CRM User Access Review: Checking Who Can See What Each Quarter
A user access review is a short quarterly check. You compare every CRM account with your current team and what each person actually does, then remove or downgrade anything that no longer fits. Sound familiar? Accounts set up ad hoc over the past two years, former freelancers who can still log in, everyone made an administrator “just to save time”. If that’s you, this check is for you. Below is a five-step routine you can finish in an afternoon and repeat every quarter.
Table of Contents
What is a user access review and why run it every quarter?
A user access review is a periodic permission review. It confirms who has a CRM account, what role that account holds and whether the access is still justified. Simple enough. But in a small firm, access drifts without anyone ever deciding it should. Accounts get created in a hurry. Projects end, freelancers wrap up their work, people change roles, and their permissions just sit there, unchanged.
Why quarterly? It’s often enough to catch leavers and role changes before they pile up, and rare enough that an owner or office manager will actually keep doing it (a monthly routine nobody follows is worth less than a quarterly one people stick to). And the risk isn’t abstract. Client contact details, deal values, contracts and support tickets stay visible to people who no longer need them. GDPR expects appropriate security measures, so check with your adviser what that means for your company.
Least privilege: why “everyone is an admin” is a problem
Least privilege means each person gets only the access their job requires. Nothing more. Admin rights in a CRM go well beyond daily work, though. An administrator can change settings and roles, export all data, delete records and add new users.
Now picture everyone holding those rights. One wrong click can bulk-delete records. Anyone can walk off with a full export. And nobody clearly owns the settings, so when something breaks, who fixes it? In my view the safer setup is boring on purpose: one or two named administrators, for example the owner and one backup, and standard roles for everyone else.
Before you start: the three lists you need
You need three lists before the review: the CRM users, the current team and a short summary of what each role needs. Put them side by side and the whole thing turns into a comparison instead of guesswork.
- CRM user list: names, email addresses and assigned roles, exported or copied from the user settings.
- Current team list: taken from payroll, contracts or the office manager, including freelancers with active engagements and their end dates.
- Job-needs sheet: which records each role actually works with, such as the sales pipeline, help desk, projects and tasks, or reports.
One more thing. Pick one reviewer to prepare the check and one approver, usually the owner, to sign it off.
The quarterly CRM access review, step by step
Five steps. Each one fits into a single sitting.
- Pull the full CRM user list, including roles.
- Match every account to a named person on the current team. No match? Then the account belongs to a leaver, a former freelancer or a shared login.
- Check each role against what that person really does. Sales reps see their own leads and deals, support staff see tickets, and office staff see contacts and tasks.
- Remove accounts belonging to people who have left, downgrade roles that give more than the job needs, and swap shared logins for personal accounts.
- Record the review date, the changes made and who approved them in a simple spreadsheet or document.
How to handle inactive user accounts and former freelancers
Deactivate or remove any account with no current owner or active contract. Straight away, not “later” (later tends to mean never). Before you remove it, though, reassign that person’s open deals, leads, tasks and tickets to someone on the team so nothing ends up orphaned.
With freelancers, tie access to the contract end date and put that date in the calendar. Base every decision on the team list and the contracts, not on anyone’s gut feeling. Staff departures follow their own procedure for removing access when people leave, and the quarterly check is the safety net that catches whatever that procedure missed.
Role review checklist: matching permissions to real jobs
A role review checklist is just a short set of questions you ask about each role. Feel free to copy this one:
- Does this role need to export data?
- Does it need to see all deals and contacts, or only the ones assigned to it?
- Does it need to change pipeline stages, tags, user roles or notification settings?
- Does it need to delete records?
- Does it need to see other people’s tasks and projects?
In EpicCRM you handle this through roles and permissions and task visibility, so a handful of standard roles covers most small teams. If you’re building them from scratch, a guide to setting up CRM roles walks you through it.
Keeping a record of each review
A one-page log is enough. Date, reviewer, approver, accounts removed, roles changed. That’s what turns a one-off cleanup into a routine you can actually show when someone asks. Keep it somewhere shared and set a quarterly reminder. Or make the review a recurring EpicCRM task with an assignee and a reminder, so it doesn’t depend on anyone’s memory.
Start each review from the previous log. Why? Because it shows the repeat offenders: shared logins creeping back, freelancers outliving their contracts. Access control is one layer of a wider approach to the security of cloud CRMs, and honestly it’s the one layer you control completely.
So, an afternoon per quarter, and your CRM data stays visible only to the right people. Book the first review this week. My advice: start with the easy wins, removing former freelancers and cutting down the number of admin accounts.
FAQ
How often should a small business run a user access review?
Quarterly, as the routine. But also check access right away whenever someone leaves or changes role. Don’t wait for the next scheduled review.
Who should approve CRM access changes?
The owner or one named manager. If the team is big enough, keep the reviewer and the approver as two different people. Either way, record who approved each change.
Is it safe to remove admin rights from long-time employees?
Yes, as long as a standard role covers their day-to-day work. Seniority doesn’t call for admin rights. What the business does need is a backup administrator, so keep one and you’ll never be locked out of your own settings.



