# Security Configuration
Unlike the other Configuration Reference pages, this is not a fill-in-the-blanks settings screen — it describes the built-in default access rules ContactManager applies out of the box, before any per-record permissions are set. There is nothing to configure here in normal use.
# Built-in default access
| Record type | Who automatically gets access |
|---|---|
| Contact (person, company, employee, …) | The user who created the contact may change who else can access it. Administrators always have full access. |
| Activity | The user who created the activity, and the activity's responsible user (its owner), may change who else can access it. Administrators always have full access. |
| Folders | Administrators always have full access. |
These defaults apply everywhere a record's own permissions haven't been set to something more specific — see Matter Permissions for how a matter's own visibility can be restricted beyond this baseline.