Features > CPQ Access Control
Governance

CPQ Access Control

Pricing analysts needed admin login to edit price lists. The same role could publish configuration rules and open every dealer quote.

The challenge

Pricing analysts needed admin login to edit price lists. The same role could publish configuration rules and open every dealer quote.

A truck scale and weighbridge OEM sells configurable platforms, load cells, and terminal software through forty regional dealers. CPQ offered admin and standard user. Pricing analysts needed list edit rights, so they received admin. Dealers needed quoting access but admin also exposed internal price books and other dealers' open quotes when someone shared the wrong bookmark.

Product managers wanted template edit without order submission. Regional sales managers needed quotes in their territory only. IT defaulted to over-provision because the permission model could not split view, edit, price, approve, and publish. Shadow spreadsheets appeared when reps lacked quote edit rights; risk grew when analysts retained publish keys they never used daily.

Audit-log pages prove who did what after the fact. Configuration-governance pages separate authors from publishers. Approval-workflows pages route changes through reviewers. Access control is different: it defines which roles see which objects, which actions they may perform, and which data scope applies before anyone logs in.

Inquiry to config to price to approval to order needs permissions that mirror org reality, not a binary switch that forces admin access for every specialist.

How it works

How Mercura assigns CPQ permissions by role and scope

Administrators define roles in Mercura, such as pricing analyst, inside sales rep, regional manager, or dealer portal user, and assign permissions at object and action level: which catalogs, price books, and quote types are visible; whether the role may create, edit, price, approve, or publish. Data scoping restricts dealers to their own quotes and assigned product range; regional managers see their territory only. Roles combine for hybrid jobs. SSO via SAML or OIDC maps identity from your directory. Permission changes write to audit logs. Governance and approval pages enforce what happens after login; access control defines who reaches which screen in the first place.

What's included

What CPQ access control covers

  • Custom roles with object- and action-level permissions
  • Separate rights to view, create, edit, price, approve, and publish
  • Dealer and territory data scoping enforced in CPQ, not UI hiding alone
  • Price book and catalog visibility per role or channel
  • SSO integration via SAML or OIDC
  • Role combination and inheritance for hybrid positions
  • Access review reports showing who holds which permissions
  • Permission changes recorded in audit logs

The difference

CPQ permissions before and after access control

Admin versus user only
  • Specialists over-provisioned with admin to do one task
  • Dealers risk seeing other dealers' quotes or internal lists
  • Pricing staff can publish rules they never intended to touch
  • Territory and channel data visible across regions
  • Access reviews rebuilt manually from spreadsheets
With Mercura
  • Pricing analysts edit lists without publish or dealer visibility
  • Dealers configure and quote within assigned catalog and own records
  • Product managers edit templates without submitting orders
  • Regional managers see territory-scoped pipeline only
  • Access review reports exportable for compliance checks

Real-world application

Example workflow: weighbridge dealer isolation

An OEM of axle weighbridges, pit mounts, and indicator terminals sold through forty dealers across six countries. Previously two CPQ tiers forced admin access for pricing staff and left dealers one mis-click from internal lists. After Mercura access control, pricing analysts received edit rights on price books only; dealers received configure-and-quote permissions scoped to their dealer ID and assigned scale families; regional managers saw quotes in their country group without admin keys. A dealer dispute about quote visibility was resolved by showing scope rules, not by trusting UI menus. Implementation took three days because roles mapped to titles HR already maintained.

Business impact

Why access control is commercial risk management in CPQ

Access control matches system permissions to organisational roles so accidental misuse and deliberate overreach both shrink. It complements audit trails, publish governance, approval routing, and separate dealer environments. Mercura does not replace your identity provider or annual access certification process outside CPQ. Someone must define roles when channels expand or product lines split. If the pain is "everyone is admin because the tiers are too coarse", scoped roles in CPQ align inquiry, configuration, price, approval, and order with who should see and change what on every quote.

See dealers, pricing, and sales on separate permission models

Book a demo and map pricing analyst, rep, manager, and dealer roles until each sees only the CPQ actions their job requires.

Let’s build together.

We empower manufacturers to master product modeling, streamline quoting process, reduce errors, and ultimately deliver the tailored solutions that customers demand.