Profiles in Zoho CRM let you control exactly which modules, records, and actions each group of users can access — creating them correctly from the start saves significant rework as your team grows.
Why this matters
When you add new users to Zoho CRM, every user must be assigned a Profile that governs their permissions. Different teams — sales, marketing, management — need different levels of access, and Profiles are the mechanism that enforces those boundaries. [3] Getting this right early means that when you need to adjust permissions for an entire group, you only update one Profile rather than editing every individual user. [1]
> Beam Help is an independent expert support resource for Zoho products — we are not official Zoho support.
---
Step-by-step
Step 1. Understand what a Profile does.
A Profile in Zoho CRM defines a permission set that is then assigned to one or more users. For example, the access a sales representative needs is typically different from what a marketing team member requires, so each group should have its own Profile. [3]
Step 2. Start from a built-in template rather than building from scratch.
Zoho CRM ships with several ready-made Profiles — including Administrator, Standard, and Marketing Manager. Our team strongly recommends cloning one of these existing Profiles as your starting point, then customising the clone to match your requirements. This approach is faster and less error-prone than configuring every permission manually. [1]
Step 3. Navigate to the Profile Management area.
In your Zoho CRM account, go to Setup (the gear icon) → Security Control → Profiles. This is where all Profile creation and editing takes place. [3]
Step 4. Clone an existing Profile.
Locate the built-in Profile that most closely matches the role you are creating (for example, "Standard" for a typical sales rep). Use the Clone option next to that Profile. Give the cloned Profile a clear, descriptive name — for instance, "Sales Executive" or "Marketing Specialist." [1]
Step 5. Configure the permissions on the new Profile.
Once the clone is open, you can enable or disable individual permissions with a single click. Permissions are grouped into logical categories, making it straightforward to customise access without having to hunt through a flat list of options. Work through each module your team uses and set the appropriate create, read, edit, and delete permissions. [3]
Step 6. Save the Profile.
After reviewing all permission groups, save the Profile. It is now available to assign to users.
Step 7. Assign the Profile when creating or editing a user.
Navigate to Setup → General → Users, then click + New User (or edit an existing user). Fill in the user's name and email address, then — critically — select both the Role and the Profile you just created. Click Save. Zoho CRM will automatically send the user an invitation email; when they log in, they will see only the modules and data their Profile permits. [1]
---
Common pitfalls
- Creating too many Profiles. If your organisation has 20 or more staff, avoid making a unique Profile for every individual. Instead, group users by function: one Profile for all sales reps, one for team leads, one for marketing. When a policy changes, you update a single Profile and every member of that group is updated instantly. [1]
- Editing the default Administrator Profile. The built-in Administrator Profile is a system default. Always clone before editing so you retain a clean baseline to reference later. [1]
- Forgetting to assign a Profile when inviting users. A user without a properly configured Profile may receive broader or narrower access than intended. Always confirm both Role and Profile are set before saving a new user record. [1]
---
What to check
- Verify the Profile is saved and visible in Setup → Security Control → Profiles before assigning it to any user.
- Confirm the user received their invitation email and that, upon first login, they can see only the modules and records appropriate to their assigned Profile. [1]
- Review grouped permissions inside the Profile to ensure no critical module has been accidentally left disabled or over-permissioned, using the single-click enable/disable controls. [3]