# Security Configuration

Unlike the other Configuration Reference pages, this is not a fill-in-the-blanks settings screen — it describes the built-in default access rules ContactManager applies out of the box, before any per-record permissions are set. There is nothing to configure here in normal use.

# Built-in default access

Record type Who automatically gets access
Contact (person, company, employee, …) The user who created the contact may change who else can access it. Administrators always have full access.
Activity The user who created the activity, and the activity's responsible user (its owner), may change who else can access it. Administrators always have full access.
Folders Administrators always have full access.

These defaults apply everywhere a record's own permissions haven't been set to something more specific — see Matter Permissions for how a matter's own visibility can be restricted beyond this baseline.

Last Updated: 9/8/2026, 2:26:35 PM