Deciding who can see which contacts
A small business usually starts with everybody seeing everything, which is simple and works for a while. It stops working the first time somebody's pay rate, a margin or a sensitive matter sits in the same list as a phone number. Everybody needs to find a customer and ring them. Far fewer need to see what that customer pays. Those are two different permissions, and most CRMs offer one.
Separate finding a contact from reading their detail
Everybody needs to find a customer and ring them. Far fewer need the rates, the margins or the notes. Treating those as one permission is why businesses end up choosing between open and useless. Diract CRM grants access by role, and a role decides both which tables somebody opens and which fields inside them they read. The phone number stays findable while the rate stays hidden, which is what the business actually wanted.
Three shapes, and when each fits
- Everybody sees everything. Right for a business of three where all three do all the work.
- By role. Right once jobs differ: a coordinator, a technician and an owner need different views.
- By record. Right where particular matters or clients genuinely need restricting, and wrong as a general rule.
Most businesses need the second and reach for the third, which produces an access model nobody can explain a year later. Restricting by record suits a handful of genuinely sensitive matters. A business with forty record level exceptions has built something only its author understands. Roles scale, and exceptions do not.
Roles describe jobs, not people
A role named after a person becomes wrong the day they leave. A role per person is a list nobody maintains. Our guide to setting permissions by role covers writing down the jobs rather than the names. Access also creeps upward, always. Every exception granted for a good reason stays granted, so a yearly review comparing each role against its job keeps the model honest.
A hidden field must not break a save
A required field somebody cannot see stops them saving a record, with no explanation they can use. Hiding a field has to hide it from the requirement too. Diract CRM drops the requirement for anybody who cannot see the field, so a permission never produces an unsaveable record. A boundary a person can work with is a boundary they respect. A dead end is one they quietly circumvent.
Search results leak more than people expect
A search returning a matter somebody cannot open has told them it exists, and sometimes the existence is the confidential part. The rule is narrow: a result appears only where the person could have reached that record anyway. Notes need the same attention. A business restricting a salary field often leaves the same figure in a note everybody can read. Deciding where sensitive content lives is the step usually skipped.
Shared devices need their own answer
A tablet on a counter, signed in as somebody, gives whoever walks past that person's access to everything. A shared device needs a narrower login than a person does. Treating the two the same is a common and expensive mistake. Diract CRM gives a kiosk account its own narrow access rather than borrowing a staff member's.
A group needs a wider view, deliberately
Somebody running two associated companies needs to see both, and that is a decision rather than an accident. Our guide to running two venues covers giving that access without merging the two businesses. The two companies stay separate for everybody else, which is the point. A wide view granted by design is safe, and one granted by merging the data is not.
Removal on the last day, from a checklist
A departed staff member with access is the most common security problem a small business has, and the easiest to fix. A written checklist, followed the same way every time, removes the dependence on somebody remembering. The last day is the deadline, not the week somebody notices. One list, four lines long, covers it for most businesses.
Say why, not just what
A team told they cannot see something assumes distrust. A team told the reason usually agrees with it. One sentence explaining the restriction prevents most of the resentment that otherwise attaches to it. That sentence also tests the restriction. A reason nobody can state out loud is usually a restriction nobody needed.
What to change first
- Finding a contact and reading their detail are separate permissions
- Roles describe jobs rather than particular people
- A hidden field cannot block a save
- The search results follow the same rules as the record list
- Sensitive content gets located before fields get restricted
- A yearly review compares each role against its job
- Access removal happens on the last day, from a checklist
How to set it up
Subscribe to our newsletter
Keep updated with the latest changes.