Learn Mokapen

Main menu
Organization settings Contact us

Security

The Security page defines the default visibility mode for data your organization creates in Mokapen: tasks, projects, contacts, companies, opportunities, tickets, quotes, orders, appointments, and other records that support Collaborators and the lock icon.

This is not a password policy or two-factor authentication (those stay in each user's Personal Profile). Here you decide whether new data starts visible to the whole organization (Public) or already restricted to a small group (Private), with automatic rules for who is added as a collaborator.

To manage who works in the organization, see the Users and Teams guide; for details on each role's permissions, see the Roles and permissions guide.

 

Overview

Mokapen distinguishes two visibility levels on every record:

  • Public (open lock icon) — all organization members with permission to view that type of data can open the record.
  • Private (closed lock icon) — only the record Owner, selected Collaborators (users or teams), and people with appropriate admin permissions can see it; others won't find it in lists, filters, or search.

The Security page does not set the lock on every record one by one: it sets the default behavior at creation and, in private mode, who is automatically added as a collaborator.

Key rule (also shown on the page): Security mode applies only to data saved after you change the setting. Existing records are not recalculated in bulk: they keep the visibility and collaborators they had when saved.

 

Where to find it and who can access it

Open the Organization menu (building icon) → in the sidebar, under the organization name, choose Security.

Only organization Owners see this menu item and can change it. Members, Users, and lower roles cannot access the global security settings (they can still work on individual records according to the rules described below).

After each save, Mokapen logs the update in the organization activity log.

 

Public mode

With Public selected, every new record starts with Public visibility: all colleagues authorized to use that area (e.g. Sales, Contacts) can see it without being added as collaborators.

What you can do before saving — if you have at least the User role, in the creation preview you can click the lock icon and switch the record to Private, then choose collaborators manually. This is useful for one-off exceptions (e.g. a contact reserved for the director) without changing the setting for the whole organization.

Example — Organization "Studio Alfa" in Public mode. Sales rep Laura creates an opportunity: it already appears as public, visible to the whole sales team. Before saving, she can make it private and add only the manager and the "Direction" team if it's a strategic client.

In Public mode, the Collaborators field does not appear by default in quick-create dialogs: visibility is implicitly "whole organization" until you make that individual record private.

 

Private mode

With Private selected, every new record starts as Private. Initial collaborators are not "the whole organization" but the group defined in settings (see following sections).

What you cannot do at creation — anyone who is not an organization Owner cannot set a new record to Public from the dialog: the lock icon stays on Private. This prevents an operational user from accidentally expanding visibility beyond company policy.

What you can do afterwardMembers (and higher roles) can still add other collaborators on the individual record, widening who sees that data without making it public for everyone. Only the organization Owner can switch a record from Private to Public (lock icon when editing).

Example — Organization "Consulenza Beta" in Private mode. Marco (User) creates a task: it starts private with pre-filled collaborators (Marco, his manager, the Team Master). He cannot remove the lock, but a Member can add a colleague from Project X team if needed for that activity.

 

Automatic collaborators (Stakeholders)

In Private mode, below the Public/Private choice, the Collaborators section appears with three options (plus you, always included):

  • Me — always active: whoever creates the data stays among the collaborators and can open it.
  • My manager — adds the hierarchical manager set on the creator's user profile (Manager field in Users and Teams).
  • My teams — adds the teams the creator belongs to as collaborators (not random individual colleagues: the team groups).

You can combine the checkboxes: manager only, teams only, or both. If you uncheck manager and teams, only you plus the Team Master remain (next section).

Practical example — Options: Me + My manager + My teams. Sara is on the "Customer Care" team and her manager is Luca. Sara creates a ticket: initial collaborators = Sara, Luca, Customer Care team, Team Master. A colleague from another department won't see it until added manually.

Note — if a user has no manager set in their profile, the "My manager" checkbox adds no one. If they belong to no teams, "My teams" adds no groups. Keep user profiles and teams up to date before enabling private mode.

 

Team Master

The Team Master is a special team created by Mokapen for organization security. Members you select on the Security page form this group and are always added as collaborators on every new record created in Private mode — even if the creator doesn't know them or doesn't choose them manually.

Typically you include: the Owner, internal IT, the DPO, or a compliance lead who needs cross-cutting visibility on sensitive data.

When creating and editing records — the Team Master appears as a badge with a crown icon. The organization Owner can remove it on a single record (with a warning) if it's not needed for that specific case; other roles see it but cannot remove it from the global policy.

Notifications — when someone is added to the Team Master, Mokapen sends an in-app notification (and email according to preferences), same as joining a regular team.

