CRM Basics6 September 2026

How to Access a CRM: Logins, Phones, Users and Who Sees What

Do you have to install anything? Can you use it on your phone? Who in the team gets a login, and who should see which customers? A practical answer to the most-asked beginner questions about getting into a CRM — including what happens when someone leaves.

Vilartech Team

How to Access a CRM: Logins, Phones, Users and Who Sees What

For someone who has never used one, the practical questions come before the strategic ones. Do I have to install something? Is my data on my computer or somewhere else? Can my salespeople use it outside the office, and if they can, what stops one of them walking off with the whole client list?

These are good questions and they have short answers. Here they are.

If you have arrived here without reading what a CRM is, that is the place to start.

You almost certainly do not install anything

Most CRMs are reached the way you reach your email: open a browser, go to an address, log in. Nothing is installed on your computer, and nothing lives on one machine that can break, be stolen, or turn out to be the laptop somebody took home on the day you needed a phone number. When a new person joins, you send an invitation and they are working the same morning.

The alternative — running the software on servers your company owns — is a real project, and the choice between the two is covered in types of CRM. Unless someone has actually told you that your data must sit on your own equipment, whether a regulator, a customer contract or your own security policy, you will not need it.

Two honest qualifications. Some products still ask you to install something small, such as a phone app or a plug-in that connects your email — worth asking about, since it is where "nothing to install" usually turns out to have an asterisk. And if the internet is down, you are out. Most systems keep working over mobile data on a phone, which covers the common case of the office connection failing. Some have a limited offline mode. Ask; do not lose sleep.

"Nothing to install" also does not mean nothing to manage. The vendor looks after the servers. Your business still looks after who has a login, what each of them can see, and the security settings below.

Yes, it works on a phone — and this matters more than it sounds

Most CRMs offer a phone app; some use a website built to work well on a phone instead. Either can be fine — what matters is that the phone experience is genuinely usable, because for a sales team that is where most of the recording actually happens.

The reason is timing. A salesperson finishes a viewing, a meeting or a call, and there is a window of about a minute in which they will record what happened. If the only way to do that is a laptop back at the office, the record gets written four hours later from memory, in summary, or not at all. On a phone it is thirty seconds while walking to the car.

Two things to test on a real phone before you commit, both commonly bad and rarely mentioned in a demo:

  • Does it work on a weak connection? Apps built and tested on office wifi become unusable in a basement or on a rural road.
  • Is the Arabic interface genuinely usable? Many products translate the words and leave the layout broken right-to-left. Ask to see the Arabic app on a real phone, not a screenshot.

Who gets a login

Everyone who talks to customers, plus anyone who needs to see the numbers.

Most systems charge per person, and a paid-for login is often called a seat. Two mistakes to avoid, in opposite directions. Do not pay for seats nobody will ever open. And do not let two people share one login.

Sharing feels like a saving and costs you the point of the system. You lose the record of who did what, which is half the value of keeping a history at all. Handing work to a named person stops working, because the system cannot tell the two of them apart. Notifications go to nobody in particular. And on the day one of them leaves, you cannot cut off their access without cutting off their colleague's too.

Roles: what different people are allowed to do

Most systems have three or four levels. The names vary; the shape does not.

Administrator. Can change how the system works: stages, fields, users, integrations. This should be one or two people, not everyone senior. Most damage to a CRM is done by well-meaning people with admin rights redesigning something on a Thursday.

Manager. Sees their team's customers and reports, reassigns work, but cannot restructure the system.

Agent. Works their own customers. Adds, updates, moves stages, logs conversations.

Read-only or finance. Can see, cannot change. Useful for an accountant or a partner who wants visibility without the ability to move something by accident.

Set these before you send the invitations. Adding permissions later is easy; taking them away from someone who has had them is a conversation nobody enjoys.

Who sees which customers

Separate from roles, and the setting people most often get wrong on the first day.

There are three common arrangements:

  • Everyone sees everything. Simple, and fine for a team of three who all work the same customers.
  • Agents see only their own; managers see the team. The right default for most sales teams above about five people.
  • Team-based. Several teams, each seeing only its own book. Used by larger operations or where teams handle genuinely different markets.

