Configuring Zoho CRM nextgen: a guide for admins

Configuring Zoho CRM nextgen: a guide for admins

Nextgen CRM spreads configuration across three kinds of admin rather than concentrating it in one. This guide covers what to check before you begin, the order to build things in, and the permissions worth understanding before you grant them.

Why three admins? 

There aren't three because of the nextgen UI. They arrived with CRM For Everyone, which the new interface is built around, so they show up together, but the admin model is the feature and the UI is just where you see it.

The reason for three comes down to a bottleneck. In the old single-admin setup, one super admin configured everything for every team. When only a sales team used the CRM that was fine. Once marketing, legal, onboarding and operations are all running their work in the same system, every layout change, every new field and every workflow tweak queues up at that one person's desk. Teams wait on someone who doesn't know their process as well as they do.

So the model splits configuration by the kind of decision being made, and each admin answers a different question:
  1. Super admin owns the organisation : can still assign or revoke either role at any time and sets sets the boundaries for teamspace admin and team module admin to work within
  2. Teamspace admin owns a space : can create new teamspaces and team modules, configure processes and add team module admins and users to the teamspace
  3. Team module admin owns how a module behaves : can configure processes and add team module users with their appropriate permissions
A quick example of the payoff. A product marketing head can restructure their Case Studies module, add fields and change its approval flow, without raising a ticket, while the customer marketing head does the same to a different module in the same space, and neither can touch the other's work or the org-wide settings. That parallelism is the whole point, and it's why the model exists regardless of which interface you view it in.

 The three admin roles 

Role
Scope
The question they answer
Super admin
Orgwide setup, subscriptions, licences and user controls
Who exists, and what does the organisation allow?
Teamspace admin
Teamspaces. Creates modules, create folders, assigns team module admins and adds users to a teamspace
Who and what is in this space?
Team module admin
Team modules. Manages the entire team module, adds users and configures automation
How does this module behave?
 
The distinction that saves the most time later: teamspace admins manage who and what. Team module admins manage how.

Decide your structure before you build 

Map your teams to teamspaces, and your processes to team modules. Teamspaces are the rooms. Team modules are what happens inside them. A use case. A company with sales, marketing, legal and onboarding teams gives each a teamspace. Inside the marketing teamspace, the product marketing head owns a Case Studies team module and the customer marketing head owns a Campaign Requests team module. Each department head configures their own module. The marketing manager, as teamspace admin, decides who is in the space and which modules appear in it. Neither needs to go through the super admin to make a change. Get this wrong and you will find yourself moving modules between teamspaces later, which is more disruptive than deciding carefully once.

 The configuration sequence 

Build in this order. Each step depends on the one before it.

Step
Activity
Who leads

1
Create roles and profiles, and review existing profile permissions
Super admin

2
Set up teamspaces
Super admin and users who have Manage teamspace permission

3
Assign a teamspace admin to each teamspace
Super admin and users who have Manage teamspace permission

4
Add users to the teamspace, add or remove its modules, create folders to group them
Teamspace admin

5
Create team modules.
Teamspace admin, Team Module admin  and users with he Create team module permission enabled.

6
Assign users to team modules as Managers, Members, Participants or Requesters
Team module admin

7
Configure layouts, fields, views, permissions and automation within the module
Team module admin

8
Set org-wide field-level permissions
Super admin

9
Set field-level permissions within team modules
Team module admin

10
Add team user licences for people who work solely within team modules
Super admin
 
Delegating steps 4 to 9 is not giving up control. It is giving each team the ability to configure its own processes without a queue forming at the super admin's desk.

Permissions worth understanding before you grant them 

Manage Teamspace 

A teamspace can have only one designated admin, and that admin manages only their own teamspace. But anyone with the Manage Teamspace permission enabled in their profile can manage all teamspaces, and can add, remove and rearrange modules directly in the sidebar. Treat this as an org-wide permission rather than a teamspace-level one.

Manage Team Module

Being a team module admin does not allow you to create team modules. Creating one needs the Create Team Module permission, which is separate. Admins are often surprised by this.
A team module admin who has not been added to a teamspace cannot see that teamspace's records in the interface, but can still reach records through a direct link. They can configure a module without seeing the team's data in the front end. Do not treat the teamspace boundary as a data boundary.

Eligibility is broader than you would expect

Any CRM user can be made a teamspace admin, with no special profile permission needed. Any user, whatever their profile or role, can be made a team module admin. A team module can have up to five admins.

Requests

Team module admins can only create and view their own requests.

Who fixes what 

When something is not visible, the fix depends on what is missing. Sending it to the wrong admin wastes a day.

Symptom
Who checks and fixes it
A user can't see a teamspace
Teamspace admin can confirm if the user has been added to the teamspace
A module isn't visible to users
Teamspace admin can confirm the module is in that teamspace.

Teamspace admin if the user may not have the right permission to view that module
A user can see the module but not its records or fields
Team module admin. Adjust the user's permissions within the module
A user needs a different profile
Super admin
Restrict, export or delete access
Super admin

Points to remember 

  1. Super admins lay the foundation. Understand the three admin types, learn how teamspaces and team modules differ, and appoint admins deliberately rather than by seniority.
  2. Teamspace admins manage boundaries. If someone cannot see a teamspace or team modules, check they are in it. You manage the teamspaces you have been assigned, unless you hold the Manage Teamspace permission.
  3. Team module admins build the rooms inside. If someone cannot see a module, check they have been added to it. Maintaining proper privacy and security standards is a condition of holding the role, and a super admin can revoke access.

