Your CRM can contain customer, sales, support, finance, project, and internal business data, so account security matters.
Recommended controls
- Use strong, unique passwords.
- Give staff only the permissions they need.
- Remove staff access quickly when someone leaves.
- Do not share admin accounts.
- Review users and roles regularly.
- Keep customer portal access separate from staff access.
Data handling
- Avoid storing unnecessary sensitive data.
- Do not send passwords or full card details through tickets.
- Only upload files that belong in the customer or project record.
- Check contact permissions before exposing files or project records through the portal.
MFA status
- Admin MFA is available as an installed module, but it is currently left disabled until the business decides to enforce it.
Good to know: Security is usually strongest when permissions are reviewed regularly, not only during setup.