language
theme
WhatsApp +7 701 960 13 11
//Security · September 14, 2026 · 11 min

The rep left and took the clients: locking down your database with Bitrix24 access rights

The role model, blocking export, change history and a proper offboarding routine: what Bitrix24 really covers out of the box, what no setting can prevent, and why without a trade-secret regime your configuration protects you only halfway.

The story repeats itself in every second company. A sales rep resigns calmly, without conflict, works out their two weeks honestly. A month later their former clients receive an offer from a competitor — and that is no coincidence. Before leaving, they exported the database to Excel, and nobody noticed, because there was nowhere to look.

Bitrix24 has almost everything needed to prevent this: a role model, a separate export permission, a change history, two-factor authentication. The problem is elsewhere — by default the portal is configured on the principle of "everyone sees everything", because that makes the launch faster. And that temporary mode stays forever.

The short version, if you have no time for the whole thing. 1) The main tool is the CRM role model: a sales rep sees only their own deals, a manager sees their department. 2) Export is a separate permission: remove it and an employee can no longer download the database to Excel. 3) The change history shows who changed what, but out of the box it covers system fields only. 4) Hiding a phone number from a sales rep is not possible with stock settings: either close the field with permissions or install a solution from the Marketplace. 5) Without an NDA and a trade-secret regime the settings protect you only halfway: Article 126 of the Civil Code of Kazakhstan protects only those who actually took measures to safeguard confidentiality.

Why "everyone here is family" is not a strategy

The objection always sounds the same: "we are a small team, I trust everyone". Trust has nothing to do with it. Access rights are not about distrusting a particular person — they are about the company owning an asset, and an asset needing a perimeter. The same argument does not stop you from locking the warehouse, even though you trust the storekeeper too.

The practical difference shows up the moment someone leaves. If the rep only ever saw their own clients and could not export data, their departure means handing over fifty deals. If they saw the entire database and had an "Export" button, their departure means a potential copy of your client base sitting with a competitor. The configuration is the same and takes half an hour; the difference in consequences is orders of magnitude.

There is a second layer people recall less often. A client base is personal data: names, phone numbers, e-mail addresses. A leak hits not only revenue but also compliance with the Law on Personal Data and Its Protection. How this works on our side is described in the privacy policy.

The role model: who sees what

The core tool is CRM roles, configured under CRM → More → Settings → CRM access permissions. They can be changed by a portal administrator or by an employee granted the right to change CRM settings. The free plan has no role model — it is part of the paid plans; the vendor revises the plan line-up from time to time, so check the current grid or ask us.

The logic is simple: you create a role ("Sales rep", "Head of department", "Accountant"), set an access level for each CRM entity — leads, deals, contacts, companies — and then assign the role to employees or departments. The levels are:

  • Personal — only items where the employee is the assigned owner. The baseline for a sales rep.
  • Department — plus items belonging to colleagues in the same department.
  • Department and subdepartments — plus everything below in the structure. The level for a division head.
  • Own teams and own teams and subordinate teams — the same idea, but by teams rather than by the org chart.
  • All open — items with the "Available to everyone" option enabled.
  • All employees — the entire database for that item type.
  • Full access — no restrictions; the opposite pole is access denied entirely.
Access levels in the Bitrix24 CRM role model: personal, department, subdepartments, all open, all employees
Levels run from "personal only" to "the entire database" — the first is usually enough for a sales rep

The level is set not in general but separately for each operation. This is exactly where the question of a stolen database is decided:

  • Read — what the employee sees in the list and in the record.
  • Add, edit, delete — what they can create and change.
  • Export — downloading CRM items out of the system.
  • Import — loading items into the system.
  • Also: running automation rules, seeing the totals on kanban stages, moving items between stages, using a custom record layout.
Export is a separate permission, and it is the single most important checkbox in this article. An employee can run deals, make calls, write in messengers and close sales — while being unable to export the database to Excel. Remove export from every role except the administrator and, perhaps, the head of sales. Note that task export is configured separately from CRM — check that too.

