Salesperson quit Friday. By Monday, 40 customers said he had already called from his new store.
The CRM export log showed 300 leads downloaded Thursday at 9 p.m. Our user audit found a larger problem. Forty former employees still had active accounts. Thirty salespeople had permission to export the full database.
We audited six dealership CRMs with 120 user accounts. Every store had former employees with active access. Five stores let salespeople export hundreds of records. Four stores had far too many administrators.
The five permission errors took 10 working hours to correct inside a 48-hour review window. The changes removed the access paths used in the incident and gave management a clean export trail.
The 48-Hour CRM Permission Audit
| # | CRM Permission Error, Six Stores and 120 Users | Stores Affected | Leads Exposed | Fix Time | Generic Fix Path | Security Result |
| 1 | Former employees still active, 40 of 120 users | 6 of 6 | Up to 15,000 records | 2 hours | Users, deactivate accounts, revoke sessions, remove SSO access | Removes former employee access |
| 2 | Sales role permits full lead exports | 5 of 6 | 500 rows per export across 30 users | 1 hour | Roles, Sales, disable bulk export, limit access to assigned leads | Removes most bulk-export access |
| 3 | Every department sees every customer record | 6 of 6 | Sales, service and finance records | 4 hours | Roles, departments, restrict records by job need | Reduces cross-department exposure |
| 4 | No remote-login restriction or managed-device rule | 6 of 6 | Full account access from any location | 2 hours | Security, approved IP or device, VPN, MFA | Blocks unapproved remote sessions |
| 5 | Twenty users hold administrator rights | 4 of 6 | Exports, permission changes and audit logs | 1 hour | Roles, Admin, retain two named administrators | Limits high-risk account power |
| Total | Five permission errors | Six-store audit | One 15,000-record database exposed through overlapping paths | 10 hours inside 48 hours | Recheck users, roles, sessions and exports | Closes most permission paths found in the audit |
CRM menu names differ by provider. The control matters more than the label. Your vendor should show where to deactivate accounts, revoke active sessions, limit exports, separate departments and review administrator activity.
The lead counts also overlap. Do not add 15,000 database records to another 15,000 possible export rows and call the total 30,000 unique leads. The audit involved one 15,000-record database exposed through several permission failures.
#1 Former Employees Still Active: 40 Accounts, Two-Hour Fix
Forty of 120 reviewed accounts belonged to former employees. The oldest departure had occurred six months earlier.
A former employee with a working username and password still looks like a valid user to the CRM. If the account holds broad permissions, the former employee retains access to customer names, phone numbers, email addresses, appointment notes and vehicle interests.
Deactivating the CRM account is only the first step. Complete the full offboarding sequence:
- Disable the CRM user.
- Revoke every active browser and mobile session.
- Remove access through the identity provider.
- Reset shared credentials used by the employee.
- Remove connected email, texting and lead-routing access.
- Review exports and unusual logins from the prior 30 days.
Shared accounts create another hole. “Sales1” or “BDC Desk” provides no reliable record of who logged in or downloaded data. Give each employee a named account. Remove shared credentials from daily use.
Run the active-user list against payroll every Friday. Any name missing from payroll should reach IT and the department manager the same day. Terminated employees need immediate removal. Planned departures need access removed at the time set by HR.
Action: Export the active-user list today. Match every account to one current employee, role, manager and rooftop.
#2 Salespeople With Full Export Rights: 300 Leads Left Thursday Night
Thirty of 70 sales users had bulk-export permission. Each user was able to download 500 records in one action.
The incident appeared in the export log at 9 p.m. Thursday. The employee downloaded 300 leads, resigned Friday and started contacting customers from another store.
A salesperson needs access to assigned prospects, sold customers and active follow-up tasks. Full-database export rights do not support normal daily selling.
Open the Sales role and remove these permissions:
- Export all customers
- Export unassigned leads
- Download department-wide reports containing customer details
- Run mass lists outside the assigned book of business
- Access leads owned by another rooftop
Allow exports only for approved managers with a documented business reason. Add a row limit where the CRM supports one. A 25-record exception for an approved campaign carries less exposure than a 15,000-record download.
Set alerts for unusual behavior. Flag exports outside store hours, repeated maximum-size downloads and exports within days of a resignation notice. Review the report daily during an employee’s final week.
Disabling exports does not stop screenshots, handwritten notes or photos of a screen. Permission control reduces bulk theft. Training, supervision and a documented customer-data policy still matter.
Action: Remove “Export All” from the sales role. Test the change using a standard salesperson account, not an administrator account.
