Reviewing admin permissions: Check who has admin access and why they need it; Verify current duties still justify elevated rights; Audit permission grants across roles, teams and permission sets
Image: CRM Stack

Permissions

Part of CRM permissions

Reviewing administrator permissions

Inventory CRM administrators, compare grants with current duties, inspect audit history and record decisions when privileged access changes.

Review CRM administrator permissions by checking who has powerful access, why they need it and whether their current duties still justify it. An administrator may be able to change sharing rules, manage users, alter integrations or reach large amounts of customer data. A job title alone is a poor reason to keep those rights indefinitely.

Key CRM Security Practices in Australia

Audit logs available in HubSpot
Yes (varies by subscription tier)
Salesforce Setup Audit Trail
Available
Dynamics 365 security roles for sales
Defined and configurable
Cyber.gov.au guidance on admin privileges
Restrict administrative access to minimise risk

Inventory the actual grants

Export or inspect current user and permission assignments using the CRM’s available controls. Include full administrators, narrower configuration roles, users who can manage permissions or exports, integration identities and any external consultants with elevated access.

For each account, record a human owner, business purpose and approval. Note whether the account supports daily sales work, occasional configuration work or an integration.

Look for grants from several places. A user may receive permissions directly, through a team or role, or through an added permission set. Check effective rights before concluding that removing one assignment will narrow access. Also check whether a former project or vendor engagement explains an exception that is still active.

Compare access with the work

Ask the responsible manager to identify the tasks that require each privileged grant. Someone who reviews sales performance may need reports but not user administration.

A colleague who adjusts a pipeline may need configuration rights for that work without broad authority over security settings. Where the CRM allows narrower privileges, use them and test the resulting workflow with the person doing the task.

Review question / Evidence to examine

What can this account change?
Effective role, permission set and team grants
Why is the grant needed now?
Current task and approving owner
What did it change recently?
Available setup or account audit history
What happens if access is reduced?
Test of the required task with narrower rights

Keep a reliable way for authorised staff to recover administrative access, but define who can use it and how its use is recorded. Avoid making broad rights the routine answer to a single blocked task.

Review changes and repeat at the right moments

Inspect available audit history for permission changes, new integrations and changes to sharing settings. HubSpot documents account audit logs, with available data varying by subscription.

Salesforce’s page title indicates a Setup Audit Trail. Neither replaces a current inventory: an audit log tells you what changed, while the inventory tells you who can act now.

Repeat the review when an administrator changes role, a consultant finishes work or a system integration is replaced. Include administrator grants in a scheduled access review as well.

Revalidate privileged access regularly and when duties change or staff leave. Record the decision and the reviewer so a retained exception remains explainable.

More from Permissions