GDPR Compliance

We use cookies to ensure you get the best experience on our website. By continuing to use our site, you accept our use of cookies, privacy policy and terms of service.

Roles and permissions in Deal Desk 365

Updated September 15, 2026

Deal Desk 365 ships three security roles, and your administrator assigns them. One license gives a user access to the app; the role decides what they can do. The roles are complementary, not nested, and they stack.

The three roles

Role Can do
Deal Desk Seller Create, edit, delete, and reorder quotes, sections, and templates, and submit quotes for approval. Sees pricing rules and approval policies (read-only) and the approval status of their own submissions. Cannot decide approvals and cannot set the approval state directly; it is field-secured, so only the submit and decision logic can change it.
Deal Desk Approver Read every submitted quote and decide approvals (approve or reject with a decision note) on requests assigned to their approver team. Cannot build quotes: no create, edit, or delete on quotes, sections, or templates.
Deal Desk Administrator Set up and maintain the rules of the desk: full control of pricing rules, approval policies, and quote templates. Config-only by design: it reads quotes, approval requests, accounts, and products, but does not build quotes or decide approvals.

Roles stack

A pure Seller cannot decide approvals, a pure Approver cannot build quotes, and a pure Administrator does neither; they configure the desk. Give a user every role their job needs:

  • A sales-ops lead who also builds quotes gets Administrator plus Seller.
  • Someone who builds quotes and signs off gets Seller plus Approver.
  • Assigning roles to a Microsoft Entra group instead of individuals scales better for larger teams.

Why an Administrator role?

Creating pricing rules and approval policies used to require a Power Platform System Administrator, which is too much privilege for a sales-ops owner. The Administrator role is scoped to exactly the configuration Deal Desk 365 owns, so the person who runs the desk can maintain it without holding the keys to the whole environment.

Assigning roles

Roles are assigned in the Power Platform admin center under Settings → Users + permissions → Users (select the user, then Manage security roles), on top of the user's existing Sales role. See Set up Deal Desk 365 after installing.

Licenses are separate from roles

A role does not grant access on its own. Everyone who opens the Deal Desk app needs a Deal Desk 365 - Named User license, assigned in the Microsoft 365 admin center, plus their existing Dynamics 365 Sales license. The ten-seat minimum applies to the plan. See Requirements and licensing.

Environment variables are separate too

The approval behavior settings live in the Power Apps maker portal and need a System Customizer or System Administrator to change. They are not governed by the Deal Desk roles, including Administrator. See Approval behavior settings.