NearSync Help

Settings

Who Sees Whose Records How hub scope and hub access grants decide whether someone sees every office's records or only their own.

Permissions decide what a role can do. Hub scope decides whose records they can do it to. Two people with identical roles in different offices should not see each other's deals, and this is the setting that makes that true.

If your workspace has one hub, none of this applies - there is nothing to separate, and the Hub Scope surface says so.

Two surfaces, under Settings, Hubs:

  • Hub Scope - the policy per area. Read-only.
  • Hub Access - grants per person. Editable.

Hub Scope

Settings, Hubs, Hub Scope. For each area of the platform, one of three modes:

Mode What it means
Global Keys to every office. The person sees every hub's records; the acting-hub selector is ignored.
Hub-scoped Only their own rooms. The person sees only the acting hub's records; the selector drives the view.
Hybrid Advisory only. Not yet enforced per record - treated as hub-scoped today.

Caution

Hybrid does not currently do anything different from Hub-scoped. If an area shows Hybrid, plan on hub-scoped behaviour. Do not design a process around a per-record split that is not enforced yet.

How A Mode Is Decided

Resolution order, first match wins:

  1. Logic-locked - some areas are fixed by the platform and cannot be changed. These show a lock and a reason.
  2. Your override
  3. Platform default
  4. Falls through to global

Each row shows where its value came from, under "Source", so you can tell a deliberate setting from an inherited one.

A global grant always wins. If an area resolves to Global, the acting-hub selector is ignored no matter where that value came from.

Keep in mind

This surface is currently read-only. It shows you what is in force and why; setting your own override per area is not yet available. To change what a specific person sees, use Hub Access grants below, or the role's hub reach on the Permissions surface.

Hub Access

Settings, Hubs, Hub Access. Grants for individual people, layered on top of the policy above. You need weight 60 or above.

By default someone sees records in their home hub only, under their own role. A grant adds to that:

  • Global scope covers every active hub. Intended for executives.
  • A specific hub grants that one office.
  • A role override on the grant lets someone hold a different role in a different hub - Manager in Dubai, Member in Riyadh, one person, one login.

Granting Access

  1. Find the person.
  2. Choose the target - global scope, or a specific hub.
  3. Optionally set a role for the grant. Leave it empty and they keep their own role there.
  4. Save.

Granting global scope removes any specific hub grants that person had, because global supersedes them.

Grants can carry an expiry date and a note. Use both when the access is temporary - maternity cover, a secondment, an audit. A grant with an expiry and "covering Riyadh Q3, per JD" in the note is a grant someone can safely revoke later. An unexplained permanent grant never gets removed.

Two Views

  • Table shows grants as rows and is where you add and remove them.
  • Matrix shows people against hubs as a grid, and is for auditing - the fastest way to spot someone with more reach than they should have.

Role Reach Or Personal Grant

Both exist. They solve different problems.

Use role reach (on Permissions) when the restriction is structural: the Riyadh sales role works in Riyadh. It applies to everyone holding the role, now and in future.

Use a hub access grant when it is an exception: one manager covering a second office. It applies to that person, and can expire.

If you find yourself granting the same exception to everyone in a role, it was structural. Move it to role reach.

Checking Someone's Actual Reach

  1. Open Hub Access and switch to the matrix view.
  2. Find their row. It shows their effective role in each hub, including the implicit grant from their home hub.
  3. Compare against what the job needs.

Common Questions

Someone cannot see a record they should. Check in order: is the record attached to a hub at all, is the person granted that hub, and does the area resolve to Hub-scoped. A record with no hub falls back to the default hub.

Someone can see records they should not. Almost always a global grant. Check the matrix view for global scope on their row, and check whether their role's reach is set global on the Permissions surface.

Why can I not edit Hub Scope? Tenant overrides are not available yet. Locked rows are fixed by the platform regardless. Use hub access grants and role reach for now.

Does this replace permissions? No. Permissions decide what they can do, this decides which records they can do it to. Someone needs both.

8 minUpdated 28 July 2026

Did this answer your question?

No, ask a person