Operations and governance
After go-live: how to keep the account healthy with auditing, configuration change governance, global governance, RBAC and data retention.
Once the team is live, the administrator role shifts from configuring to governing: making sure access stays correct, that configuration changes are traceable and that data follows the organization rules.
Audit trail
In Settings → Audit you see who did what and when: record creation, changes and deletions, plus sensitive changes. The trail is read-only (append-only): it serves as the source of truth in investigations and periodic reviews.
Configuration change governance
Changing the configuration of a CRM in production is risky. In Settings → Changes you follow the history of configuration changes and, when available, require approval before applying sensitive changes. Treat configuration as code: review, approve and record.
Global governance
In Settings → Global governance you define policies that apply to the whole account: naming standards, corporate required fields, limits and rules the teams cannot bypass. It is where the administrator enforces top-down consistency.
RBAC: periodic access review
Access rots over time: people change roles, leave, join. Review the roles (Settings, under Roles and permissions) and the users (Settings → Users) periodically. Deactivate whoever left (never delete, since the history must remain) and readjust the roles of whoever changed position.
- Quarterly, list active users and check the role of each one.
- Deactivate access for those who left; adjust those who changed role.
- Check field-level permissions on sensitive data (financial, personal).
Data retention
Define how long data is kept and what happens to old records. Combine retention policies with the privacy tools (Settings → Privacy) to meet legal requirements and reduce the risk of keeping unnecessary data.