Back to Resources
Guide · Core

Data Security Best Practices

How to set up granular permissions and protect your operation's sensitive data in Centriu.

1. Data security is a management decision, not just IT

Data today carries everything: customers, billing, pipeline, contracts, support. Without a clear policy:

  • Too many people see what they don't need to see.
  • Important changes happen without a trace.
  • Database exports become a “normal” habit.

The guide shows a simple path to protect what matters without slowing down the operation.

2. Basic principles for organizing access

Before opening Centriu, align on four principles:

Least privilege possible

Each role sees only what is needed for daily work.

Separation of duties

Whoever creates records is not whoever approves; whoever pays is not whoever audits.

Traceability

Critical actions need a record: who did it, when, and what.

Periodic review

Roles and access are not permanent; they need to be reviewed in cycles.

3

Modeling roles within Centriu

The guide provides a base model that you can adapt:

AdminConfigures modules, permissions, integrations. Sees all sensitive data. Should be restricted to a few people.
ManagerTracks reports, metrics, and pipelines. Can approve some actions, but doesn't change everything.
OperationalWorks day to day with leads, customers, tickets. Doesn't export the full database, doesn't access billing.
FinanceSees plans, payments, billing status. Doesn't need to see interaction details.

For each role, the guide explains which modules can be accessed, which actions are allowed, and what to never grant.

4. Protecting critical information in practice

Customer databases

Control over who can export and masking of sensitive fields.

Financial data

Separation between who sees amounts, who changes plans, and who only tracks status.

User access

Use of corporate email, password policies, and immediate removal upon departure.

How Centriu Core helps you apply the guide

  • Create custom roles aligned with job functions.
  • Define permission levels by module and by action.
  • Track logs and records of relevant activities.
  • Integrate with corporate identity providers.

Implementation in 10 steps

1
List all types of users who access Centriu today.
2
Map which data each role actually needs to see.
3
Define the role matrix (Admin, Manager, Operational, etc.).
4
Set up these roles in Centriu and review permissions.
5
Reduce excessive access (exports and deletions).
6
Create a security checklist for new users.
7
Define an offboarding flow for quick removal.
8
Schedule quarterly reviews of roles and access.
9
Train the team on what sensitive data is.
10
Track reports/logs and adjust when risks are identified.

Ready to better protect your operation's data?

Use the best practices guide to set up roles and permissions in Centriu and keep security without slowing down the team's work.