Mapping CRM Users and Roles to Mobileforce

Mapping CRM Users and Roles to Mobileforce

Since Mobileforce CPQ is SSO integrated with CRMs, you just need to log in to your CRM, and from there, you can directly access Mobileforce without additional authentication. Furthermore, your CRM user role can be leveraged by Mobileforce to provide you with a personalized user experience (based on your role).

CRMs typically associate Users with Roles, in order to simplify and control access (Read, Write) to CRM Objects. This section describes how Mobileforce uses CRM roles to provide fine grain control to the CPQ workflow, the CPQ screens, and access control on various CPQ processes such as approvals, discounts, Quote UI, etc.

HubSpot Permission Sets

Roles in HubSpot are called Permission Sets, which control fine grain access (View, Edit, Delete) to various objects that are grouped as CRM Objects, Sales Objects, etc.

In order to use Mobileforce CPQ with HubSpot permission sets, the following steps need to be taken by a HubSpot Administrator.

  1. Add all the seller users to your HubSpot SalesHub instance. This is done by navigating to Settings --> Account Management --> Users and Teams. and clicking "Create User".

This step can be skipped if the users are already created in HubSpot Sales (but you'd need to ensure that the users have appropriate access to various CRM Objects).

Since Mobileforce CPQ relies on HubSpot SSO, all users of Mobileforce CPQ must also be HubSpot users. If you need non-HubSpot users to gain access to Mobileforce CPQ (perhaps because they need to approve quotes), please contact your Mobileforce Support Team.

  1. Next, you should create a HubSpot Permission Set that gives all such "seller" users the necessary HubSpot object permissions in order to use Mobileforce CPQ. For example, your organization may have a group of "global" sellers who follow a unique sales workflow and quoting process, that may be different from regional sellers. To create a permission set, specifically for such Global Sellers, click on the "Permission Sets" tab (on top) on the HubSpot Users and Teams screen. See the following

From here, use the " Install and Configure Mobileforce for HubSpot" to select the correct permissions for various HubSpot SalesHub objects such as Contacts, Companies, and Deals.

  1. For verification, click on the "review" tab on the Edit Permission Sets page and verify that your permissions are as follows:

  2. Next, assign those sellers that you created in Step 1, to the appropriate permission sets, created in Step 2. See the following:

  3. Finally, assign these users (e.g., users in the permission set: Global Sales), to a team. This step is important, since Mobileforce uses Teams to map users to a personalized sales experience. To do this, First, select the Teams tab in Users and Teams screen.

Now, create a team (" Global Sales"), and add all the users, e.g., all users in "Global Sales" Permission Set to this team. Note that the Team name can be distinct from the Permission Set name.

Once Teams (e.g., Global Sales, Local Sales) are created in HubSpot, Mobileforce can automatically access these Teams via the Mobileforce role specified by the tag: hs-Global Sales. Notice the prefix "hs-" which indicates a Mobileforce role that was derived from a HubSpot Team. Using the tag !hs-Global Sales) Mobileforce allows (or prevents) specific Teams from accessing specific Application screens and workflow. Notice also the use of "!" to indicate the negation of the hs-Global Sales role: thus referring to all users who are NOT in the hs-Global Sales role. To personalize your Teams to capability or Screen mapping, please contact your Mobileforce Support Team.