Systems case / 06 · Ownership, visibility & edit authority

Designing CRM visibility for a global commercial organization

A fictional case about access as architecture: ownership, record visibility, hierarchy, shared commercial responsibility, global accounts and sensitive data.

Fictional scenario

Independently created. Contains no employer or client implementation detail, internal names or figures.

01The outcome

An access model in which ownership means accountability, visibility follows explicit relationships, edit rights are narrower than view rights, and sensitive data has its own boundary.

The reality

Access rules grew one request at a time; nobody can explain who sees what, or why.

Architecture question

Does ownership mean accountability or visibility—and how is access granted without making everything public?

Key decision

Separate accountability (one owner), visibility (derived from organization and account-team relationships) and edit authority (narrower and role-based)—and drive all three from governed organizational data.

ContextA global commercial organization works across subsidiaries, regions, sales teams, key-account teams and specialists. Access rules grew one request at a time: sharing exceptions, copied profiles and manual grants. Some users see everything; others cannot see accounts they work on every day.

Systems and partiesCRMHR & org dataIdentity providerData platform

02The reality · current state

What the platform looks like today.

  • Ownership is used to grant visibility, so accounts are reassigned just to be seen
  • Global account teams cannot see local opportunities on their own accounts
  • Manual sharing exceptions pile up and nobody reviews them
  • Sensitive terms are visible to anyone who can see the account
  • Access changes lag behind organization changes
  • Reports show different totals to different people, with no explanation

03System responsibilities

Every platform, one job—and a boundary.

What each platform owns in this design, and what it deliberately does not. These are the responsibilities for this context, not universal rules.

CRM

Enforces record access
Owns
  • Record ownership (accountability)
  • Account teams and shared responsibility
  • Visibility rules from hierarchy and teams
  • Field-level protection of sensitive data
Deliberately does not own
  • Who belongs to which organization unit
  • Authentication

HR & org data

The organization as it is
Owns
  • Organization units and reporting lines
  • Role assignments and effective dates
Deliberately does not own
  • Account ownership decisions

Identity provider

Who the user is
Owns
  • Authentication and single sign-on
  • Joiner, mover and leaver events
Deliberately does not own
  • Record-level access

Data platform

Reporting access that matches the CRM
Owns
  • Row-level security aligned with CRM visibility
  • Access-review analytics
Deliberately does not own
  • Operational access decisions

04Key dimension · Ownership, visibility & edit authority

Who sees and edits what

Visibility is broader than edit authority, and both are separate from ownership. The matrix is the model—not a list of exceptions.

Who sees and edits what
RoleOwned accountsAccount-team accountsRegionGlobal accountsSensitive terms
Account managerEditEditSummaryNo accessView
SpecialistNo accessViewNo accessNo accessNo access
Sales managerEditEditViewSummaryView
Global account leadEditEditSummaryEditView
FinanceNo accessNo accessViewViewEdit
  • Ownership is accountability, not visibility.
  • View is broader than edit—by design.
  • Hierarchy grants visibility, never ownership.
  • Sensitive data has its own boundary.
  • Manual sharing expires.

“Everyone sees everything” and “everything is private” both avoid the design question. The matrix answers it.

05Data authority

Who may create, change, read or derive each concept.

Highlight
Data authority by business concept: which system may create, update, read or derive each concept
Business conceptCRMHR & org dataIdentity providerData platform
Account ownerOne accountable owner per account. Changing it is a governed commercial decision, not an access fix.CreateUpdateNo authorityNo authorityRead
Account team membershipShared commercial responsibility—specialists and global leads—without changing ownership.CreateUpdateNo authorityNo authorityRead
Organization unit & reporting lineVisibility through hierarchy follows the HR truth, synchronized—not maintained by hand in the CRM.ReadCreateUpdateReadRead
User identity & statusLeavers lose access when the identity provider says so.ReadReadCreateUpdateRead
Credit terms & marginProtected at field level: visible to finance and management roles, not to everyone who sees the account.UpdateNo authorityNo authorityRead
Effective visibilityDerived from ownership, teams and hierarchy—reviewed, not hand-maintained.DeriveNo authorityNo authorityDerive

No system owns a whole record here. Authority sits with each concept—and sometimes changes hands when the lifecycle does.

06Candidate architectures

Credible options, judged against these premises.

Rejected

Everyone can see everything

Small, single-entity organizations

Cost: Sensitive terms exposed; ownership loses meaning
Rejected

Private by default, manual sharing

Highly confidential sales

Cost: Sharing exceptions pile up; collaboration breaks
Selected

Private by default; visibility from hierarchy and account teams; field-level protection

A global organization with shared accounts

Cost: Needs governed org data and periodic access reviews

07The second layer

Questions that change the architecture.

Ownership

  1. Does ownership mean accountability or visibility?
  2. Can one record have several commercial stakeholders?
  3. What happens to access when ownership changes?

Visibility

  1. How does a manager inherit visibility?
  2. How is global access separated from edit permission?
  3. Which reports must show the same totals to everyone?

Boundaries

  1. What should remain private?
  2. Which fields are sensitive, and for whom?
  3. Who reviews manual sharing—and when does it expire?

08Decisions & outputs

What the work produces.

  1. 01Ownership model
  2. 02Visibility matrix
  3. 03Sharing strategy
  4. 04Hierarchy model
  5. 05Permission boundaries
  6. 06Access review cadence