Skip to main content

Seen CRM

Access Control Policy

Document numberSEEN-POL-02
Version1.0
Effective dateOn approval
Policy ownerSeen CRM Management
Approved bySeen CRM Management
ClassificationPublic
Next reviewWithin 12 months of the effective date

1. Purpose

This policy ensures that access to the Seen CRM platform and to customer data is limited to authorised people, for authorised purposes.

2. Scope

This policy applies to all user accounts on the platform, to Seen CRM's administrative accounts, and to the systems that operate the platform.

3. Policy

  1. Least privilege. Each person receives only the access their role requires.
  2. Customer control. Each customer's administrators manage their own users, roles and permissions.
  3. Passwords. Passwords are stored only in a one-way protected form. Repeated failed sign-in attempts temporarily block further attempts.
  4. Multi-factor authentication. Required for every Seen CRM administrative account. Customers may require it for their own users.
  5. Single sign-on. Customers may allow their users to sign in with Google or Microsoft.
  6. Sessions. Sessions expire automatically. Deactivating a user or changing their password ends their active sessions. Sensitive actions require the password to be entered again.
  7. Support access. Seen CRM accesses a customer's workspace only to provide support, and every such access is recorded in that customer's own audit log.
  8. Leavers. Access is removed on the day a person leaves or no longer needs it.
  9. Reviews. Administrative access is reviewed at least every three months.

4. Responsibilities

Management grants and reviews administrative access. Customer administrators are responsible for the access they grant within their own workspace.

5. Exceptions

Any exception must be approved in writing by management, with a stated reason and an end date.

6. Review

This policy is reviewed at least once a year, and after any major security incident.

7. Contact

Questions about this policy: info@seencrm.com

This policy describes Seen CRM's security practices and does not form part of any contract. If it conflicts with the Terms of Service or a signed agreement, the Terms of Service or the signed agreement prevail. Seen CRM may update this policy at any time; the version in force is the one published at seencrm.com.

© 2026 Seen CRM. All rights reserved. This document and its contents are the intellectual property of Seen CRM and are protected by the Copyright Protection Law of the Kingdom of Saudi Arabia and applicable international treaties. It is published for the information of Seen CRM's customers and prospective customers. No part of it may be copied, reproduced, modified, distributed or used for any other purpose without the prior written consent of Seen CRM. “Seen” and “Seen CRM” are trade names of Seen CRM.