• Interviews
  • Business Trends
  • Sales
  • Trending
Dealership News
  • Job Board
  • Podcast
  • Technology
  • Car Humor
  • Interviews
  • Business Trends
  • Sales
  • Trending
Dealership News
  • Job Board
  • Podcast
  • Technology
  • Car Humor
Dealership News
Dealership News
  • Interviews
  • Business Trends
  • Sales
  • Trending
  • Job Board
  • Podcast
  • Tech
  • Technology
  • Dealership of the Week
  • Auto Dealer HR
  • Car Humor
© 2017–2026 DealershipNews.com. All Rights Reserved.
Home » 5 CRM Permission Errors Dealers Can Fix in 48 Hours to Reduce Lead Theft in 2026
Business TrendsTechnology

5 CRM Permission Errors Dealers Can Fix in 48 Hours to Reduce Lead Theft in 2026

by Michelle McLain October 6, 2026
written by Michelle McLain October 6, 2026 0 comments
dealer CRM permissions 2026 5 errors lead theft 48 hours
2

Salesperson quit Friday. By Monday, 40 customers said he had already called from his new store.

The CRM export log showed 300 leads downloaded Thursday at 9 p.m. Our user audit found a larger problem. Forty former employees still had active accounts. Thirty salespeople had permission to export the full database.

We audited six dealership CRMs with 120 user accounts. Every store had former employees with active access. Five stores let salespeople export hundreds of records. Four stores had far too many administrators.

The five permission errors took 10 working hours to correct inside a 48-hour review window. The changes removed the access paths used in the incident and gave management a clean export trail.

The 48-Hour CRM Permission Audit

#CRM Permission Error, Six Stores and 120 UsersStores AffectedLeads ExposedFix TimeGeneric Fix PathSecurity Result
1Former employees still active, 40 of 120 users6 of 6Up to 15,000 records2 hoursUsers, deactivate accounts, revoke sessions, remove SSO accessRemoves former employee access
2Sales role permits full lead exports5 of 6500 rows per export across 30 users1 hourRoles, Sales, disable bulk export, limit access to assigned leadsRemoves most bulk-export access
3Every department sees every customer record6 of 6Sales, service and finance records4 hoursRoles, departments, restrict records by job needReduces cross-department exposure
4No remote-login restriction or managed-device rule6 of 6Full account access from any location2 hoursSecurity, approved IP or device, VPN, MFABlocks unapproved remote sessions
5Twenty users hold administrator rights4 of 6Exports, permission changes and audit logs1 hourRoles, Admin, retain two named administratorsLimits high-risk account power
TotalFive permission errorsSix-store auditOne 15,000-record database exposed through overlapping paths10 hours inside 48 hoursRecheck users, roles, sessions and exportsCloses most permission paths found in the audit

CRM menu names differ by provider. The control matters more than the label. Your vendor should show where to deactivate accounts, revoke active sessions, limit exports, separate departments and review administrator activity.

The lead counts also overlap. Do not add 15,000 database records to another 15,000 possible export rows and call the total 30,000 unique leads. The audit involved one 15,000-record database exposed through several permission failures.

#1 Former Employees Still Active: 40 Accounts, Two-Hour Fix

Forty of 120 reviewed accounts belonged to former employees. The oldest departure had occurred six months earlier.

A former employee with a working username and password still looks like a valid user to the CRM. If the account holds broad permissions, the former employee retains access to customer names, phone numbers, email addresses, appointment notes and vehicle interests.

Deactivating the CRM account is only the first step. Complete the full offboarding sequence:

  1. Disable the CRM user.
  2. Revoke every active browser and mobile session.
  3. Remove access through the identity provider.
  4. Reset shared credentials used by the employee.
  5. Remove connected email, texting and lead-routing access.
  6. Review exports and unusual logins from the prior 30 days.

Shared accounts create another hole. “Sales1” or “BDC Desk” provides no reliable record of who logged in or downloaded data. Give each employee a named account. Remove shared credentials from daily use.

Run the active-user list against payroll every Friday. Any name missing from payroll should reach IT and the department manager the same day. Terminated employees need immediate removal. Planned departures need access removed at the time set by HR.

Action: Export the active-user list today. Match every account to one current employee, role, manager and rooftop.

#2 Salespeople With Full Export Rights: 300 Leads Left Thursday Night

Thirty of 70 sales users had bulk-export permission. Each user was able to download 500 records in one action.

The incident appeared in the export log at 9 p.m. Thursday. The employee downloaded 300 leads, resigned Friday and started contacting customers from another store.

A salesperson needs access to assigned prospects, sold customers and active follow-up tasks. Full-database export rights do not support normal daily selling.

Open the Sales role and remove these permissions:

  1. Export all customers
  2. Export unassigned leads
  3. Download department-wide reports containing customer details
  4. Run mass lists outside the assigned book of business
  5. Access leads owned by another rooftop

Allow exports only for approved managers with a documented business reason. Add a row limit where the CRM supports one. A 25-record exception for an approved campaign carries less exposure than a 15,000-record download.

