Masked Field Type with Permission-Controlled Visibility in Zoho CRM

Masked Field Type with Permission-Controlled Visibility in Zoho CRM

Dear Zoho CRM Team,

Greetings,

We would like to request a new feature that would enhance data security and access control within Zoho CRM, especially when handling sensitive internal information.

Use Case:

Our team occasionally needs to store sensitive data — such as API keys, access tokens, or credentials — within CRM records. To ensure this information is protected yet accessible under controlled conditions, we are looking for a new “Masked Field” type (similar to a password field in web forms), with the following capabilities:

  1. Masked by Default:
    Display the field value as masked (e.g., **** or XXXX) to prevent casual viewing.

  2. “Eye” Icon to Reveal:
    Include an eye icon that users can click to temporarily reveal the real value on-screen.

  3. Permission-Controlled Unmasking:
    Visibility of the real value (via the “eye” icon) should be governed by profile/role permissions, to ensure only authorized users can unmask it.

  4. API Access:
    The field value should still be accessible via the Zoho CRM API, assuming the request is properly authenticated and authorized.

Why This Matters:

While we understand some of this can be approximated using client scripts or workarounds, these methods do not support secure unmasking with permission control, nor do they provide a smooth user experience like native password fields. Introducing a built-in masked field type would significantly improve the security and usability of Zoho CRM for teams who need to manage confidential data internally.

We appreciate your consideration of this request and would be happy to provide additional context or discuss the use case further if needed.

Best regards,
Ram

    Nederlandse Hulpbronnen