What stock settings cover, and what they do not

To keep expectations realistic, here is an honest picture of the requests owners usually bring.

What owners want to closeStock featureHow it is done
Reps seeing other people's dealsYesA role with read level "Personal"
Exporting the base to ExcelYesRemove the "Export" permission from the role
Mass deletion of recordsYesRemove "Delete", keep editing
Who changed which field and whenPartlyThe "History" tab — system fields only
Hiding phone and e-mail from a repNoRestrict the field with permissions or use a Marketplace solution
Blocking logins from personal devicesNot in the cloudTwo-factor authentication reduces the risk of account takeover
Preventing a photo of the screenNoThere is no way — this is an organisational, not a technical perimeter
Access rights reduce the scale of a leak, but do not make it physically impossible

A word on phone numbers, since this is the most common question. Bitrix24 has no stock toggle for "hide the number from the sales rep". There are two workarounds: close the field itself with access permissions for the relevant roles, or install a Marketplace solution that masks numbers in the record and in the mobile app. The second route is more robust but must be tested against your configuration: masking must not break telephony — the rep still needs one-click calling.

Change history: who touched the record

Lead, deal, contact and company records have a History tab. It shows the date, the author, the event type and a description: who moved the stage, who reassigned the owner, who edited a field. It is the first place to look when a deal "suddenly" turns into a loss or a client's owner changes.

An important nuance that is rarely written down: the stock history records changes to system fields. Custom fields you added yourself for your own processes are not included by default. If tracking edits in those fields is critical for you, that is a separate task solved by customisation or a Marketplace solution — and it should be planned in advance, not in the middle of an investigation.

Two-factor authentication

Access rights are pointless if someone else's account can simply be opened with a leaked password. Two-factor authentication is enabled under Settings → Security and can be turned on for the whole company at once: you set a deadline by which employees must configure it, after which logging in without the second factor is blocked. The confirmation arrives in an authenticator app, in the Bitrix24 mobile app, by SMS or by e-mail.

On higher plans two-factor authentication is mandatory — that is the vendor's policy, not our recommendation. On lower plans it is worth enabling yourself: it is the cheapest security measure in existence.

Offboarding: what to do in the first hour

The moment of resignation is not "sometime later" but the hour right after the conversation. The order is:

  • Close access. An administrator dismisses the employee under Company → Employees. The person stays in the structure and their messages, tasks and files are kept, but they can no longer log in to the portal.
  • Hand over the work. After dismissal, CRM deals and activities, tasks, mail and personal drive files are reassigned to the manager or a new owner.
  • Check the history. Look through the "History" of records for mass edits or reassignments during the last days of employment.
  • Change shared passwords. If the employee knew the credentials for mail, social accounts or the telecom operator's portal — change them, do not rely on hope.
  • Revoke external access. The mobile app, open channels, connected services — everything that was tied to their account.
Two perimeters protecting a client base: technical — roles, export ban, history, 2FA; legal — NDA, trade-secret regime, signed acknowledgement
The technical perimeter limits access, the legal one gives the right to claim damages — they work only together

What no setting will ever cover

Here it is important to be honest, because the market promises otherwise. A sales rep by definition sees the clients they work with: they call them, write to them, travel to meetings. They can photograph the screen with a phone, copy numbers into a notebook, or simply memorise a dozen key accounts. No CRM in the world prevents that.

Access rights do not make stealing a database impossible — they change its scale. The difference between "copied 3,000 contacts with one click" and "wrote down twenty numbers by hand" is the difference between a disaster and a nuisance. And in the second case you still have the change history and something you can prove.

The legal perimeter: without it, settings work only halfway

Article 126 of the Civil Code of Kazakhstan protects official and commercial secrets when three conditions hold at once: the information has actual or potential commercial value because it is unknown to third parties, there is no free access to it on a lawful basis, and — crucially — the holder of the information takes measures to safeguard its confidentiality.

