Dataabout 20 min

    How do I control who sees what data?

    Short answer

    Base access on role, not tenure, so someone only sees the records, pipelines, and financial details their job actually requires. Start narrow and grant more access as it is needed, since it is far easier to expand permissions later than to walk back an oversharing mistake.

    Before you start

    • A list of roles on your team and what each one actually needs to see.
    • Access to the permission or role settings for user accounts.
    • Agreement on which data is considered sensitive, like financials or personal details.
    • A process for reviewing access when someone changes roles or leaves.

    Step by step

    1. 1

      Map roles to actual data needs

      List each role on the team and what records, pipelines, or reports they truly need.

      Access decisions based on real job needs are far easier to defend and maintain.

    2. 2

      Start every new user narrow

      Grant the minimum access needed for their role on day one.

      It is simple to add access later but much harder to notice and remove excess access.

    3. 3

      Separate financial visibility from general access

      Restrict payment details and revenue reports to roles that specifically need them.

      Financial data is usually the most sensitive information in the system and deserves its own limits.

    4. 4

      Use team or location based restrictions where relevant

      Limit visibility to a specific territory, crew, or location if your business has multiple.

      This keeps staff focused on their own customers and reduces exposure across the wider list.

    5. 5

      Restrict who can export or bulk edit

      Give export and bulk change permissions to a small, trusted group only.

      Broad export access turns any account compromise into a full data breach.

    6. 6

      Review access when roles change

      Update permissions the same day someone changes position, not weeks later.

      Stale access from an old role is one of the most common sources of unnecessary exposure.

    7. 7

      Audit the full permission list quarterly

      Check every user's access level against what their current role actually needs.

      A quarterly audit catches drift before it becomes a real problem.

    What good looks like

    • Each team member sees only the data their role genuinely requires.
    • Financial and personal details stay limited to a trusted group.
    • Access changes happen the same day a role changes, not months later.
    • Regular audits catch unnecessary access before it causes a problem.

    Common mistakes

    The ways this goes wrong in data, and what to do instead.

    Giving everyone full access by default

    New hires see financial and sensitive data they never needed for their role.

    Do this instead: Start every new account with narrow access and expand only when a real need appears.

    Forgetting to update access after a role change

    A former manager keeps seeing reports and records well after moving to a different position.

    Do this instead: Update permissions the same day a role or employment status changes.

    Never auditing existing access

    Permissions granted years ago for a one-time project remain active indefinitely.

    Do this instead: Run a quarterly review comparing every user's access against their current role.

    Frequently asked

    6 questions about control who sees what data

    No, restrict payment and revenue details to roles that specifically require them.

    Pick the next thing to set up, or back up a step if something here assumed work you have not done yet.

    People usually get here from

    Guides that lead into this one, in case you skipped a step.

    Was this guide helpful?

    Tell us what worked and what didn't. It shapes what we rewrite next.

    You didn't get into business to be in the tech business.

    Managed Tech clients hand this to us. We build it, test it, maintain it, and add to it as the business changes, so nobody on your team has to become the person who knows how the system works.

    Schedule a fit callCallCalls are answered by Troy, our AI assistant. Troy answers questions about the system and services and can schedule, reschedule, or cancel appointments. He never sells or makes offers. Any communication with TactStack is stored in our systems and referenced by Troy during certain interactions. AI can make mistakes.Full documentation