Who sees what, who does what.
You decide, down to the field.
In HOP, every role, every user, every team has exactly the rights it needs. Field by field, action by action. And every operation leaves a trace.
Permissions that fit your organization
In HOP, permissions are attached to roles and teams. A user can hold several roles and belong to several teams: their rights result from the whole.
Per entity, per action
For each entity, standard or custom, every action is set independently: view, create, edit, delete, but also business operations such as calculating an invoice or validating a quote.
The owner is the exception
Each record can have one or several owners: users, teams, or both. And each permission can include an exception, for example: forbid deletion for everyone, except the owner. Your rules, case by case.
Arbitration
When several rules overlap, you stay in control: a permission can be declared imperative and override all the others. An imperative "no" remains a no, whatever the user’s roles and teams.
Down to the field
Seeing a record does not mean seeing everything. In HOP, permissions go down to field level: every field, every action.
A margin on a quote, a salary in an HR record, a clause in a contract: some information only concerns part of those who access the record. You decide who views each field, and who edits it. The others do not see it: for them, the field does not exist.
True for standard fields as well as custom fields, as everywhere in HOP
Quote Q-2026-0318 · Sales management role
Quote Q-2026-0318 · Sales administration role
Same record, two roles: the Margin field does not exist for the second one
Delegate with full control
An absence, a replacement, a handover: team life does not stop at individual permissions.
In HOP a user can delegate their permissions to another user. Their manager can do it for them. Delegation is time-bound: it ends on the planned date, with no intervention. The delegate acts with the permissions received, and each action is traced under their name. No shared password, no generic account: everyone acts under their own identity.
Active delegation
Camille R.
Delegates their permissions
Julien T.
Delegate
Every action leaves a trace
Knowing what was done, when and by whom: privacy does not go without traceability.
Everything is logged
Creation, modification, deletion... every operation is recorded, with its author and date. And the trace is detailed: for a modification, every modified field is kept, with its old and new value. Business operations too: calculating an invoice, validating a quote. And for sensitive entities, you can enable view logging: knowing who opened a record, not only who modified it.
The log follows the same rules
The log is a HOP object like any other. It is therefore subject to the permission engine: you decide who can view it. No special regime, including for traceability itself.
Log · Today
Roll back, field by field
A typing error, a misconfigured import, an unfortunate deletion: traceability lets you see, reversibility lets you fix.
Selective restoration
From the log or from the record, you view the list of modified fields, with their value before and after. You check the fields to restore, you leave the others. And a deletion can be undone.
Permissions apply here too
Restoring is modifying. Restoration therefore follows modification permissions: among the modified fields, a user can only restore those they are allowed to modify.
And restoration is traced
Every restoration is logged, both as a restoration and as a modification. It is therefore itself reversible.
Restoration · Quote Q-2026-0318
One permission engine, applied everywhere
Fine-grained rules are only worth having if nothing can bypass them. In HOP the permission engine is unique, and everything goes through it.
Search, views, exports
Centralized search only returns authorized records and fields. Lists, dashboards and exports apply the same rules. What a user must not see appears nowhere.
Automations too
Control applies from the design stage: a user cannot program in an automation an action that their own permissions forbid. Business rules are designed by those who have the right to, and by them only.
You decide, your integrator implements
Roles, teams, exceptions, logging: your permission model reflects your organization, not an imposed standard. You define it with your certified integrator, who implements it and makes it evolve with you.
No code, like the rest of HOP configuration.
Your data deserves rules that fit you
A HOP certified integrator analyzes your permission model with you and implements it
Request a demo