Read that last condition again. If the base is open to every employee and anyone can export it, you took no protective measures, which means there is nothing to defend in court either. Configured access rights are precisely those measures, and they are documented ones. But settings alone are not enough — you also need paperwork:

  • A list of information constituting the company's trade secret — a specific list, not "all information".
  • An NDA or a non-disclosure section in the employment contract, acknowledged by the employee in writing.
  • A trade-secret regime policy: who is admitted to what, how access is granted, what happens on dismissal.
  • A record of granted access — who was assigned which role and when.

Under the same article, persons who disclose a trade secret in breach of an employment or civil-law contract must compensate the damage caused. But you can only claim compensation if the perimeter was built in advance. After the leak it is too late to assemble it.

A working setup for a sales department

The configuration we most often implement in small and mid-sized Kazakhstani companies:

  • Sales rep. Read — "Personal", edit — "Personal", add yes, delete no, export no. Sees their own clients, works with them, cannot export the base.
  • Senior rep or head of sales. Read and edit — "Department", delete no, export no. Sees the team's work, but the base still cannot be exported.
  • Executive. Read and edit across subdepartments, export at the owner's discretion. We usually leave it, with the understanding that this is a trusted person.
  • Accountant. Access to deals and invoices to the extent their job requires, and the minimum necessary access to contacts.
  • Administrator. Full access, two-factor authentication mandatory, a named account rather than a shared one.

This is then layered onto the org chart: the "department" and "subdepartments" levels work exactly as the company structure is built inside the portal. If the structure is nominal and everyone sits in one department, the role model gives you nothing. That is why order is restored from both sides at once — it is part of implementing Bitrix24, not a separate task.

Five mistakes we see during audits

  • Everyone is an administrator. More common than you would think: it is convenient right up until somebody deletes a pipeline.
  • Permissions configured, export forgotten. The most frustrating one: access was restricted, but the export button stayed available to everybody.
  • A shared "sales" account. Three people work under it, and the change history is useless — you cannot tell who did what.
  • An org chart on paper only. Everyone is in one department, so the "department" level effectively means "the whole company".
  • Dismissed but not disabled. The person left a month ago, yet still has access to the portal and the mobile app.
Which Bitrix24 plan includes CRM access permissions?
The free plan has no CRM role model — it comes with the paid plans and with the self-hosted edition. The vendor revises plan names and contents from time to time, so it is best to check the exact mapping against the current grid at the time of purchase, or to ask us.
Can I stop a sales rep from exporting the database to Excel?
Yes. Export is a separate permission in the CRM role model. Remove it from every role except the administrator and, if needed, the head of sales. The employee will keep running deals but will not be able to export CRM items. Task export is configured separately — check that as well.
Can I see who exported data from the CRM?
The stock history in a record logs changes to the item itself: who moved the stage, the owner, a field. Do not expect a full "who exported what and when" log in the cloud. It is therefore more reliable not to grant the permission at all than to try to track exports after the fact.
How do I hide a client's phone number from a sales rep?
There is no stock toggle for this. Two options: restrict access to the field itself through permissions for the relevant roles, or install a Marketplace solution that masks numbers in the record and the mobile app. The key check is that telephony still works after masking and the rep can still call in one click.
An employee resigned — what comes first?
Close access under Company → Employees, hand over deals, tasks, mail and files to a new owner, review the "History" of records for the last working days, and change every shared password they knew. The dismissed employee's data is retained in the portal.
Will access rights protect the base completely?
No, and promising otherwise would be incorrect. A sales rep sees the clients they work with and can copy or photograph their contacts. Permissions limit the scale: exporting the entire base with one click is one thing, writing down twenty numbers by hand is another. Full protection is technology plus paperwork: an NDA, a list of protected information and a trade-secret regime.
Not sure how permissions are configured in your portal right now? More often than not it turns out they are set "by default", which means not at all. We will review your configuration in a free 30-minute consultation: we will show who sees what and what can be exported right now, and propose a scheme that fits your structure. Request a consultation.
Next step
Bitrix24 implementationFree auditPricing and timeline
//ready to start

Ready for hands-on implementation?

A free 30-minute audit — we will show how to apply this article in your business.

Call UsSee pricing