# CRM Security Checklist

**Kind:** Checklist · **Stage:** Security · **Last reviewed:** 2026-08-14

Gate buy and go-live on SSO/MFA plan truth, object visibility, contact/deal exports, email-sync privacy, and access reviews — including FS niches.

Companion reading: [financial services CRM security](/guides/financial-services-crm-security/), [vendor evaluation](/guides/crm-vendor-evaluation/), [CRM implementation](/guides/crm-implementation/). Align role names with your [training plan](/resources/crm-training-plan/).

**Not legal advice.** Involve security, legal, or compliance partners for regulatory interpretation.

---

## How to use

1. Draft an access map (roles × account/contact/deal visibility + export).
2. Confirm SSO/MFA on the **plan you would buy** — not the demo tier.
3. Walk export, email-sync privacy, and audit rows.
4. Assign owners for identity, roles, exports, and access reviews.
5. Fail any must-have row that lacks an owner or evidence.
6. Add FS access-review rows when client books demand them.
7. Re-run after major role, SSO, sync, or integration changes.

**Decision rule:** Do not buy or go live until you can name every role that needs client contact or deal data, what each role can view/edit/export, how email sync visibility works, and how you will review who still has that access after the first quarter.

---

## 1. Identity & SSO/MFA plan gate

| # | Check | Owner | Evidence / notes | Status |
| --- | --- | --- | --- | --- |
| 1.1 | SSO availability confirmed on the **proposed plan** | IT / security | | ☐ |
| 1.2 | MFA expectations documented (SSO and/or app) with exceptions | IT | | ☐ |
| 1.3 | Local / break-glass CRM admin accounts limited, named, monitored | CRM admin | | ☐ |
| 1.4 | Leaver offboarding disables CRM (and tokens/mobile) same day | IT / HR ops | | ☐ |
| 1.5 | Joiner provisioning assigns role from access map (not “copy a peer”) | CRM admin | | ☐ |
| 1.6 | Session timeout / idle policy checked on plan | IT | | ☐ |
| 1.7 | Identity escalation owner named for SSO/MFA incidents | Project lead | | ☐ |

---

## 2. Object visibility & roles

| # | Check | Owner | Evidence / notes | Status |
| --- | --- | --- | --- | --- |
| 2.1 | Access map drafted (roles × accounts / contacts / deals) | Ops + security | | ☐ |
| 2.2 | Production roles listed (AE, manager, admin, CS, read-only) | CRM admin | | ☐ |
| 2.3 | Contact visibility rules tested with persona users | CRM admin | | ☐ |
| 2.4 | Deal / opportunity visibility rules tested (AE vs manager) | CRM admin | | ☐ |
| 2.5 | Account visibility / sharing model documented (coverage, households, multi-client) | Ops | | ☐ |
| 2.6 | Sensitive field limits confirmed on proposed plan | Security | | ☐ |
| 2.7 | Full admin count minimized and justified | Ops lead | | ☐ |
| 2.8 | Persona permission test logged (AE cannot export all; read-only cannot edit) | QA / ops | | ☐ |
| 2.9 | Permission-change approver named for post-go-live role edits | CRM admin | | ☐ |

---

## 3. Exports of contacts & deals

| # | Check | Owner | Evidence / notes | Status |
| --- | --- | --- | --- | --- |
| 3.1 | Who can CSV-export **contacts** defined and minimal | Security + admin | | ☐ |
| 3.2 | Who can CSV-export **deals / pipeline** defined and minimal | Security + admin | | ☐ |
| 3.3 | Export logging / audit of exports checked on plan | Security | | ☐ |
| 3.4 | Contact/deal report & dashboard sharing reviewed (not world-readable) | CRM admin | | ☐ |
| 3.5 | API / integration paths that pull contacts or deals inventoried with owners | IT / admin | | ☐ |
| 3.6 | API keys/tokens owned with rotation/revocation path | IT | | ☐ |
| 3.7 | Migration cutover contact/deal files access-controlled (not open shared drives) | Security / ops | | ☐ |

