Rebuilding User Roles and Permissions After CRM Migration
You moved the data. Then half the sales team could not open their deals, while three managers could export every contact. Permission models never transfer one-to-one, and a rushed role mapping leaves either over-permissioned users or locked-out teams.
We redesign and test access control before go-live so your new CRM is neither a data breach waiting to happen nor a sales blackout.

Sound Familiar?
These are the exact access control failures our clients faced after a CRM switch:
- Sales reps cannot edit their own deals on Monday morning because field-level security was copied wrong
- Managers suddenly see every account, including competitor pricing and confidential notes they never needed
- Admin-equivalent access landed on nearly a third of seats after a one-to-one role copy
- Sharing rules from the old CRM were pasted across, so export and mass-update rights followed everyone
- IT spends the first fortnight firefighting lockouts and over-access instead of finishing the migration
South Africa's Information Regulator has confirmed that unauthorised internal access is a POPIA security compromise, with no materiality threshold. Wrong CRM sharing rules that expose personal information to staff who should not see it trigger the same notification duties as an external breach, and fines can reach R10 million.
What Permission Migration Actually Looks Like
Audit old access → design the role matrix → test in sandbox → harden at go-live. No guessing on Monday morning.
Audit Old Access
Profiles, permission sets, sharing rules, and privileged users inventoried and ranked by risk
Design Role Matrix
Personas mapped to least-privilege rights: object, field, report, and export access by job
Test Access Controls
Named users prove they can do their job and cannot reach records or exports they must not
Cutover Hardened
Validated matrix live, migration privileges revoked, week-one access tickets near zero
Everything You Need for Role Mapping and Access Control
Role and Persona Mapping
We inventory every old profile, permission set, and sharing rule, then redesign access around job functions, not legacy role names that never mapped one-to-one.
Least-Privilege Rebuild
Base profiles stay minimal. Object, field, and system rights move into permission sets and groups so sales can sell without Modify All Data or unrestricted export.
Sandbox Access Testing
Named personas run real workflows before cutover: create deals, edit contacts, run reports, and fail the actions they must not reach.
Sharing Rule Redesign
Record visibility is rebuilt from territory, ownership, and team rules, not copied from the old org. Wrong sharing is a POPIA security compromise, not a minor config quirk.
Privileged Access Hardening
Integration users, migration accounts, and temporary admin rights are scoped, time-boxed, and revoked after go-live so orphaned credentials do not linger.
Go-Live Access Pack
Role matrix, exception list, rollback steps, and a week-one support rota so lockouts and over-permissions get fixed in hours, not days.
CRM Platforms We've Remapped Access For
From 31% Admin Access to Under 4% Before Go-Live
How an 85-seat industrial supplier rebuilt CRM roles and permissions so cutover landed with zero sales lockouts and no over-exposed client data.
The One-to-One Role Copy
- IT mapped old Salesforce profiles into HubSpot seats by name, not by job function
- 26 of 85 users (31%) landed with admin-equivalent export and mass-edit rights
- Sharing rules copied wholesale, so three managers saw competitor pricing on every account
- Field-level security blocked reps from editing their own opportunities for three days after a dry-run attempt
- Week-one support queue projected at 40-plus access tickets
The Validated Access Matrix
- Six personas redesigned with least privilege: rep, manager, finance, support, marketing, integration
- Admin-equivalent seats cut to three named owners (under 4% of the org)
- Sandbox access tests covered create, edit, report, and deliberate deny cases for every persona
- Go-live: zero sales lockouts, zero unauthorised export paths left open
- Migration service accounts revoked within 48 hours of cutover
Before vs After Access Control Rebuild
How It Works
From first audit to hardened go-live in 2–4 weeks alongside your migration calendar.
Permission Audit
Export every profile, permission set, sharing rule, and privileged user. Flag admin sprawl and rights that must not travel.
Role Matrix Design
30-minute call to lock personas, least-privilege targets, and what success looks like before go-live.
Build and Test Access
Rebuild roles and permission sets in sandbox, then test with named users against real workflows and negative cases.
Cutover and Harden
Apply the validated matrix at go-live, revoke migration privileges, and monitor week-one access tickets until quiet.
Frequently Asked Questions
Why can't we copy old CRM roles straight into the new system?
Permission models never transfer one-to-one. Salesforce profiles, HubSpot seats, Pipedrive visibility groups, and Dynamics security roles use different building blocks. A mid-market Salesforce org typically needs 40 to 80 hours just to audit, map, and migrate profiles into a clean permission-set model (Simplementix). Copying roles by name produces over-permissioned users, locked-out sales teams, or both.
How bad is admin sprawl after a CRM migration?
Across roughly 1,000 Salesforce permission audits, Clientell found a median mid-market org with 26% of users on System Administrator, against a healthy benchmark under 5%. Migrations that grant temporary "god mode" to speed cutover often leave that privilege in place. That is how customer PII, pricing, and export rights end up far wider than intended.
What does a CRM access failure cost under POPIA?
IBM's Cost of a Data Breach Report 2025 puts the global average breach at about $4.44 million (roughly R73 million at R16.55). Malicious insider vectors averaged about $4.92 million (around R81 million). Under POPIA, unauthorised access by an employee is still a security compromise with no materiality threshold, and administrative fines can reach R10 million (section 109). Wrong sharing rules are a compliance event, not an IT inconvenience.
How long does a permissions rebuild take before go-live?
Discovery and mapping alone often run 15 to 25 hours. Implementation another 15 to 30. Testing and validation add 10 to 25 more. Mid-size orgs land around 40 to 80 hours total; larger orgs with 50-plus profiles and complex sharing can exceed 100 hours (Simplementix). We schedule that work before cutover so launch week is not when you discover who can export the client list.
Will tightening access lock out the sales team?
Only if you skip persona testing. We build the matrix around what each role must do every day, then prove it in sandbox with create, edit, report, and deliberately failed actions. Least privilege is designed so reps can sell and managers can forecast, without handing Modify All Data to half the company.
How much does a CRM permissions rebuild cost with WebFootprint?
Focused role mapping and access testing for a mid-market CRM migration typically lands between R35,000 and R90,000 depending on seat count, number of personas, and sharing complexity. Against weeks of post-go-live firefighting, a single POPIA incident, or a global breach average near R73 million, most clients see payback as soon as cutover lands without lockouts or over-access.
Do Not Discover Permissions on Go-Live Monday
If your CRM migration treats roles as a last-minute checklist, you are choosing between locked-out sales teams and over-permissioned users who can export the client list.
Tell us which CRM you are leaving, which you are moving to, and how many seats and personas you have. We will show you exactly how role mapping and access control testing would land before cutover.