Why View-Only Access Should Be the Default for Portfolio Company Marketing Reviews
View-only access, sometimes called read-only access, generally prevents campaign, configuration, budget, and administrative changes inside a portfolio company’s CRM, analytics, advertising, and marketing automation platforms. It does not automatically block every export, download, or record-level action. Those permissions vary by platform and must be verified separately on each system before access is granted. For a portfolio company marketing review, the working standard is least-privilege access: give the reviewer only what the diagnostic requires, confirm export and record-level permissions on each platform rather than assuming them, and remove access when the review ends.
- Why operators are right to be cautious about outside access
- What view-only access actually covers, and what it does not guarantee
- Which systems usually need access, and how to scope the list
- A practical access-control checklist
- What access requests reveal about a portfolio company’s governance
- Final Thoughts
- Frequently asked questions
Why operators are right to be cautious about outside access
The caution is reasonable. A portfolio company’s CRM holds every customer relationship the business has. Its ad accounts hold live budget and payment details. Its analytics account holds traffic and conversion data a competitor would rather not see. Handing broad access to someone outside the company, even someone the firm brought in, is a real decision, not a formality. The stakes behind that decision are not abstract. According to IBM’s 2026 Cost of a Data Breach Report, the global average cost of a data breach reached $4.99 million, a twelve percent increase over the year before and a record high. That figure does not mean granting one reviewer excessive access will cause a breach. It means access governance is worth taking the time to configure correctly on every system a reviewer touches. The more common mistake is not that operators worry about access. It is that they resolve the worry in the wrong direction. Some lock the review down so tightly that the reviewer cannot see enough to reach a real conclusion. Others open broad admin access because configuring a narrower role feels like more work than it is worth, and because they assume a role called Viewer or Read Only already limits what a reviewer can do. That assumption is where the real risk sits. This question comes up most often right before I run the review before you replace anyone, when a reviewer needs to see live systems for the first time.What view-only access actually covers, and what it does not guarantee
View-only access is built on a documented security principle called least privilege. NIST’s definition of least privilege describes granting each user only the minimum resources and authorizations needed to perform a specific function, nothing more. That is the right target for a portfolio company marketing review. It is not, by itself, a guarantee of what a specific platform’s view-only role will and will not allow. Here is the nuance operators miss. A role labeled Viewer, Analyst, Guest, Reporting, or Read Only does not mean the same thing on every platform. Google’s own support documentation for Analytics confirms that a user with the Viewer role can export reports to PDF, CSV, or Google Sheets. CSV and Google Sheets exports may contain up to 100,000 rows. That does not mean the user has unrestricted access to export every piece of property data, but it does show that a Viewer role is not the same as a no-export role. HubSpot works differently, but the same principle applies. HubSpot’s user permissions guide confirms that users with View permissions on a CRM object can still create notes or tasks on records of that object, even though they cannot edit existing notes or tasks, or create emails, calls, and meetings, without additional Communicate permissions. A reviewer with view-only CRM access is not fully locked out of record-level activity by default. Neither example means view-only access is the wrong standard. It means the label is a starting point, not a finished configuration. Before granting access on any platform, confirm whether that role allows export, download, billing visibility, user management, or record-level edits, and restrict what the diagnostic does not need.Which systems usually need access, and how to scope the list
Most portfolio company marketing reviews start with four systems: the CRM, website analytics and search-performance platforms, paid advertising accounts, and marketing automation or email platforms. These four typically cover deal source, loss reasons, channel performance, and lead-to-sales handoff.
A practical access-control checklist
Work through this list before access goes live, regardless of which systems are in scope.- Create named individual accounts rather than sharing an existing login, so there is an audit trail.
- Apply least-privilege access as the default, and treat it as a starting position to narrow, not a guarantee.
- Verify view, edit, export, download, billing, user-management, and record-level permissions separately on each system, rather than assuming a Viewer or Read Only label covers all of them.
- Turn on multi-factor authentication where the platform supports it.
- Limit access to the specific accounts, properties, regions, business units, and date ranges the review actually needs.
- Avoid exposing customer-level or personally identifiable information the review does not require. Summary-level reporting is often enough.
- Record who approved the access and when.
- Set an expiration date where the platform supports one. Where it does not, create a dated task to revoke access manually.
- Remove access promptly once the review concludes, and confirm in writing that removal was completed.

Set the access standard before the review starts.