---

## 4. Email sync privacy

| # | Check | Owner | Evidence / notes | Status |
| --- | --- | --- | --- | --- |
| 4.1 | Email/calendar sync scope documented (metadata vs body, folders, storage) | Ops + security | | ☐ |
| 4.2 | Who can see synced email on contacts/deals defined | Ops + security | | ☐ |
| 4.3 | Sync privacy covered in AE training before mailbox connect | Enablement | | ☐ |
| 4.4 | Disconnect / revoke path tested (user + admin) | CRM admin | | ☐ |
| 4.5 | Activity body / attachment visibility reviewed | Security | | ☐ |

---

## 5. Audit logs & access reviews

| # | Check | Owner | Evidence / notes | Status |
| --- | --- | --- | --- | --- |
| 5.1 | Needed audit events listed (login, permission change, contact/deal export, admin) | Security | | ☐ |
| 5.2 | Audit export format confirmed on plan; sample seen in trial when possible | Security | | ☐ |
| 5.3 | Log retention on plan recorded | Security | | ☐ |
| 5.4 | Access review cadence set with calendar holds | Ops lead | | ☐ |
| 5.5 | Access review owner + signer named | Project lead | | ☐ |
| 5.6 | Anomaly escalation path for unexpected admin or export spikes | Security | | ☐ |
| 5.7 | Post-go-live checklist re-run scheduled (30–90 days) | Implementation lead | | ☐ |

---

## 6. Niche: financial services access reviews

Use when advisor/client-book visibility and export attestations matter. Not a product endorsement.

| # | Check | Owner | Evidence / notes | Status |
| --- | --- | --- | --- | --- |
| 6.1 | Advisor / client-book visibility model documented | Ops + compliance partner | | ☐ |
| 6.2 | Periodic review of who can export client contacts (e.g. quarterly attestation) | Compliance / security | | ☐ |
| 6.3 | Leaver client-book reassignment runbook (contacts/deals + audit trail) | Ops + CRM admin | | ☐ |
| 6.4 | Sample audit pull for client-record access (if required) | Security / compliance | | ☐ |
| 6.5 | Vendor FS-relevant questions asked on plan (field limits, export audit, retention) | Security / legal partner | | ☐ |

---

## Access map (starter)

Copy and fill for **accounts / contacts / deals**:

| Role | Accounts | Contacts | Deals | Export contacts | Export deals | Admin | Notes |
| --- | --- | --- | --- | --- | --- | --- | --- |
| AE | Own + team? | Own + team? | Own + team? | No / limited | No | No | Sync privacy brief before mailbox |
| Manager | Team | Team | Team | Limited | Limited | No | Board coaching from CRM |
| CS | Handoff accounts | Related | Closed-Won / renewals | No | No | No | If CS in scope |
| CRM admin | Org | Org | Org | Yes (logged) | Yes (logged) | Yes | Minimize count |
| Read-only / compliance | As scoped | As scoped | As scoped | No | No | No | |
| Integration / API | As scoped | As scoped | As scoped | As scoped | As scoped | No | Named token owner |

---

## Worked examples

**RIA evaluating finalists:** Before — demos showed “roles” without proving contact field limits, deal export controls, or audit of exports on the quote plan. After — identical checklist questions; a plan gap on export logging surfaced before contract; quarterly FS-style access reviews calendarized before go-live.

**B2B SaaS before cutover:** Before — leavers retained licenses; AEs could export all contacts; email sync visibility unexplained. After — offboarding, contact/deal export permissions, sync privacy in training, and monthly review owners named; go-live waited until must-have rows passed.

---

## FAQ (short)

- **FS-specific CRM required?** Not automatically — verify roles, object visibility, export auditability, and review cadence on the plan you buy; use section 6 when client books demand it.
- **When to run?** Diligence + pre-go-live; again after major identity/role/sync/integration changes.
- **No audit of exports?** Conscious risk acceptance or disqualifier — unread storage is not a control.
- **Training link?** Align role names with the training plan; include sync privacy before AE mailbox connect.

---

*Educational checklist from SoftwareGlimpse. No certification rankings, invented prices, or product endorsements.*
