Security for administrators
The security levers the administrator controls: two-step verification (2FA), corporate SSO/SCIM, field-level data masking and privacy.
The security of a CRM account is the administrator's responsibility. These are the levers you control, from how people authenticate to what each role can see in sensitive fields.
Two-step verification (2FA)
In Settings → Security you enable two-step verification (2FA via TOTP, with apps like Google Authenticator or Authy) and, if you want, make it mandatory. With 2FA required, a leaked password alone is not enough to get in. We recommend making 2FA mandatory for roles with broad access.
- Enable 2FA on the account and test it with your own user first.
- Define for which roles it is mandatory.
- Guide the team to store the recovery codes in a safe place.
SSO and SCIM provisioning
If the company uses an identity provider (Okta, Microsoft Entra/Azure AD, Google Workspace), connect it for single sign-on (SSO) and automatic user provisioning (SCIM), from Settings → Integrations. With SCIM, whoever joins or leaves the group in the IdP is created or deactivated here automatically, with no manual entry and no forgotten access.
Field-level data masking
Not everyone needs to see everything. In the role permissions (Settings, under Roles and permissions) you control access per field, including masking sensitive fields (documents, financial data, personal contacts) for roles with no legitimate need. The user sees that the field exists, but not its content.
Privacy and data protection
In Settings → Privacy are the tools to handle data subject requests (export, correct, delete) and apply data protection policies. These tools help comply with privacy rules across different countries and regions, and are not limited to a single piece of legislation. Combine them with the data retention described in "Operations and governance".