> ## Documentation Index
> Fetch the complete documentation index at: https://docs.introw.io/llms.txt
> Use this file to discover all available pages before exploring further.

# CRM users vs Admin users in Salesforce

> The two kinds of Introw access for your own team: a CRM user who works only from the Introw collaboration panel in Salesforce and takes no paid seat, and a full Introw user such as an Admin. What each one can do, what each one costs, and which to give.

> For the person adding colleagues to Introw and being asked why some of them cost a seat and some do not.

Introw has two kinds of access for your own team, and the difference is where the person works.
A **CRM user** works only inside Salesforce, on the Introw collaboration panel, and takes no paid seat.
An **Admin** gets the full Introw application: every module, every setting, and a paid seat.

Both are set on the **role** you give the person, so the same colleague can move from one to the other later.

## What you'll achieve

A rule you can apply per colleague: which access type they get, what it costs you, and what changes for them on day one.

## Access in Salesforce has two gates

On Salesforce, two separate things have to be true before a colleague sees partner data on a record.
Getting one without the other is the most common reason a rep tells you the panel is empty.

| Gate                                             | Where you set it                                                            | What it decides                                           |
| ------------------------------------------------ | --------------------------------------------------------------------------- | --------------------------------------------------------- |
| The **Introw Collaboration User** permission set | Salesforce                                                                  | Whether the panel loads for them at all                   |
| Their Introw role                                | Introw, on the **Roles** tab of [Team](https://app.introw.io/settings/team) | What the panel lets them do, and whether they cost a seat |

The permission set is per Salesforce user and the managed package only assigns it to whoever installed it.
See [Embed Introw in Salesforce](./embed-introw-in-salesforce) for placing the panel and assigning the permission set.

## CRM user and Admin, side by side

|                                                                                                 | **CRM user**                                                   | **Admin**                                              |
| ----------------------------------------------------------------------------------------------- | -------------------------------------------------------------- | ------------------------------------------------------ |
| Where they work                                                                                 | Only in Salesforce, on the Introw collaboration panel          | Anywhere in Introw, and on the panel in Salesforce too |
| Signing in to Introw                                                                            | Lands on a short screen that points them back to Salesforce    | Full application                                       |
| Paid seat                                                                                       | No, they never count against your seat allowance               | Yes                                                    |
| Salesforce permission set                                                                       | **Introw Collaboration User**                                  | **Introw Collaboration User**                          |
| Configuration (mappings, experiences, tiers, commissions, goals, courses, forms, reports, team) | None. Every permission category is off and cannot be turned on | All of it                                              |
| Partner scope                                                                                   | Every partner in the program                                   | Every partner in the program                           |
| Email notifications                                                                             | CRM object updates only                                        | Anything you switch on for the role                    |
| Available when                                                                                  | Salesforce is your connected CRM                               | Always                                                 |

<Note>
  Admin is not the only counterpart. Introw has four access types, and three of them are full Introw users on a paid seat. **CRM only user** is the one that is not.
</Note>

## The four access types

You pick one of these when you build a role on the **Roles** tab of [Team](https://app.introw.io/settings/team).

| Access type         | What it grants                                                                            | Seat |
| ------------------- | ----------------------------------------------------------------------------------------- | ---- |
| **Admin**           | Every permission on every partner, including Team, Integrations and Billing               | Paid |
| **Custom**          | The permission categories you switch on, one by one, on all partners                      | Paid |
| **Partner manager** | The categories you switch on, limited to the partners assigned to that person             | Paid |
| **CRM only user**   | Nothing inside Introw. The person works from the Introw collaboration panel in Salesforce | Free |

See [Create an internal role](/features/access/team-management/guides/create-an-internal-role) for how to build one.

## What a CRM user can do

A CRM user gets the full in-Salesforce experience: whatever the Introw collaboration panel offers on the record they have open.
For a seller, that is the whole job.

* See the linked partner on an opportunity or case, with their tier, their collaborators, and the champion or partner manager.
* Share the opportunity or case with a partner, which is what gives the partner visibility of it in their portal.
* Comment back and forth with the partner's sellers, with the thread staying attached to the Salesforce record. See [Collaborate from Salesforce opportunities and cases](./collaborate-from-salesforce-opportunities-and-cases).
* Ask AI for a summary of the partner relationship or a draft reply, without leaving the record.
* Open the partner's portal from the panel to see what the partner sees, or create one if the partner has no portal yet.
* Follow partner activity and engagement on the record.

The panel has to be on your record pages, and the person needs the **Introw Collaboration User** permission set, for any of this to be visible.
See [Embed Introw in Salesforce](./embed-introw-in-salesforce).

## What a CRM user cannot do

<Steps>
  <Step title="Open Introw itself">
    Any link into Introw sends a CRM user to a short screen that explains their access is limited and points them back to Salesforce. Only the in-Salesforce pages are reachable.
  </Step>

  <Step title="Configure anything">
    Every permission category is off for a CRM-only role, and the role editor disables them, because these users never enter Introw. That covers CRM mapping, experiences and portals, tiers, journeys, commissions, goals, courses, forms, reports, announcements, workflows, team and roles.
  </Step>

  <Step title="Reconnect Salesforce">
    If the connection to Salesforce drops, a CRM user sees a message telling them to contact their administrator. Reconnecting needs integration permissions, which a CRM-only role does not carry. See [Troubleshoot a CRM connection](./troubleshoot-a-crm-connection).
  </Step>

  <Step title="Create a partner">
    Creating a partner needs partner write permission, which a CRM-only role does not carry. Leave partner creation to a full Introw user, or to the automatic partner sync. See [Sync partners and contacts](./sync-partners-and-contacts).
  </Step>

  <Step title="Be limited to their own partners">
    A CRM-only role always covers every partner in the program. If a rep should only ever see the partners assigned to them, that is the **Partner manager** access type, and it uses a paid seat.
  </Step>

  <Step title="Receive most notifications">
    A CRM-only role can only receive notifications for CRM object updates. Every other notification type is off, and the Notifications step of the role editor hides them.
  </Step>

  <Step title="Work from another CRM">
    **CRM only user** follows the CRM your organisation connected. On a Salesforce organisation it means the Introw collaboration panel in Salesforce, and it appears as an option only when Salesforce is your connected CRM.
  </Step>
</Steps>

## Seats and billing

Your plan counts internal seats. CRM users sit outside that count.