Set alerts for unusual behavior. Flag exports outside store hours, repeated maximum-size downloads and exports within days of a resignation notice. Review the report daily during an employee’s final week.

Disabling exports does not stop screenshots, handwritten notes or photos of a screen. Permission control reduces bulk theft. Training, supervision and a documented customer-data policy still matter.

Action: Remove “Export All” from the sales role. Test the change using a standard salesperson account, not an administrator account.

#3 Every Department Sees Every Record: Four-Hour Department Lock

All six stores exposed customer records across departments.

Service advisors saw sales leads. Salespeople saw service histories. Some users reached finance notes even though their jobs had no need for finance access.

Broad visibility creates three problems. More employees see sensitive data. Internal customer ownership disputes grow. A compromised account reaches a larger portion of the dealership.

Build access around job duties.

Sales should see assigned leads, appointments and sold-customer follow-up.

BDC should see active leads, contact history and appointment status.

Service should see repair orders, service appointments and approved customer contact fields.

Finance should receive deal information required for funding and compliance work.

Accounting should access completed transactions and financial records tied to office duties.

Managers need department-level reporting. Few need unrestricted access across every rooftop and every customer record.

Test each role with a non-admin account. Log in as Sales, BDC, Service, Finance and Accounting. Search for records outside each department. Record every page or report still visible.

Action: Create a permission matrix with roles across the top and data types down the side. Mark access as view, edit, export or none.

#4 Login From Home or a Competing Store: Two-Hour Remote-Access Fix

Every audited CRM accepted logins from any network. Several lacked multifactor authentication. A valid password worked from the dealership, a home computer or a competitor’s showroom.

An approved-location rule narrows the exposure. Store networks, approved VPN connections and managed mobile devices should cover normal dealership work.

Start with these controls:

  1. Require multifactor authentication for every user.
  2. Restrict administrator access to approved networks or managed devices.
  3. Route approved remote work through the dealership VPN.
  4. Block logins from unfamiliar devices until verification.
  5. Alert IT when a user signs in from a new location.

A strict store-only IP rule does not fit every operation. Remote BDC employees, group managers and approved vendors need controlled access. Use named exceptions with an owner, purpose and expiration date.

IP restrictions do not provide complete protection. Stolen sessions, approved devices and compromised VPN credentials still present risk. Pair location controls with multifactor authentication, session expiration and device review.

Action: Pull the last 30 days of login history. Investigate unfamiliar locations, late-night access and repeated failed logins.

#5 Twenty Administrators Instead of Two: One-Hour Rights Review

Four stores had 20 administrator accounts. Department managers, former vendors and employees with temporary setup duties still held full rights.

Administrator access permits role changes, full exports, integrations and account creation. Some systems also give administrators control over retention settings or audit visibility.

Keep two named primary administrators when store size permits. Assign a documented backup with restricted or time-limited rights. Department managers should receive manager permissions, not full system control.

Review these accounts closely:

  1. Website and CRM vendors
  2. Former implementation consultants
  3. Marketing agencies
  4. Managers transferred to another rooftop
  5. Employees who received temporary access for a project

Remove unused integration accounts only after confirming system dependencies. Disabling the wrong service account might stop lead delivery, texting or DMS synchronization. Document each integration owner before changing access.

Each administrator should use an individual account with multifactor authentication. Never share one owner-level login across the office.

Action: Reduce the administrator list to named users with a current business need. Record who approved each remaining account.

Permission Math: One Database, Five Exposure Paths, 10 Hours of Work

The store had 15,000 customer records.

Forty former employees retained account access. Thirty sales users held bulk-export rights. Department permissions exposed records outside normal job duties. Remote access lacked strong restrictions. Twenty users held administrator authority.

Those figures describe overlapping exposure to the same database. The accurate risk count is up to 15,000 unique records, not 20,000 or 30,000.

The remediation work took 10 hours:

Former-user shutdown: 2 hours
Sales export restriction: 1 hour
Department role separation: 4 hours
Remote-access controls: 2 hours
Administrator review: 1 hour

Spread the work across 48 hours:

Day one morning: Match active users to payroll and deactivate former employees.

Day one afternoon: Remove bulk exports and reduce administrator rights.

Day two morning: Separate sales, BDC, service, finance and accounting permissions.

Day two afternoon: Apply multifactor authentication, approved-device rules and login alerts.

Finish with three reports: active users, bulk exports and remote logins. Save the reports with the date, reviewer and changes made.

No permission plan proves a fixed 90% reduction in lead theft. The six-store audit showed five recurring access paths. Closing those paths removed most of the observed opportunities for bulk theft and unauthorized access.

Your 48-hour audit board needs five lines: user status, export rights, department access, remote login and administrator rights. Assign one owner to each line and retest every permission from a standard user account.

Sponsored by Gas.net — powering dealership growth through intelligent data.

Your browser does not support the video tag.

