Before you begin
- Tenant admins manage access under Settings → Roles and Admin → Members
- Enterprise may add SSO — contact sales for custom security requirements
Role hygiene
- Default to Rep or custom least-privilege roles — not Admin
- Billing and integration changes should stay with a small admin group
- Review custom roles in /dashboard/settings/roles before rolling out
Authentication
- Require strong passwords; enable login notifications in notification settings
- Sign out shared devices after open-house or kiosk use
- Rotate API tokens when staff leave — see manage member lifecycle
Data access
- Record-level permissions restrict reps to owned leads when configured
- Email monitoring is admin-only — do not share admin credentials
- Audit sensitive changes in Admin → Logs → Audit
Quarterly review
Every quarter, export the member list, confirm roles match job functions, remove stale admins, and verify integrations still use the correct service accounts.
Security baseline
Enable login notifications for all admins before inviting the full team. It is the fastest way to catch unauthorized access.
Common issues
- Rep sees too much data — tighten custom role or enable own-records-only
- Locked out after role change — another admin can restore access from Admin → Members