* A colleague on Admin, Custom or Partner manager consumes one internal seat.
* A colleague on a CRM-only role consumes none, however many of them you add.
* When your seats are full, the invite dialog says so and still lets you continue with a CRM-only role.
* When your seats are full, you cannot move an existing CRM user onto a paid role. Introw refuses the change and tells you to add seats first.

Salesforce licensing is separate and unchanged: a CRM user is a Salesforce user of yours who already has a Salesforce licence, and Introw does not add one.
Partner contacts are never seats at all: partners reach their portal without an Introw seat and without a seat in your CRM.
For what else your plan meters, see [What your plan meters](/features/access/team-management/guides/understand-your-plan-limits).
For seat pricing, see [introw.io/pricing](https://introw.io/pricing).

## How to give someone each kind of access

<Steps>
  <Step title="Assign the Salesforce permission set">
    In Salesforce, assign **Introw Collaboration User** to the person. Without it the panel will not load partner data for them, whatever their Introw role says. **Introw API Access** is for the integration user behind the connection and does not grant the panel. See [Embed Introw in Salesforce](./embed-introw-in-salesforce).
  </Step>

  <Step title="Use the CRM User role that already exists">
    Connecting Salesforce creates a **CRM User** role in your organisation, so it is in the role list from the start and you do not have to build it. If you build your own, pick the **CRM only user** access type, or start from the **Sales rep** template, which is a CRM-only role when Salesforce is your CRM.
  </Step>

  <Step title="Invite the person into that role">
    On the **Users** tab of [Team](https://app.introw.io/settings/team), select **Invite team member**, enter their email, and pick the role. The role is what decides both their access and their seat type. See [Invite a team member](/features/access/team-management/guides/invite-a-team-member).
  </Step>

  <Step title="Or let them ask from Salesforce">
    A Salesforce user who opens the panel without an Introw account sees a **Request access** button instead of partner data. They appear on your **Users** tab as **Requested**, and you accept them and set their role from there. This is the path most reps take, because they meet Introw on an opportunity rather than in an invite email.
  </Step>

  <Step title="Change the role later if the job changes">
    Change the role on the person's row on the **Users** tab. Nothing is lost: it is the same user with the same history, gaining or losing access to Introw. Moving someone onto a paid role needs a free seat.
  </Step>
</Steps>

<Note>
  A new CRM user signs in to Introw once, from the invitation, to activate their account. Until they do, the Introw collaboration panel in Salesforce tells them to complete their registration at [app.introw.io/login](https://app.introw.io/login) first. Every visit after that lands on the limited-access screen and points them back to Salesforce.
</Note>

<Warning>
  Only an Admin can create an Admin role or assign one. A colleague without Admin can rename an Admin role and change its notifications, but cannot grant, strip or edit its permissions, and cannot hand Admin to anyone. Keep at least two Admins so you are never locked out.
</Warning>

## Which one to give

| Their job                                                          | Give them                                 | Seat |
| ------------------------------------------------------------------ | ----------------------------------------- | ---- |
| An AE or SDR who co-sells with partners on their own opportunities | **CRM only user**                         | Free |
| A support rep who works partner cases                              | **CRM only user**                         | Free |
| A partner manager who owns a book of partners                      | **Partner manager**                       | Paid |
| Partner ops running parts of the program                           | **Custom**, with the categories they need | Paid |
| The program owner who configures Introw and manages the team       | **Admin**                                 | Paid |

The default for a sales team is a CRM-only role.
Reps get partner context on the record they already have open, at no seat cost, and the program stays configured by the few people who own it.

## Verify it worked

Open the **Users** tab of [Team](https://app.introw.io/settings/team).
The person shows the role you assigned, and your remaining paid seats did not change for a CRM user.
Then check it from their side.
On a Salesforce opportunity linked to a partner, the **Introw collaboration** panel loads for them and they can share and comment.
A visit to Introw shows them the limited-access screen instead of the application.

## Related

<CardGroup cols={2}>
  <Card title="Invite a team member" icon="user-plus" href="/features/access/team-management/guides/invite-a-team-member">
    Add the person and pick the role.
  </Card>

  <Card title="Create an internal role" icon="lock" href="/features/access/team-management/guides/create-an-internal-role">
    Build the role and its access type.
  </Card>

  <Card title="Embed Introw in Salesforce" icon="id-card" href="./embed-introw-in-salesforce">
    The panel and permission set a CRM user works from.
  </Card>

  <Card title="Collaborate from Salesforce" icon="comments" href="./collaborate-from-salesforce-opportunities-and-cases">
    The job a CRM user does all day.
  </Card>

  <Card title="What your plan meters" icon="gauge" href="/features/access/team-management/guides/understand-your-plan-limits">
    Seats, portals and the rest of the counts.
  </Card>

  <Card title="Implementation reference" icon="screwdriver-wrench" href="../technical">
    Full configuration options.
  </Card>
</CardGroup>
