Why this matters
The everyone-is-admin account fails loudly. Someone bulk-deletes 3,000 contacts while cleaning a filter, someone else exports the full customer base the week before they resign, and a third person adds nine custom fields on a Tuesday. All three have happened in accounts we took over. Admin rights are not a courtesy rank.
The locked-down account fails quietly, which is worse. Reps cannot see whether a company is already a customer, so they create duplicates and cold-call accounts their colleague is closing. Managers cannot see the pipeline they are asked to forecast. People route around the CRM with spreadsheets, and adoption dies politely. Pipedrive gives you two instruments to steer between these failures, and they do different jobs.
The design decisions that matter
Decision one: who may do what. Permission sets control actions. Deleting deals, bulk editing, exporting data, changing account settings. Keep two admins, put everyone else in a regular set, and take bulk delete and export away from roles that never need them. An export permission is a data leak permission, treat it that way.
Decision two: who may see what. Visibility groups control items. Every deal, contact and organization has an owner and a visibility level, from owner only up to entire company. The default sets the tone for the account.
Decision three: what the default should be. Open, unless you have a named reason. Real reasons include two business units selling into the same market, freelancers who should see only their own accounts, and confidentiality rules in regulated industries. Tidiness is not a reason. A smaller field of vision does not make reps more focused, it makes them blind.
Decision four: what management needs. Whoever runs the Insights dashboards and the forecast needs visibility across every group, without necessarily holding admin rights. Seeing everything and changing everything are different privileges. Split them.
A worked example
A 22-person company: fifteen reps in two country teams, two team leads, marketing, finance and two external freelance appointment setters.
| Role | Permission set | Visibility |
|---|---|---|
| 2 admins | Admin | Entire company |
| 15 reps | Regular, no delete, no export | Entire company |
| 2 team leads | Regular plus export | Entire company |
| Finance | Regular, read-focused | Entire company |
| 2 freelancers | Regular, no delete, no export | Own items only |
Only the freelancers are restricted, because they are outside the company and work cold lists. Everyone internal sees everything, so duplicate checks work and handovers are readable. The two country teams stay unrestricted on purpose. They share accounts more often than anyone predicted, and a visibility wall would have turned every shared account into a support ticket.
Common mistakes
Admin inflation is first. It starts with making the office manager admin to edit one dropdown, and ends with seven admins, none of whom knows who changed the pipeline last Tuesday. Hand out temporary help instead of permanent rank.
Second, no offboarding path. A departed rep's records keep their dead owner, automations assign follow-ups to a mailbox nobody reads, and deals rot invisibly. Deactivate, transfer, verify, within the week. Put it in the same checklist as revoking email and laptop access, next to the mailbox disconnection.
Third, group design that mirrors the org chart instead of data sensitivity. Groups exist to answer who may see this record, not to redraw departments. Fewer groups, clearer rules, and the classic mistakes stay away.
Maintenance
Quarterly, run an access review. Read the user list aloud with the sales lead: does each person still work here, still need their permission set, still belong to their group? Ten minutes, and it catches the freelancer whose contract ended in March.
After every departure, verify the transfer actually happened by filtering deals on the deactivated owner. Zero results is the passing grade. And whenever a new restriction is proposed, ask for the incident it prevents. No incident, no wall. Accounts maintained this way stay open, safe and boring, which is exactly what access control should be.
Questions
What is the difference between permission sets and visibility groups?
Permission sets control what a user may do, like deleting deals, exporting data or changing settings. Visibility groups control what a user may see, item by item. You need both, and they are configured separately.
How many admins should a Pipedrive account have?
Two. One primary owner of the configuration and one backup for holidays and emergencies. Every additional admin is another person who can change settings, delete in bulk and add fields on a whim.
What should the default visibility for deals and contacts be?
For most teams under thirty people, visible to the entire company. Restrict by group only when there is a concrete reason, like competing units, external freelancers or regulated client data.
Can a rep see that a colleague already works with a company?
Only if visibility allows it. This is the strongest argument against over-restriction: a rep who cannot see the existing organization will create a duplicate and may call a customer who is mid-negotiation with a colleague.
What happens to records when someone leaves the company?
Nothing automatic. Deactivate the user, then bulk-transfer their deals, contacts and activities to a successor. Do the transfer the same week, because ownerless follow-ups are how open deals silently die.