Current behavior When “Restrict data visibility to only assigned data” is enabled, users should only have access to data related to contacts they are authorized to access. However, this restriction currently does not apply to Documents & Contracts. Users can see contracts belonging to contacts they cannot access and for which they are neither the Assigned User nor a Follower. We previously raised this with GHL Support and were informed that user-level permissions and visibility settings for Documents & Contracts are currently not supported. Why this is a problem Contracts can contain sensitive personal, financial and business information. If a user cannot access a contact because of “Only Assigned Data”, it is inconsistent that the same user can still access that contact's contracts. Currently: Contact not accessible → Contract belonging to that contact is still accessible The current workaround is not a solution The only workaround we have found is to remove the “View & Manage Payments” permission. This prevents the user from seeing Contracts, but it also prevents them from collecting payments via POS / Tap to Pay. For organizations like ours, where multiple users or volunteers need to collect payments at events, this is not a viable solution. In practice, we are forced to choose between: Allow payment collection → users can access Contracts they should not see Protect Contracts → users can no longer collect payments A user who only needs POS/payment functionality should not automatically receive access to potentially sensitive Contracts. This makes it difficult to follow the principle of least privilege, where users should only receive the permissions they actually need to perform their role. Expected behavior “Only Assigned Data” should also apply to Documents & Contracts. User has access to the contact → related Contracts are visible User does not have access to the contact → related Contracts are not visible Alternatively, Documents & Contracts should have their own granular visibility permission, allowing administrators to choose between: All Documents & Contracts or Only Documents & Contracts related to contacts the user has access to This would allow organizations to give users the POS/payment permissions they need without unnecessarily exposing Contracts and sensitive customer information.