This is a classical scenario, and it's described very well in the Reference Guide, within the chapter "Security". The only caveat to keep in mind is that you can't link directly to the field USERID (I think...) - you need to create an additional field (like SP for salesperson) and link to it instead.