FAQ & Troubleshooting

Updated 15 July 2026

Quick answers when something does not look restricted, looks too restricted, or a user cannot sign in.

Overview

Most support tickets fall into a few patterns: testing as an exempt admin, profile not assigned, archived profile, multiple profiles stacking, or a domain filter that is too strict.

Work through the checklist in How It Works before changing many settings at once.

How It Works

Quick diagnosis checklist

Step-by-Step Guide

Fields Table

These are the settings you will see for this feature, explained in everyday language.

Field Explanations

Each field from the table above is explained in more detail here.

Why don’t I see any restrictions?

Administrators are exempt by design. Also check assignment and Active.

User sees an empty list

Domain filters hide rows. Confirm with a manager account that data exists, then loosen the domain.

Menu hidden but user still opens records

Hiding navigation is not full security by itself – add model and domain rules for sensitive apps.

Export still available

Check both Global and Model Access. Also Hide Spreadsheet if they use spreadsheets to extract data.

Button still visible

Keys are technical; use Discover rather than guessing.

Cannot log in

Only an ACS Administrator (or someone not blocked) can fix Disable Login on that profile.

Rules vanished after archive

Expected. Restore the profile to bring rules back.

Import skipped some lines

Normal when databases differ. Install the same apps or recreate missing lines manually.

New employee has no limits

Defaults are optional – turn on Default for Internal Users on your baseline profile.

Two profiles conflict

Prefer one role profile plus one light baseline instead of many overlapping packs.

Tips

Common mistakes