Features > CPQ Access Control
Governance

CPQ Access Control

Pricing analysts needed admin login to edit price lists. The same role could publish configuration rules and open every dealer quote.

Access control · session

Role × object × action × scope

Illustrative demo
RoleView quotesEdit pricingEdit configApprovePublishAll regions
Sales Rep✓—✓——Scoped
Pricing Analyst✓✓————
Product Manager✓—✓—Scoped✓
Regional Manager✓—✓✓—Scoped
DealerScoped—✓———

Pricing Analyst

Object access

  • · Price books
  • · Pricing rules

Actions

  • · View
  • · Edit

Denied

  • · Publish configurations
  • · View dealer quotes
  • · Manage users

Scope

EU Pricing

The challenge

Pricing analysts needed admin login to edit price lists. The same role could publish configuration rules and open every dealer quote.

A truck scale and weighbridge OEM sells configurable platforms, load cells, and terminal software through forty regional dealers. CPQ offered admin and standard user. Pricing analysts needed list edit rights, so they received admin. Dealers needed quoting access but admin also exposed internal price books and other dealers' open quotes when someone shared the wrong bookmark.

Product managers wanted template edit without order submission. Regional sales managers needed quotes in their territory only. IT defaulted to over-provision because the permission model could not split view, edit, price, approve, and publish. Shadow spreadsheets appeared when reps lacked quote edit rights; risk grew when analysts retained publish keys they never used daily.

Audit-log pages prove who did what after the fact. Configuration-governance pages separate authors from publishers. Approval-workflows pages route changes through reviewers. Access control is different: it defines which roles see which objects, which actions they may perform, and which data scope applies before anyone logs in.

Inquiry to config to price to approval to order needs permissions that mirror org reality, not a binary switch that forces admin access for every specialist.

How it works

How Mercura assigns CPQ permissions by role and scope

Administrators define roles in Mercura, such as pricing analyst, inside sales rep, regional manager, or dealer portal user, and assign permissions at object and action level: which catalogs, price books, and quote types are visible; whether the role may create, edit, price, approve, or publish. Data scoping restricts dealers to their own quotes and assigned product range; regional managers see their territory only. Roles combine for hybrid jobs. SSO via SAML or OIDC maps identity from your directory. Permission changes write to audit logs. Governance and approval pages enforce what happens after login; access control defines who reaches which screen in the first place.

Data scoping

Who sees which quotes

Admin

Broader scope

Regional Manager

Dealers A + B + C within assigned region

Dealer A

Only Dealer A quotes

Dealer B

Only Dealer B quotes

Dealer C

Only Dealer C quotes

What's included

What CPQ access control covers

Role

  • Custom roles with object- and action-level permissions

Object

  • Price book and catalog visibility per role or channel

Action

  • Separate rights to view, create, edit, price, approve, and publish

Scope

  • Dealer and territory data scoping enforced in CPQ, not UI hiding alone
  • SSO integration via SAML or OIDC

The difference

CPQ permissions before and after access control

Admin versus user only

  1. 01 Specialists over-provisioned with admin to do one task then
  2. 02 Dealers risk seeing other dealers' quotes or internal lists then
  3. 03 Pricing staff can publish rules they never intended to touch then
  4. 04 Territory and channel data visible across regions then
  5. 05 Access reviews rebuilt manually from spreadsheets

With Mercura

  1. 01 Pricing analysts edit lists without publish or dealer visibility
  2. 02 Dealers configure and quote within assigned catalog and own records
  3. 03 Product managers edit templates without submitting orders
  4. 04 Regional managers see territory-scoped pipeline only
  5. 05 Access review reports exportable for compliance checks

Real-world example

Example workflow: weighbridge dealer isolation

An OEM of axle weighbridges, pit mounts, and indicator terminals sold through forty dealers across six countries. Previously two CPQ tiers forced admin access for pricing staff and left dealers one mis-click from internal lists. After Mercura access control, pricing analysts received edit rights on price books only; dealers received configure-and-quote permissions scoped to their dealer ID and assigned scale families; regional managers saw quotes in their country group without admin keys. A dealer dispute about quote visibility was resolved by showing scope rules, not by trusting UI menus. Implementation took three days because roles mapped to titles HR already maintained.

Business impact

Why access control is commercial risk management in CPQ

Access control matches system permissions to organisational roles so accidental misuse and deliberate overreach both shrink. It complements audit trails, publish governance, approval routing, and separate dealer environments. Mercura does not replace your identity provider or annual access certification process outside CPQ. Someone must define roles when channels expand or product lines split. If the pain is "everyone is admin because the tiers are too coarse", scoped roles in CPQ align inquiry, configuration, price, approval, and order with who should see and change what on every quote.

Business impact

Least-privilege access

Permissions matched to the job, not admin versus user.

Dealer and territory isolation

Data scoping enforced in CPQ for dealers and regions.

Lower over-permission risk

View, edit, price, approve, and publish stay separated.

Compare

SSO vs access control

SSO Authentication

Who are you?

Identity provided by enterprise IdP.

Access Control

What are you allowed to do?

Permissions provided by Mercura role/scope model.

Role permissions · least privilege

See dealers, pricing, and sales on separate permission models

Book a demo and map pricing analyst, rep, manager, and dealer roles until each sees only the CPQ actions their job requires.

Let’s build together.

We empower manufacturers to master product modeling, streamline quoting process, reduce errors, and ultimately deliver the tailored solutions that customers demand.