adding new links of that type. Links already on a profile are not deleted.
  </Step>

  <Step title="Grant CRM access">
    Tick the CRM providers this department may sync to. Leaving all unticked means members in this department can't reach any CRM.
  </Step>

  <Step title="Save">
    Nothing takes effect until you save. This is the step that flips the department from full access to restricted.
  </Step>
</Steps>

## A template just for this department

A department can also carry its own **Custom Template**, so one part of the business presents differently without needing a separate company.

<Frame caption="Custom Template sits alongside Permissions on the department">
  ![The Custom Template tab within a department's settings.](https://cdn.gettap.co/docs/images/screens/teams-department-template.png)
</Frame>

## Sub-admin management

A department can be allowed to have its own admin — someone who manages the profiles inside their department without being a full company admin. This is off by default and enabled per company.

Use it when regional managers should onboard their own reps but shouldn't touch billing, templates, or other departments.

## Common setups

<AccordionGroup>
  <Accordion title="Field sales — locked brand, open personal details" icon="briefcase">
    Lock company name, logo, and brand colors. Leave name, title, photo, direct phone, and calendar link editable. Allow LinkedIn and email link types, block everything else. Grant CRM access.

    Reps look consistent, still feel like individuals, and their leads reach the CRM.
  </Accordion>

  <Accordion title="Event staff — fully locked" icon="calendar-days">
    Lock every profile field. Allow no link types. Grant no CRM access.

    Temporary staff share a company profile and capture leads, but can't modify anything or reach customer data.
  </Accordion>

  <Accordion title="Executives — unrestricted" icon="crown">
    Save no restrictions at all. Full access is the default, so an unrestricted department needs no configuration — just don't add rules.
  </Accordion>
</AccordionGroup>

## Troubleshooting

<AccordionGroup>
  <Accordion title="A member says they can't edit a field" icon="lock">
    Check their department's profile field rules. Also confirm which department they're actually in — members moved between departments pick up the new department's rules immediately.
  </Accordion>

  <Accordion title="Restrictions don't seem to apply" icon="triangle-exclamation">
    The most likely cause is that no rules were ever saved for that department, which means full access. Open the permissions screen and confirm rules are present, not just that the department exists.
  </Accordion>

  <Accordion title="A member can't sync to the CRM" icon="plug-circle-xmark">
    CRM access is deny-by-default. Unlike field and link rules, an empty configuration blocks rather than allows. Grant the provider explicitly.
  </Accordion>
</AccordionGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.