Designing CRM visibility for a global commercial organization
A fictional case about access as architecture: ownership, record visibility, hierarchy, shared commercial responsibility, global accounts and sensitive data.
Independently created. Contains no employer or client implementation detail, internal names or figures.
01The outcome
An access model in which ownership means accountability, visibility follows explicit relationships, edit rights are narrower than view rights, and sensitive data has its own boundary.
Access rules grew one request at a time; nobody can explain who sees what, or why.
Does ownership mean accountability or visibility—and how is access granted without making everything public?
Separate accountability (one owner), visibility (derived from organization and account-team relationships) and edit authority (narrower and role-based)—and drive all three from governed organizational data.
A global commercial organization works across subsidiaries, regions, sales teams, key-account teams and specialists. Access rules grew one request at a time: sharing exceptions, copied profiles and manual grants. Some users see everything; others cannot see accounts they work on every day.
02The reality · current state
What the platform looks like today.
- Ownership is used to grant visibility, so accounts are reassigned just to be seen
- Global account teams cannot see local opportunities on their own accounts
- Manual sharing exceptions pile up and nobody reviews them
- Sensitive terms are visible to anyone who can see the account
- Access changes lag behind organization changes
- Reports show different totals to different people, with no explanation
03System responsibilities
Every platform, one job—and a boundary.
What each platform owns in this design, and what it deliberately does not. These are the responsibilities for this context, not universal rules.
CRM
Enforces record access- Record ownership (accountability)
- Account teams and shared responsibility
- Visibility rules from hierarchy and teams
- Field-level protection of sensitive data
- Who belongs to which organization unit
- Authentication
HR & org data
The organization as it is- Organization units and reporting lines
- Role assignments and effective dates
- Account ownership decisions
Identity provider
Who the user is- Authentication and single sign-on
- Joiner, mover and leaver events
- Record-level access
Data platform
Reporting access that matches the CRM- Row-level security aligned with CRM visibility
- Access-review analytics
- Operational access decisions
04Key dimension · Ownership, visibility & edit authority
Who sees and edits what
Visibility is broader than edit authority, and both are separate from ownership. The matrix is the model—not a list of exceptions.
| Role | Owned accounts | Account-team accounts | Region | Global accounts | Sensitive terms |
|---|---|---|---|---|---|
| Account manager | Edit | Edit | Summary | No access | View |
| Specialist | No access | View | No access | No access | No access |
| Sales manager | Edit | Edit | View | Summary | View |
| Global account lead | Edit | Edit | Summary | Edit | View |
| Finance | No access | No access | View | View | Edit |
- Ownership is accountability, not visibility.
- View is broader than edit—by design.
- Hierarchy grants visibility, never ownership.
- Sensitive data has its own boundary.
- Manual sharing expires.
“Everyone sees everything” and “everything is private” both avoid the design question. The matrix answers it.
06Candidate architectures
Credible options, judged against these premises.
Everyone can see everything
Small, single-entity organizations
Cost: Sensitive terms exposed; ownership loses meaningPrivate by default, manual sharing
Highly confidential sales
Cost: Sharing exceptions pile up; collaboration breaksPrivate by default; visibility from hierarchy and account teams; field-level protection
A global organization with shared accounts
Cost: Needs governed org data and periodic access reviews07The second layer
Questions that change the architecture.
Ownership
- Does ownership mean accountability or visibility?
- Can one record have several commercial stakeholders?
- What happens to access when ownership changes?
Visibility
- How does a manager inherit visibility?
- How is global access separated from edit permission?
- Which reports must show the same totals to everyone?
Boundaries
- What should remain private?
- Which fields are sensitive, and for whom?
- Who reviews manual sharing—and when does it expire?
08Decisions & outputs
What the work produces.
- 01Ownership model
- 02Visibility matrix
- 03Sharing strategy
- 04Hierarchy model
- 05Permission boundaries
- 06Access review cadence