Expert knowledge for digital decisions
How to Plan Permissions and Roles in CRM?
Short answer
A Functional Role Model
| Role | Sees | Can Change |
|---|---|---|
| Sales | Own customers and opportunities | Own records |
| Sales Management | All customers and opportunities | All, plus assignment |
| Internal Sales | All customers | Master data, tasks |
| Accounting | Master data, invoices | Payment status |
| Management | Everything, read-only | Reports |
Three to five roles are usually sufficient. Creating twelve roles means they will not be maintained.
What is Often Overlooked
Reports Bypass Permissions. A report on all sales shows figures that the person in the individual record should not see. Reports require their own permissions.
Export is a Permission. Those who are allowed to export can take the entire inventory. This permission should be granted consciously and logged.
Departed Employees. Access must be blocked on the last working day – not when someone notices. Their records must simultaneously be assigned to someone else; otherwise, they become invisible.
Data Protection
A tiered permission concept is not an option but part of the technical and organizational measures according to Art. 32 GDPR. "Everyone sees everything" is difficult to justify in an audit case.
Practical Advice
Start narrow and open up as needed. The reverse approach – granting everything first and later restricting – creates resistance because people lose something they already had.
Key facts
- Number of Roles
- Three to five
- Often Overlooked
- Reports and export permissions
- Approach
- Start narrow, open up as needed
Sources
All external claims are backed by traceable sources.-
01
Datenschutz-Grundverordnung (Verordnung (EU) 2016/679) Amt für Veröffentlichungen der EU