Why this matters
The everyone-is-admin account fails loudly. Someone bulk-deletes 3,000 contacts while cleaning a filter, someone else exports the full customer base the week before they resign, and a third person adds nine custom fields on a Tuesday. All three have happened in accounts we took over. Admin rights are not a courtesy rank.
The locked-down account fails quietly, which is worse. Reps cannot see whether a company is already a customer, so they create duplicates and cold-call accounts their colleague is closing. Managers cannot see the pipeline they are asked to forecast. People route around the CRM with spreadsheets, and adoption dies politely. Pipedrive gives you two instruments to steer between these failures, and they do different jobs.
The design decisions that matter
Decision one: who may do what. Permission sets control actions. Deleting deals, bulk editing, exporting data, changing account settings. Keep two admins, put everyone else in a regular set, and take bulk delete and export away from roles that never need them. An export permission is a data leak permission, treat it that way.
Decision two: who may see what. Visibility groups control items. Every deal, contact and organization has an owner and a visibility level, from owner only up to entire company. The default sets the tone for the account.
Decision three: what the default should be. Open, unless you have a named reason. Real reasons include two business units selling into the same market, freelancers who should see only their own accounts, and confidentiality rules in regulated industries. Tidiness is not a reason. A smaller field of vision does not make reps more focused, it makes them blind.
Decision four: what management needs. Whoever runs the Insights dashboards and the forecast needs visibility across every group, without necessarily holding admin rights. Seeing everything and changing everything are different privileges. Split them.
A worked example
A 22-person company: fifteen reps in two country teams, two team leads, marketing, finance and two external freelance appointment setters.
| Role | Permission set | Visibility |
|---|---|---|
| 2 admins | Admin | Entire company |
| 15 reps | Regular, no delete, no export | Entire company |
| 2 team leads | Regular plus export | Entire company |
| Finance | Regular, read-focused | Entire company |
| 2 freelancers | Regular, no delete, no export | Own items only |
Only the freelancers are restricted, because they are outside the company and work cold lists. Everyone internal sees everything, so duplicate checks work and handovers are readable. The two country teams stay unrestricted on purpose. They share accounts more often than anyone predicted, and a visibility wall would have turned every shared account into a support ticket.
Common mistakes
Admin inflation is first. It starts with making the office manager admin to edit one dropdown, and ends with seven admins, none of whom knows who changed the pipeline last Tuesday. Hand out temporary help instead of permanent rank.
Second, no offboarding path. A departed rep's records keep their dead owner, automations assign follow-ups to a mailbox nobody reads, and deals rot invisibly. Deactivate, transfer, verify, within the week. Put it in the same checklist as revoking email and laptop access, next to the mailbox disconnection.
Third, group design that mirrors the org chart instead of data sensitivity. Groups exist to answer who may see this record, not to redraw departments. Fewer groups, clearer rules, and the classic mistakes stay away.
Maintenance
Quarterly, run an access review. Read the user list aloud with the sales lead: does each person still work here, still need their permission set, still belong to their group? Ten minutes, and it catches the freelancer whose contract ended in March.
After every departure, verify the transfer actually happened by filtering deals on the deactivated owner. Zero results is the passing grade. And whenever a new restriction is proposed, ask for the incident it prevents. No incident, no wall. Accounts maintained this way stay open, safe and boring, which is exactly what access control should be.