Business Systems

Why Your Team Has the Wrong Data Access Permissions

Your ex-bookkeeper can still open your payroll sheet. Here is why data access permissions get this loose at SMBs, and how to actually fix it before you bolt on any automation.

Why Your Team Has the Wrong Data Access Permissions
Fig. 01 — Business Systems July 28, 2026

Your old bookkeeper left in November. It's July, and she can still open the shared Google Sheet that has every customer's card-on-file notes, your payroll runs, and the margin on every job you've quoted this year. Nobody revoked her access because nobody owns data access permissions at your company. The sheet just... exists, shared with "anyone with the link," because three years ago that was the fastest way to get a contractor working by Friday.

That's the real shape of the data access permissions problem at most small and mid-sized businesses. It's not a hacker. It's not a disgruntled employee. It's a warehouse lead who can see everyone's salary because he was CC'd on a spreadsheet once and never removed. It's a part-time VA who can edit the master pricing tab instead of just viewing it. It's a former vendor whose Dropbox folder access outlived the contract by fourteen months.

Why data access permissions get this loose

Nobody sits down one day and decides to give everyone edit rights to everything. It happens one invitation at a time. Someone needs to see one number in a Google Sheet, so you share the whole tab. A new hire needs to update inventory counts, so you give them the same login as the person who left. QuickBooks, your CRM, a shared drive, three different spreadsheets that all sort of track the same customer. None of them were built with roles in mind, so permissions default to "everyone gets in," because setting up tiers takes time nobody has.

Small teams also run on trust, which is a real asset and also the reason nobody wants to be the person who says "actually, you shouldn't see that." Restricting access can feel like an accusation. So it doesn't happen, and access just accumulates like sediment. Two years in, a 12-person company has forty live shares across six tools, and not one person could tell you who currently has write access to payroll.

Why the usual fixes don't hold

The instinct is to patch it with more spreadsheet gymnastics: hide a tab, protect a range, password-lock a specific cell. This buys you a week of peace. A hidden tab in Google Sheets is one click away from unhidden. A protected range still shows the underlying data to anyone who can open the file. It just stops them from typing over it. None of this creates an actual boundary. It creates the appearance of one, which is worse than nothing, because it lets you stop worrying about it.

The other common fix is the audit. Once a year, someone goes through and manually revokes stale access. It feels responsible. But by the time you run it, half the access list is already wrong, because nobody's offboarding checklist includes "pull them out of the shared drive, the CRM, the invoicing tool, and the three Slack-connected sheets." The audit fixes the past. It does nothing for the next new hire, who'll get dropped into the same overshared folder next Tuesday.

And then there's the overcorrection: buying an enterprise platform with granular roles, permission groups, and approval chains, then never actually configuring it. Setting up real role-based access takes someone sitting down and mapping who needs what, and that's the part everyone skips. The tool isn't the problem. The unmapped decision underneath it is.

The tradeoff nobody wants to name

Tighter access has a real cost: friction. If your ops coordinator has to request access every time she needs a number, she'll find a workaround. Usually a screenshot in Slack, or worse, someone exporting the data to their own personal sheet so they don't have to ask again. That's how access sprawl regenerates even after you clean it up.

So this isn't "lock everything down." It's matching the level of restriction to the actual sensitivity and actual need, on purpose, instead of by accident. A few criteria that hold up in practice:

  • Who needs to act on this data regularly, versus who needs to glance at it occasionally? Regular actors get edit access in a real system. Occasional viewers get a read-only view or a report, not a live editable file.
  • What's the blast radius if this is wrong or leaked? Payroll, banking details, and customer payment info get the tightest tier no matter how small your team is. A job-status tracker doesn't need the same lockdown as a bank feed.
  • Does the access map to a role, or to a person? If you're granting permissions by name ("give Sarah edit access") instead of by role ("ops coordinators get edit access to job scheduling"), you'll be redoing this every time someone changes jobs or leaves.
  • Is there a log? If you can't answer "who changed this number and when" without asking around, you don't have access control — you have a shared folder with extra steps.

A practical way to actually fix it

You don't need a six-month security overhaul. You need an honest inventory and a system that can enforce tiers instead of relying on people remembering not to touch things.

  1. List where sensitive data actually lives. Not where it should live, where it currently lives. Payroll numbers, customer payment details, pricing, vendor contracts. Most SMBs find this spread across four or five tools plus a handful of "temporary" spreadsheets that became permanent eighteen months ago.
  2. Assign each data type an owner and a small number of access tiers. Usually view, edit, and admin is enough. Resist the urge to design ten permission levels; you'll never maintain them.
  3. Move sensitive, shared data out of link-based spreadsheets and into a system that supports real roles. A CRM, an ERP, or an internal tool with row-level or field-level permissions, not "anyone with the link can edit."
  4. Tie access changes to onboarding and offboarding, not to memory. When someone joins or leaves, access changes are a checklist item with a name attached, not a maybe.
  5. Turn on activity logging wherever you can. Even a basic "last edited by" trail changes behavior — people are more careful when changes are attributed.
  6. Revisit quarterly. Not annually. A quarter is short enough that stale access doesn't have time to become invisible.

This is also where a lot of automation and AI plans quietly fall apart before they start. If you're hoping an AI assistant can pull numbers into a report, flag anomalies in spending, or draft a customer update, it needs a clean, permissioned, structured source to work from. Point an AI tool at a shared folder where anyone can edit anything and you haven't gotten a smart assistant — you've gotten a fast way to surface bad data to the wrong person, or worse, let something act on data it should never have touched. Access control isn't a compliance checkbox you do before AI. It's the thing that makes AI usable at all, because the system finally knows what "correct" and "allowed" mean for each piece of data.

Where to start this week

You don't have to fix all of it at once. Start with the one dataset that would actually hurt if the wrong person changed it: payroll, pricing, or customer payment info. Give it a real owner and a real tier structure before you touch anything else. Everything else can wait a quarter. That one can't.

If you want a second pair of eyes on where your access and data actually live right now, we run a free Process Teardown: a 30-minute session where we map one of your painful workflows and show you, in hours and dollars, what it's quietly costing. No pitch, no obligation — just a clear look at what's broken. You can see the kind of before-and-after we're talking about in our case studies, where we've taken businesses running on scattered spreadsheets and shared drives and connected them into one system before layering on any automation.

Free Process Teardown

Want to see where your hours are actually going?

Book a free 30-minute Teardown — we map one of your most painful workflows live and show you exactly how much time it's quietly costing. No pitch, no obligation.

Book your free Teardown

0 Comment

Leave A Reply

logo
Let's talk

Book a free Process Teardown. We'll map one workflow and show you the hours it's draining — no obligation, whether or not you build with us.

Book a free Process Teardown