#3 Every Department Sees Every Record: Four-Hour Department Lock
All six stores exposed customer records across departments.
Service advisors saw sales leads. Salespeople saw service histories. Some users reached finance notes even though their jobs had no need for finance access.
Broad visibility creates three problems. More employees see sensitive data. Internal customer ownership disputes grow. A compromised account reaches a larger portion of the dealership.
Build access around job duties.
Sales should see assigned leads, appointments and sold-customer follow-up.
BDC should see active leads, contact history and appointment status.
Service should see repair orders, service appointments and approved customer contact fields.
Finance should receive deal information required for funding and compliance work.
Accounting should access completed transactions and financial records tied to office duties.
Managers need department-level reporting. Few need unrestricted access across every rooftop and every customer record.
Test each role with a non-admin account. Log in as Sales, BDC, Service, Finance and Accounting. Search for records outside each department. Record every page or report still visible.
Action: Create a permission matrix with roles across the top and data types down the side. Mark access as view, edit, export or none.
#4 Login From Home or a Competing Store: Two-Hour Remote-Access Fix
Every audited CRM accepted logins from any network. Several lacked multifactor authentication. A valid password worked from the dealership, a home computer or a competitor’s showroom.
An approved-location rule narrows the exposure. Store networks, approved VPN connections and managed mobile devices should cover normal dealership work.
Start with these controls:
- Require multifactor authentication for every user.
- Restrict administrator access to approved networks or managed devices.
- Route approved remote work through the dealership VPN.
- Block logins from unfamiliar devices until verification.
- Alert IT when a user signs in from a new location.
A strict store-only IP rule does not fit every operation. Remote BDC employees, group managers and approved vendors need controlled access. Use named exceptions with an owner, purpose and expiration date.
IP restrictions do not provide complete protection. Stolen sessions, approved devices and compromised VPN credentials still present risk. Pair location controls with multifactor authentication, session expiration and device review.
Action: Pull the last 30 days of login history. Investigate unfamiliar locations, late-night access and repeated failed logins.
#5 Twenty Administrators Instead of Two: One-Hour Rights Review
Four stores had 20 administrator accounts. Department managers, former vendors and employees with temporary setup duties still held full rights.
Administrator access permits role changes, full exports, integrations and account creation. Some systems also give administrators control over retention settings or audit visibility.
Keep two named primary administrators when store size permits. Assign a documented backup with restricted or time-limited rights. Department managers should receive manager permissions, not full system control.
Review these accounts closely:
- Website and CRM vendors
- Former implementation consultants
- Marketing agencies
- Managers transferred to another rooftop
- Employees who received temporary access for a project
Remove unused integration accounts only after confirming system dependencies. Disabling the wrong service account might stop lead delivery, texting or DMS synchronization. Document each integration owner before changing access.
Each administrator should use an individual account with multifactor authentication. Never share one owner-level login across the office.
Action: Reduce the administrator list to named users with a current business need. Record who approved each remaining account.
Permission Math: One Database, Five Exposure Paths, 10 Hours of Work
The store had 15,000 customer records.
Forty former employees retained account access. Thirty sales users held bulk-export rights. Department permissions exposed records outside normal job duties. Remote access lacked strong restrictions. Twenty users held administrator authority.
Those figures describe overlapping exposure to the same database. The accurate risk count is up to 15,000 unique records, not 20,000 or 30,000.
The remediation work took 10 hours:
Former-user shutdown: 2 hours
Sales export restriction: 1 hour
Department role separation: 4 hours
Remote-access controls: 2 hours
Administrator review: 1 hour
Spread the work across 48 hours:
Day one morning: Match active users to payroll and deactivate former employees.
Day one afternoon: Remove bulk exports and reduce administrator rights.
Day two morning: Separate sales, BDC, service, finance and accounting permissions.
Day two afternoon: Apply multifactor authentication, approved-device rules and login alerts.
Finish with three reports: active users, bulk exports and remote logins. Save the reports with the date, reviewer and changes made.
No permission plan proves a fixed 90% reduction in lead theft. The six-store audit showed five recurring access paths. Closing those paths removed most of the observed opportunities for bulk theft and unauthorized access.
Your 48-hour audit board needs five lines: user status, export rights, department access, remote login and administrator rights. Assign one owner to each line and retest every permission from a standard user account.
Sponsored by Gas.net — powering dealership growth through intelligent data.
Alt text: “Gas.net connects franchise dealers with integrated analytics and marketing tools.”