Hello
We are evaluating whether one self-hosted EspoCRM instance can be used by multiple legally separate entities.
Users of each entity must only be able to access their own customer and operational data. Selected management users, however, need a consolidated view and consolidated reporting across all entities.
Our intended approach is to assign records and users to separate Teams and control access through Roles using the “own”, “team” and “all” access levels.
Is this the recommended architecture for this type of setup?
We would also appreciate clarification on the following points:
- Can Teams and Roles provide reliable data separation between the entities?
- Do Advanced Pack reports respect record-level and field-level access permissions of the user viewing or executing the report?
- Do workflows and BPM processes respect the permissions of the initiating user, or can they access fields and records beyond that user's permissions?
- Are there any known limitations when management users require consolidated reporting across all entities?
- Are there situations in which separate EspoCRM instances would be recommended instead?
No legal or contractual tenant isolation is required for this question. We are specifically interested in the technical access-control model.
Thank you.

Comment