Pomio CRM has four roles, sales rep, sales manager, viewer and organisation admin, each with an own, team or organisation scope that is enforced on the server. Setting up access correctly once is easy. Keeping it correct a year later is the part most small teams skip.
Why access drifts
A sales rep gets team scope while covering for a manager on holiday, and nobody takes it back. A former intern still has a viewer login. A colleague who moved to finance keeps a sales role because nobody thought to change it. None of this is a breach on day one. Over a year it adds up to people seeing customer data they have no reason to see, and logins that nobody watches.
What to check, person by person
Go through the user list and ask four questions for each person. Do they still need a login at all? Is their role still the one that matches their work? Is their scope the narrowest that fits, own before team, team before organisation? Is multi-factor authentication switched on? If one answer is no, fix it during the review, not in a follow-up that never happens.
Look hardest at administrators
An organisation admin can invite and suspend users, change roles and reset passwords and multi-factor authentication. That is why a small team needs only one main administrator and one backup. In the quarterly review, check that the list of administrators is still exactly those people, and that nobody got admin rights “just for this one import” and kept them.
Suspended accounts and leavers
Leavers should be handled on the day itself, as described in suspending a CRM user on their last working day. The quarterly review is the safety net. Check that everyone who left is suspended, that no open deal, task or contact is still in their name, and that suspended accounts stay suspended rather than deleted, so history keeps a name.
Multi-factor authentication for everyone
A login without a second factor is the easiest way in. The review is a good moment to check that multi-factor authentication is on for every active user, starting with administrators and anyone with organisation scope. If someone lost their authenticator app, reset it properly instead of switching it off.
Keep the review small and regular
Put it in the calendar for the first week of every quarter and give it to one person, usually the main administrator, with the sales manager checking the sales roles. For a team of ten to thirty users it takes about half an hour. Write down what you changed and why in a short note, so the next review starts from facts instead of memory.
How Pomio CRM supports an access review
In Pomio CRM an organisation admin invites users by email, activates and suspends them, changes roles and resets passwords and multi-factor authentication without seeing the secret. Roles and their scope are enforced on the server, so a changed scope takes effect for every screen and export at once. Important actions are recorded in the audit log, without passwords or multi-factor secrets, so it stays clear who changed which access and when.
A practical checklist
Plan the review in the first week of each quarter; give it to one owner; for every user check whether the login is still needed, the role is right, the scope is the narrowest that fits and multi-factor authentication is on; check that only the agreed administrators have admin rights; take back temporary rights; confirm leavers are suspended and own no open work; note what changed and why.
Go deeper
Is once a quarter often enough?
For most small sales teams, yes, as long as leavers and role changes are also handled on the day they happen. The quarterly review catches what slipped through.
Who should do the review?
The main CRM administrator, with the sales manager confirming that sales roles and scopes match how the team works today.
Should temporary rights have an end date?
Agree one when you give them, and check in the review that they were taken back. Temporary rights without an end date tend to become permanent.
What if a user objects to a narrower scope?
Ask what they need to see for their work. If there is a real need, give the scope with a reason in the note. If not, the narrower scope stays.