KamoCRM

The external field view of a lead, ?fieldAudience=EXTERNAL (KamoCollab CP07 Task 9)

FeatureSecurityService
Shipped
October 11, 2026 at 9:36 AM UTC
Author
Kamo
Commit
7db3e36

LeadFieldMask.applyExternal keeps exactly spec §5.18's fields, reduces the assignee to name and title, and nulls every other LeadDTO field through a fail-closed allow-list. getLeadById applies it after the existing gates and colleague mask; any other fieldAudience value is a 400 naming the field. The PHI-access record of the read is unchanged.

All changes

Like what you see shipping?

All of it arrives in your workspace on its own. Start on the free plan and read this page again in a month.

Start Free ForeverView Pricing