Example — Team Master: Anna (Owner) and Paolo (IT). Every new private contact created by a sales rep is also visible to Anna and Paolo, in addition to the sales rep and the automatic collaborators chosen in the options.

 

What happens when you switch modes

The change counts from the moment you save onward. Think of two sets of data: already saved and new to be saved.

From Public to Private (e.g. today)

  • Existing records — stay as they are. A public contact created yesterday stays public; a task already private stays private with its collaborators. No automatic migration.
  • Records created from now on — follow Private mode: closed lock by default, automatic collaborators + Team Master.
  • Team Master — Mokapen creates the team (if it didn't exist) and saves the members you choose. At least one is required: the field is mandatory in Private mode.
  • Creation dialogs — from immediately after save, the pre-filled Collaborators field and Team Master badge appear; for anyone who is not an org Owner, the Private lock cannot be changed.

"Going private from today" scenario — Monday morning the Owner enables Private with Me + Manager + Team Master (themselves and compliance). Monday afternoon a sales rep creates a company: it starts private, visible to them, their manager, and the Team Master. The 2,000 companies already in the directory stay public until you change them one by one (or with bulk tools where available). If you also need to make historical data private, plan a project to review collaborators / visibility on existing records: it does not happen on its own.

From Private to Public

  • Existing records — once again unchanged. A private deal with three collaborators stays private.
  • New records — start as Public; anyone with User role or higher can set Private on the individual record before saving again.
  • Team Master — the special team is removed from the organization (access and membership). Older records that had it among collaborators may still show it as a reference until you update collaborators.
  • Stakeholder settings — the manager/team checkboxes no longer apply to new data.

"Going back to public" scenario — After a confidential project, the org switches back to Public. Private projects from that period stay private; tasks created from tomorrow onward will be public by default. The Team Master disappears: people who were only there for oversight must be added manually where needed, or you set up a different policy.

 

Visibility and collaborators on individual records

Beyond the global policy, every record has:

  • Visibility icon (lock) — Public or Private for that record.
  • Owner — person responsible for the data; almost always among the actual collaborators.
  • Collaborators — users and/or teams who can open a private record.

In a Public organization, a public record does not require collaborators: everyone can see it. If you make it private, you must specify who has access.

In a Private organization, new records start private with pre-set collaborators; Members and higher roles can expand the list when editing. Users with lower roles see collaborators in read-only mode.

In saved filters, the visibility field in a private organization is available only to Owners; collaborators can be filtered by Members and higher roles.

 

Who can change what (by role)

  • Organization Owner — configures Security; on any record can switch Public ↔ Private; manages Team Master on individual records; sees visibility filters.
  • Member — cannot open the Security page; on private records can edit collaborators (add/remove, subject to Team Master constraints for non-owners).
  • User / Limited User — creates data according to policy; in a private org cannot unlock Public; collaborators read-only on private records.
  • Guest — does not manage org security; works only on what is shared (e.g. assigned projects).

 

Application examples

  • Law firm — Private + Team Master (senior partners). Every new client contact starts visible only to the creator, their manager, their teams, and the partners. Associates on other teams don't accidentally see other people's clients.
  • Creative agency — Public, with manual exceptions. Projects and tasks are open; before saving a quote for a secret brand, the account manager switches the record to Private and adds only the "Direction" team.
  • GDPR transition — From Public to Private on an agreed date. Internal communication: "from March 1 new data is private; historical data must be reviewed." Team Master = privacy lead + IT.
  • Manager always in the loop — Private with "My manager" checked. Every new deal is visible to the creator's sales manager without adding them manually each time.
  • Temporary confidential project — Org stays Public; the PM makes the single project private and adds the development team. When done, they archive the project without changing the global policy.

 

 

Frequently asked questions

Q: If I switch to Private today, does yesterday's data become private?

A: No. Only data saved after the change follows the new mode. Historical data must be updated explicitly if needed.

 

Q: Can a User create public data in a Private organization?

A: No at creation. Only the organization Owner can set Public on an individual record (when creating or editing).

 

Q: Can I have a Private organization but a public record?

A: Yes, if the org Owner sets the lock to Public for that record. It's the intended exception to the default rule.

 

Q: What happens to the Team Master if I switch back to Public?

A: The team is removed from the organization. New data will no longer include it. Old private records may still list it among collaborators until you edit them.

 

Q: Does "My teams" add individual people or the whole team?

A: It adds the teams you belong to as collaborators (group visibility). Colleagues see the data if they belong to that team or are added individually.

 

Q: Where do I configure password and 2FA for the whole organization?

A: Not on this page. Each user manages their own password and two-factor authentication from Profile → Security. This page is only about CRM data visibility.

Need help?