Read-only CRM audit: how to audit a customer database without modifying it

Updated October 5, 2026

A read-only CRM audit analyzes a customer database through a connection that can read data but cannot change it. It answers a question most teams ask before letting any tool near production data: what if it breaks something? With a read-only connection, it cannot.

In brief

  • The audit reads your contacts and never writes to your database.
  • Read-only is enforced twice: by the database account you create, and by the session Recovizy opens.
  • The report includes proof: a write attempt that your own server refused.
  • You get duplicates, data health and revenue opportunities, in figures.

What "read-only" means in practice

A database connection is read-only when it can run SELECT queries and nothing else: no INSERT, no UPDATE, no DELETE, no table creation. The analysis happens on a copy of the data held by the audit tool, and your production tables stay exactly as they were.

This matters because the usual objection to a CRM audit is not its price, it is the risk. A tool with write access can merge the wrong records or overwrite a field. A tool that can only read cannot.

Two layers of protection

Either layer is enough on its own. Having both means you do not have to take anyone's word for it.

  • Your side: you create a dedicated database user that only has the right to read the contact table. Even if the tool tried to write, your server would refuse.
  • Recovizy's side: every session is opened in read-only mode, over an encrypted (TLS) connection. No write statement is ever sent.

How to verify it yourself

A claim of read-only access is only worth something if it can be checked. The Recovizy audit report contains a "Connection security" section that records what was actually observed on your server:

  • whether the connection was encrypted with TLS;
  • whether the session was read-only;
  • the result of a deliberate write attempt, made inside a transaction that is immediately rolled back: your server's refusal is the proof;
  • whether the account used has administrator rights or any write permission, so you can tighten it if needed.

What the audit measures

Revenue figures are estimates built from the values in your own data. They describe a scenario, not guaranteed income.

AreaWhat you learn
DuplicatesHow many records are duplicated, and how many groups they form
Data healthShare of valid email addresses and how complete the records are
Revenue opportunitiesAn estimate, in euros, of what dormant opportunities are worth
Connection securityProof that the database was read and never modified

What you need to start

The free diagnostic runs on a random sample of 1,000 contacts. A data processing agreement is signed before any data is read.

  1. A PostgreSQL database that holds your contacts, reachable over the Internet with TLS.
  2. A database user limited to reading the contact table.
  3. About ten minutes with our team to set up the connection.

Frequently asked questions

Can a read-only audit damage my CRM?

No. A read-only connection cannot insert, update or delete anything. Recovizy opens every session in read-only mode, and the dedicated user you create has no write permission.

How do I know the tool did not write anything?

The report records a write attempt that your server refused, the read-only state of the session and the permissions of the account used. You can also check your own database logs.

Does it work with a CRM that is not a database?

The free diagnostic connects to PostgreSQL. HubSpot, Pipedrive, Salesforce and REST APIs also connect to the application.

See it on your own data

The diagnostic on a random sample of 1,000 contacts is free, read-only and comes with no commitment.

Request the free diagnostic