This is worth getting right for reasons that have nothing to do with suspicion. It stops two agents working the same customer and calling them separately, which is the most common cause of internal arguments about commission. It limits the damage if one login is stolen. And it means the amount of company data any one person can reach is a decision you made, rather than an accident.

Be realistic about what it does and does not do, though. Permissions control what an account can reach. They cannot stop someone photographing a screen, and they do not undo an export somebody took last year. So pair them with the other two controls: restrict who can download the database at all, keep a record of when it happens, and remove access the day a person leaves rather than the week after.

Ask to see permissions set up live during a demo. "Yes, we support roles" is not the same as "here is exactly what an agent sees".

Keeping the account secure

A CRM contains every customer your business has, along with their phone numbers, their budgets and everything they told you in confidence. Treat the login accordingly.

Two-step login. Often called two-factor authentication: as well as the password, the person types a code sent to their phone. Turn it on, at minimum for administrators and ideally for everyone. A password on its own is one leak, or one reused password, away from being somebody else's.

Automatic sign-out, and signing out a lost phone. Set the system to ask for the password again after a period of inactivity. And check that an administrator can sign a specific device out from a distance — this is the setting you will want urgently the day a phone is left in a taxi, and the moment to find it is before that day.

Ask what gets recorded. Some systems keep a log of who signed in, from which device, and what they downloaded; others record less, or only on the more expensive plans. Ask, and ask to see it during the demo rather than assuming. Nobody reads these logs routinely. Everyone reads them once, usually in the week after a resignation.

Watch downloads. The ability to save the whole database as a spreadsheet is both necessary and dangerous. Ideally only administrators can do it, and the system notes when they have.

What happens when someone leaves

This is one of the two questions that decide whether a CRM was worth buying, so it deserves a clear answer.

You switch the person off; you do not delete them. Switching them off — most systems call it deactivating — cuts their login while leaving everything they recorded in place, so the notes they wrote in March are still readable in September and still show their name. In some badly built systems, deleting a user instead disconnects or hides everything filed under them. Check which one you are buying before you sign.

Then you move their customers to someone else, either all to one colleague or split across the team. Good systems do this in a couple of clicks and bring the open tasks with them, so nothing quietly ends up with no owner.

What that buys you is a much smaller gap for the customer — not none, because a new person still has to read and ring. But the difference between "someone will call you back once we work out who was handling you" and a colleague who already knows what was agreed is most of the relationship.

This is the single best scenario to make a vendor act out in a demo: ask them to switch off an agent in front of you and hand fifty open customers to somebody else.

Getting your data out

The last access question, and the one people ask too late.

Your customer data is yours. Before you put real information into any system, get two answers, ideally in writing:

  1. Can we download everything ourselves, at any time, without asking you? Do not settle for a yes — ask for a sample download during the trial and open it. It should be a spreadsheet file you can open in Excel, and it should contain the customers, the deals, the notes and the conversation history. A file with names and phone numbers in it is not your data; it is your address book.
  2. What happens to it if we stop paying? Some vendors leave the account readable for a period before deleting it; some do not. Do not assume there is a grace period. Ask how long it is and get the answer in writing.

A supplier who answers both immediately and without discomfort is telling you they expect to keep you by being good. Hesitation on either is worth acting on, because these terms are far easier to settle before you sign than in the middle of a disagreement.

Getting your first login

The path is shorter than most people expect:

  1. Take a demo with a real product, not a slide deck, and use the scenarios above — the departing employee, the agent's restricted view, the Arabic app on a phone.
  2. Start a trial, and work a few real situations through it — a real enquiry arriving, a real follow-up, a real handover. Feature lists tell you nothing about whether your team can work in something. A week of pretending to be busy in it tells you everything.
  3. Settle the data questions before you load your customer list in. Who at the vendor can see it, where it is stored, how you get it back, how you have it deleted. Those are your customers' details, and they were given to you rather than to a software company. Use made-up records until you have the answers.
  4. Then import your live customers and open enquiries, invite the team, and run the first two weeks properly. How to use a CRM covers exactly what that looks like.

If your customers reach you mainly on WhatsApp, there is one more setup step worth reading about on its own: WhatsApp CRM integration.

That completes this series. The other four parts are what a CRM is, the types, how to use one and what it actually changes. When you are ready to compare specific products rather than understand the category, the buyer's guide to CRMs in Egypt picks up where this leaves off.