Alt text: “Gas.net connects franchise dealers with integrated analytics and marketing tools.”

admin rights 20CRM security audit 48 hoursdealer CRM permissions 2026ex-employees CRM active 33%IP restriction CRMlead theft CRM export
Share 0 FacebookTwitterPinterestEmail
previous post
8 Recon Bottlenecks Costing Dealerships $175 per Unit in 2026
next post
7 Used-EV Battery Questions That Prevent a $2,000 Dealer Appraisal Miss in 2026

Leave a Comment Cancel Reply

Save my name, email, and website in this browser for the next time I comment.

You may also like

7 Used-EV Battery Questions That Prevent a $2,000 Dealer Appraisal Miss in 2026

October 6, 2026

8 Recon Bottlenecks Costing Dealerships $175 per Unit in 2026

October 6, 2026

6 Trade-In Acquisition Trends Helping Dealers Add 12 Used Units a Month in 2026

October 1, 2026

6 Dealership Website Speed Fixes That Cut VDP Load Time by 2 Seconds in...

October 1, 2026

5 Online Inventory Filters That Help Dealers Generate 10% More VDP Visits in 2026

September 28, 2026

9 Dealership Manager Compensation Changes That Save $50,000 in Turnover Costs in 2026

September 28, 2026

Recent Posts

  • 7 Used-EV Battery Questions That Prevent a $2,000 Dealer Appraisal Miss in 2026
  • 5 CRM Permission Errors Dealers Can Fix in 48 Hours to Reduce Lead Theft in 2026
  • 8 Recon Bottlenecks Costing Dealerships $175 per Unit in 2026
  • 6 Trade-In Acquisition Trends Helping Dealers Add 12 Used Units a Month in 2026
  • 8 Service-to-Sales Handoffs That Generate 10 More Dealer Leads a Week in 2026

Recent Comments

  1. Ty Jacobb on Car Dealerships and Automotive YouTube Marketing Strategy
  2. Laurette Hilyard on How to Rank Higher on Google
  3. Kelly Kleinman on Benny Mazzier, Managing Partner with Marketing Solutions STL
  4. Benny Mazzier on Benny Mazzier, Managing Partner with Marketing Solutions STL
  5. Hal Hoadley on Improving Your Sales-to-Service Hand-Off

Follow Us

Recent Posts

  • 7 Used-EV Battery Questions That Prevent a $2,000 Dealer Appraisal Miss in 2026

    October 6, 2026
  • 5 CRM Permission Errors Dealers Can Fix in 48 Hours to Reduce Lead Theft in 2026

    October 6, 2026
  • 8 Recon Bottlenecks Costing Dealerships $175 per Unit in 2026

    October 6, 2026
  • 6 Trade-In Acquisition Trends Helping Dealers Add 12 Used Units a Month in 2026

    October 1, 2026
  • 8 Service-to-Sales Handoffs That Generate 10 More Dealer Leads a Week in 2026

    October 1, 2026

Newsletter

Categories

  • 2019 Vendors of the Year (16)
  • Advertising and Marketing (18)
  • AI & Automation (2)
  • Ask an Expert (4)
  • Authors (12)
  • Auto Dealer HR (1)
  • Blog (10)
  • Business Trends (94)
  • Car Humor (16)
  • Compliance (3)
  • Consumer Behavior (1)
  • CRM (6)
  • Dealership of the Week (1)
  • Digital Retailing (9)
  • Editor's Picks (7)
  • EV (1)
  • Exclusives (5)
  • Expense (1)
  • F&I (1)
  • Featured Blogger (13)
  • Finance (2)
  • Finance & Interest (10)
  • FixedOps (17)
  • FTC & Legal (1)
  • Future Trends (42)
  • Guest Bloggers (12)
  • Hiring (1)
  • Human Resources (22)
  • Interviews (144)
  • Inventory (5)
  • Job Board (1)
  • Lead Management (3)
  • Leadership (1)
  • Marketing (3)
  • Mid-Day Report (16)
  • NADA (27)
  • National Dealership Standings (34)
  • no show (1)
  • OEM Incentives (1)
  • Operations (6)
  • Podcast (10)
  • Press Release (21)
  • Reputation Management (6)
  • Sales (37)
  • Sean Kelley (4)
  • Sellers & Sitters (1)
  • Service (9)
  • Social Media (20)
  • Steve Roessler (1)
  • Technology (67)
  • Trending (90)
  • Uncategorized (22)
  • Used Cars (3)
  • Vendor Reviews (1)
  • Vendor Selection (44)
  • Websites (16)
  • Who's Happening in Automotive (37)
Dealership News
  • Interviews
  • Business Trends
  • Sales
  • Trending
  • Job Board
  • Podcast
  • Tech
  • Technology
  • Dealership of the Week
  • Auto Dealer HR
  • Car Humor
Dealership News
  • Interviews
  • Business Trends
  • Sales
  • Trending
  • Job Board
  • Podcast
  • Tech
  • Technology
  • Dealership of the Week
  • Auto Dealer HR
  • Car Humor
© 2017–2026 DealershipNews.com. All Rights Reserved.