A useful review needs enough visibility to reach a conclusion without giving an outside reviewer broader control than the work requires.
Schedule a Strategic Growth DiagnosticWhat access requests reveal about a portfolio company’s governance
I have written before about the governance gap that shows up as a sales and marketing fight. Access requests are an early, practical version of the same question: does anyone actually own the systems, or is ownership scattered across whoever still has a login. The same pattern shows up in why you can’t size up every portfolio company from scratch. A company that has never been reviewed on its own terms often has not assigned clear ownership over its systems either, and access requests are usually the first place that gap shows. It also connects to the leadership vacuum at the portfolio level. When no one has explicit authority over a decision, from strategy down to a login, someone eventually has to guess, and guessing is where delay and risk both live. In a well-documented environment, access can often be arranged without materially delaying the review, because someone already knows which platforms exist and how to create a limited role. A prolonged access process may point to unclear system ownership or undocumented permissions. That is a reasonable working hypothesis, not a confirmed conclusion, and the actual cause is worth confirming before treating slow access as proof of a governance problem. Either way, the fix is the checklist above: named accounts, documented ownership, and a repeatable process for granting and removing access, so the answer does not depend on any single person’s memory.Final Thoughts
View-only access is the right default for a portfolio company marketing review, but the label alone does not do the work. Least-privilege access means confirming, on every platform in scope, what a view-only or read-only role actually allows before access goes live, and narrowing it further where the platform’s default is broader than the review requires. Scope the systems to what the diagnostic needs, prefer summary-level data where it answers the question, and use the checklist above so access decisions do not depend on memory or goodwill. If you want an independent read on a specific portfolio company, including how its systems and access are set up, that is the work I do at CMO Strategy Pro.Review the company without overexposing the systems.
Define the scope, confirm the permissions, and give the reviewer only the access the diagnostic actually requires.
Schedule a Strategic Growth DiagnosticFrequently asked questions
What is view-only access in a portfolio company marketing review?
View-only access, also called read-only access, is meant to let a reviewer see data in the CRM, analytics platform, ad accounts, and marketing automation system without making campaign, configuration, budget, or administrative changes. The exact export, download, and record-level permissions still need to be confirmed on each platform.
Does view-only access always prevent exports or downloads?
No. Export and download permissions are often controlled separately from view permissions. Google’s own documentation confirms a Viewer role in Analytics is enough to export a report, and some CRM view roles still allow limited activity such as notes or tasks. Confirm export and record-level permissions on each platform rather than assuming a view-only label blocks them.
Which systems usually require access during a marketing review?
The CRM, website analytics and search-performance platforms, paid advertising accounts, and marketing automation or email platforms are the usual starting points. Depending on scope, additional systems such as call tracking, e-commerce, business intelligence dashboards, data warehouses, revenue intelligence tools, or customer support platforms may also be needed.
Why should reviewers avoid full administrator access?
Full administrator access adds the ability to change settings, spend budget, or alter records. A properly scoped review generally does not require those capabilities, and the information needed is typically available through narrower roles or approved reports.
Who should approve and configure reviewer access?
The operating partner or portfolio company leadership should specify what access is needed in writing, and the company’s IT lead or marketing operations lead should create and configure the roles. The reviewer should not set their own permission level, and the approval should be recorded.
How should access be removed after the review?
Access should be removed promptly once the review concludes, using an expiration date where the platform supports one and a dated revocation task where it does not. The removal should be confirmed in writing rather than assumed.
Can a useful review be completed without customer-level data?
Often, yes. Summary-level or report-level data is usually sufficient to answer the questions a marketing review is built around, including channel performance, pipeline stages, and campaign spend. Row-level access to names, contact details, or other personally identifiable information is rarely necessary for the diagnostic itself.
What is the difference between view-only access and least-privilege access?
View-only describes a platform role or permission level. Least privilege is the broader security principle of granting only the minimum access needed for a specific task. A role labeled View Only may still allow exports, downloads, or limited record activity, so the role must be checked and narrowed to match the least-privilege standard.
By Mark Toney, CMO Strategy Pro
Mark Toney is the founder of CMO Strategy Pro, where he runs marketing evaluations and installs fractional marketing leadership at PE-backed portfolio companies. He has spent his career connecting marketing decisions to revenue and works directly with operating partners and portfolio company leadership through hold periods, from acquisition through exit.
