CRM playbook
CRM Permissions, Roles, and Security Without Slowing the Team
CRM security is usually ignored until a contractor can see every deal amount or a departed employee still has a login. Then it becomes a panic project. You can avoid that with a small set of roles, a rule for sharing, and a quarterly access review. This is not an enterprise GRC manual. It is what a growing team can actually maintain.
Start with four roles
Most companies need a seller, a manager, an admin, and a read-only viewer. Sellers see their own records and, if your culture requires it, the team's records. Managers see their people. Admins change fields and automations. Viewers include finance or leadership who should not edit stages on a Friday night.
If everyone is an admin because it was easier on setup day, you do not have roles. You have hope. Create the four profiles even if two people wear three hats. When you hire, you will drop them into a lane instead of cloning a superuser.
Sharing rules that match how you sell
Private by owner is the safest default for amounts and notes. Team-visible is fine when collaboration is the product. Org-wide visibility of every note is how gossip and side deals leak. If you sell into competitors in the same territory, think harder than “everyone can see everything.”
Field-level security matters for salary-like data: discount ceilings, home addresses, and support credentials that should never have been pasted into a note. If people must store secrets, give them a vault, not a CRM text box.
Guests, contractors, and agencies
Marketing agencies and fractional operators love a full login. Give the minimum. A partner portal or a shared view is better than a spare admin seat. Expire guest access on a date. Calendar a reminder. The contractor who finished in March should not still be browsing accounts in November.
When someone leaves, remove access the same day, including connected inbox and mobile sessions. Export their personal notes only if policy allows. Do not keep a “we might need their login” culture.
Audit and exports
Turn on login history if the product offers it. Know who exported a list. A CRM is a directory of your buyers. Treat a full export like you would treat a customer spreadsheet on a USB drive. If you cannot see exports, ask the vendor during buying, not after an incident.
SSO and multi-factor authentication should be on before you store serious volume. Shared passwords in a chat channel are not a temporary phase. They are the phase that lasts until something breaks.
Operational security is also data quality
Duplicate accounts and personal email addresses on company deals create risk. So do notes that include customer passwords from a screen share. Train once. Add a short “do not store this here” line in onboarding. Review a sample of notes quarterly. Culture beats another policy PDF.
The least glamorous admin job in a CRM is also the one regulators and customers assume you already do: knowing who can see a record, and proving you removed the people who should not.
30-day access cleanup
- List every user and mark employee, contractor, or leftover.
- Create seller, manager, admin, and viewer roles.
- Remove unused admin rights.
- Turn on MFA. Prefer SSO if you already have it.
- Set a default sharing model and write it in one paragraph.
- Expire or calendar-expire every guest seat.
- Check whether exports are logged.
- Schedule a 15-minute access review on the first Monday of each quarter.
Frequently asked questions
Should sellers see each other's pipelines?
In small collaborative teams, often yes. In competitive or regulated environments, no. Choose on purpose.
Is a password manager enough without SSO?
It is better than reused passwords. SSO is better still once you have more than a handful of tools.
Can we give the board a login?
Give a read-only dashboard or a scheduled export. Curious clicking on live deals creates accidental edits.
What about API keys?
Treat them like admin passwords. Named owner, rotation, and no keys in public scripts.
Do we need a data processing addendum?
If you handle personal data of customers or their customers, legal should review vendor terms. This is normal, not optional decoration.
Operating notes for CRM access and security
Design roles around job responsibilities, not individual names. Sales reps, managers, finance, marketing operations, support, contractors, and administrators should each receive the minimum access needed for normal work. Exceptions should expire or be documented; permanent one-off permissions are how a clean model slowly becomes impossible to audit.
Protect the actions that change history. Bulk export, deletion, ownership reassignment, workflow editing, integration credentials, and permission changes deserve tighter controls than ordinary record updates. Use single sign-on and multi-factor authentication where available, and keep at least two trusted administrators so access does not depend on one person.
Review connected apps with the same seriousness as user seats. An integration token can have broader access than the employee who installed it. Record who owns each connection, what objects it reads or writes, and what happens when the owner leaves. Remove abandoned marketplace apps and rotate credentials after material staff or vendor changes.
Run a quarterly access review using a real export of users and roles. Compare it with current employees, contractors, and responsibilities. Sample sensitive records to confirm field-level restrictions work in practice. Security controls are useful only when the permissions visible in the admin screen match what users can actually see and change.