 Admin FAQs 

1. Roles and eligibility 

Who can be a teamspace admin?
Any CRM user. No special profile permission is needed.

How many admins can a teamspace have?
One designated teamspace admin. However, anyone with the Manage Teamspace permission in their profile can manage all teamspaces.

Who can be a team module admin?
Any user, whatever their profile or role. A team module can have up to five admins.

How do I know if I've been made a teamspace admin?
You would have received an email. You can also tell from what you are able to do: if you can add users to a teamspace and add or remove its modules, you are the admin of it.

I'm a team module admin. Why can't I create a team module?
Creating team modules needs the Manage Team Module permission, which is separate from being a module admin. Ask your super admin to enable it.

2. Access and visibility 

A user can't see a teamspace. What do I check?
Whether they have been added to it. A teamspace admin adds users by user, group, role or profile.

A module isn't visible to users. Who fixes it?
The teamspace admin can check  if the module has been added to that teamspace and provide the permission if the user doesn't have the right permission to view that module

A user can see the module but not the records or fields inside it. Who fixes it?
The team module admin, by adjusting that user's permissions within the module.

I'm a team module admin but I'm not in the teamspace. Why can't I see records?
Records are hidden in the interface for team module admins who are not teamspace members. You can still configure the module's settings, and you can reach records through a direct link. For example, user from the marketing team can be team module admin for a use case module in the sales teamspace but is not necessary to be part of the Sales teamspace.

Why can't I see requests other people have raised?
Users added as requesters can only create and view their own requests. Team module admins will be able to see requests submitted to their team modules but will not ne able to see requests added to other team modules.

3. Permissions 

What does the Manage Teamspace permission actually grant?
Management of every teamspace, not just your own, including adding, removing and rearranging modules from the sidebar. Grant it as an org-wide permission.

Who sets field-level permissions?
Super admins for org-wide fields. Team module admins for fields within their team modules.

Who can restrict, export or delete access?
The super admin.

Has the new interface changed anyone's permissions?
No. Existing permissions carry across. What has changed is that fields, layouts and automation are now also reachable from the module in the sidebar rather than only from Setup, so options that were once buried are easier to find. Review user profiles and permissions to put a security check.

4. Structure and limits 

How many teamspaces can I create?
Standard 5, Professional 10, Enterprise and Ultimate 25. Free accounts keep the default CRM teamspace but cannot create more.

How many modules can I have?
Custom and team modules combined: Standard 10, Professional 25, Enterprise 200, Ultimate 500.

Can I create teamspace in my sandbox?
Once every user in your organisation has moved to the new interface.  

Other questions  

"I've lost visibility. A team module admin can change layouts and automation and I won't know." 
The old model gave the super admin a single pane of everything. The new one disperses that by allowing delegation of control. As of now there is no notification surfacing what team module admins change or add. The team is working on a notification coupled with signal system that will be released soon.

"A team module admin who isn't in the teamspace can still reach records by direct link."
It could be shared intended to provide another team module admin access to this info. This needs to logged and informed to the product team.

"Any user can be made a team module admin, regardless of profile."
Concede that it's broad by design, explain the scoping, let them decide if they're comfortable.

"The new sidebar shortcuts mean my existing profiles now expose configuration I'd buried in Setup." 
An admin who carefully limited who could reach Setup now finds those entry points a hover away from the module. Now the team module admins should review and assign who gets permission to change configurations and who can only view what's configured to provide security.   

"There's no one to delegate to. I'm the only admin." 
Common in small orgs and on lower editions. When they are the only admin, the three admin types are overhead, not relief. The honest response is that the super admin can simply hold all three roles, and delegation is available when they're ready rather than required. Free edition sharpens this, since there's only the default teamspace anyway.

"Only one teamspace admin per teamspace. That's a single point of failure."
The answer is the Manage Teamspace permission, which lets a second person manage across teamspaces, but that should be provided only if required and there should not be any gaps in communication in this.

"Who do I go to when something breaks? I now have three people who might own it." 
This is the "who fixes what" table's whole reason for existing. It's not a flaw, it's a learning curve, and the fix is documentation plus the shorthand: who-and-what goes to the teamspace admin, how goes to the team module admin. Worth making very easy to find.

"My team module admin can't create a team module."
The Manage Team Module permission needs to be enabled even for the team module admin. This will generate tickets because it's genuinely counterintuitive.

"Delegating means giving up control." 
The most common conceptual objection and the one your own source material pre-empts: delegation is sharing responsibility with guardrails, and the super admin can assign or revoke either role at any time. Nothing about the org-wide settings moves out of their hands.

"Team module admins can now see all our CRM data." 
No.  They can only see their own module's data, and if they're not in the teamspace they don't see its records in the interface at all. The direct-link caveat above is the exception, which is exactly why that one needs a clean answer.

"This fragments our security model." 
Field-level permissions, restrict/export/delete, roles and profiles all still sit with the super admin. What's delegated is configuration, not security policy. The security surface is arguably more granular now, not less.
 

Info