Visibility of contacts — who sees which contacts and contracts?
In ContractHero there is no separate permission layer for contacts. Anyone who is allowed to see contacts sees all contacts in your organisation. What they do not see everywhere are the linked contracts — those follow the normal permission rules (Standard or APC concept).
That is usually sensible, but it can lead to misunderstandings — for example when someone asks: “Why can I see this contact but not all of its contracts?” This article explains how the visibility logic actually works and what you should bear in mind.
Your benefit
A clear model of who sees what saves you follow-up discussions:
- Sales sees the customer contact but not the confidential management contract — without you having to hide the contact.
- External consultants see the supplier list, but only the contracts in their own contract category.
- Audit-relevant data stays protected through the contract permission — not through creative contact workarounds.
How contact visibility works
Step 1: contacts are visible organisation-wide
Every employee with read permission for the contacts area sees all contacts under Contacts [Kontakte] → Overview [Übersicht] — regardless of whether they are allowed to see the associated contracts.
This means that contact master data (company name, address, contact person, telephone, email) is transparent across the entire organisation. A contact is not “hidden” just because one of its contracts is confidential.
Step 2: the contracts per contact follow the contract permission
When an employee opens a contact, they see the contract list for that contact on the right — but only the contracts they have access to through their permission concept.
Example: the contact “Aroundcity Immo GmbH” has 3 contracts — a tenancy agreement (Real Estate team), a supplier contract (Operations team) and an NDA (Legal team). If Lisa is only in the Operations team and only sees supplier contracts, she will see only that one contract — the other two do not appear in her list.
Step 3: the permission logic comes from the roles
The actual visibility of the contracts is controlled through your organisation's permission concept — Standard or APC. The role rules define which contracts are visible and editable. Those rules automatically apply in the contact view as well.
What this means in practice
Anyone who is allowed to create, edit or view contacts sees all contacts.
There is no differentiated “contact X is only visible to user Y” logic in ContractHero. Master data of contract partners is transparent organisation-wide.
Anyone who is not allowed to see contracts will not see them via the “contact” detour either.
The contract permission applies everywhere — in the contract list, in the contact view, in the export and in search results. There is no loophole for finding a confidential contract “indirectly” via the contact.
Frequently asked questions
Can I make a contact visible to one specific user only?
No. Contacts are visible organisation-wide to all users with read access to contacts. If you really do want to show individual people to just one person, ContractHero is the wrong tool — the platform is deliberately built to be transparent.
How do I hide confidential business partners?
You cannot hide the contact, but you can protect all of the contracts belonging to it through the permission concept (category, team, status). Anyone who opens the contact will see the company name, but no confidential contract details.
Why do I see a contact but no contracts for it in the list?
Because you have no permission for any of the contracts linked to that contact. The contact itself is visible (master data); the contracts are filtered by the permission concept.
Who can edit or delete contacts?
Editing rights depend on your role. Write permissions for contacts are a permission separate from write permissions for contracts — ask your admin if you are unsure.
Can I set up different visibilities per contact type (Customer [Kunde], Supplier [Lieferant], Service provider [Dienstleister], Person [Person], Company [Unternehmen])?
No. Contact types control the fields of a contact (Field Builder [Feldbaukasten]), not its visibility. Visibility is the same organisation-wide.
What happens to a contact if the only contract for it is deleted?
The contact remains — contacts and contracts are separate objects. You can delete the contact manually if it is no longer needed.
Are contact notes treated in the same way as master data?
Yes. Everything in the contact record (master data, notes, address, industry, etc.) is visible to all users with read access to the contacts area.
Good to know
- Contacts are not a confidentiality layer. If you genuinely need secret business-partner lists (M&A, undisclosed subsidiaries), they do not belong in ContractHero. The platform is designed for transparency in contract management.
- APC protects contracts, not master data. Even with the strictest APC setup, the contact remains visible as an entry — what is protected is the linked contract content.
- Audit logs show contact changes. Anyone who edits a contact appears in the change log [Änderungsprotokoll]. That is an additional safeguard against master data being manipulated unnoticed.
- Keep the main contact person and the business partner separate. The main contact person [Hauptansprechpartner] entry of a contact is a convention, not a permission mechanism. Anyone who sees the contact also sees the contact person.
- We are often asked this during onboarding. “Who is allowed to see which contacts?” is a frequent question in the first onboarding call — and the right answer is usually: “Everyone who is allowed to see contacts — the real separation happens through contract permissions.”
Not using this feature yet, or would you like to set your permissions up more cleanly?
Your account manager will show you how roles, APC and contract categories can be sensibly combined — 15 minutes is usually enough. Get in touch via the web chat, by email to support@contracthero.com or by phone on 030 / 577 123 32.
Related articles
- How can roles and permissions be managed for additional users?
- How do I create roles?
- Permission concepts compared: Standard and APC (incl. Dynamic)
- Advanced Permission Concept (APC): how to configure roles with rules
- Contacts: creating and managing contract partners cleanly
- Contact Field Builder: managing different types of contacts
Updated on: 08/26/2026
Thank you!
