SoftwareGlimpse

CRM resources

Audit templateCRM Security Diligence Pack

CRM Security Checklist

Prove CRM access controls on the plan you would actually buy.

Work through identity, object visibility, contact and deal exports, email-sync privacy, audit evidence, and access reviews — asking each vendor the same questions and confirming answers against the quoted plan, not the demo tier.

Free to use · No email required · Updated 15 Aug 2026

Educational CRM security checklist interface covering SSO and MFA, account, contact and deal visibility, export controls, email-sync privacy, and access-review cadence.
Access model first — visibility, exports, sync privacy, and reviews on the plan you would buy.
Best for
IT / security
Stage
Validate
Time
2–6 hours
Format
XLSX + PDF + MD
  • 44

    checklist items

  • 7

    categories

  • 1

    consistent process across vendors

  • Better decisions

    with less risk and more proof

What's inside

Diagram pairing common CRM security gaps — shared logins, open exports, stale user access — with fixes: SSO and unique accounts, export controls with audit, and recurring role reviews.
Common gaps on the left, the controls this checklist gates on the right.
  • Identity: SSO & MFA

    Plan-scoped SSO, MFA expectations, joiner-leaver paths, and break-glass accounts.

  • Roles & object visibility

    An access map for accounts, contacts, deals, and activities — tested per persona.

  • Export controls

    Who can extract contacts and deals via CSV, reports, or connected apps.

  • Email sync privacy

    What syncs from mailboxes, who can read it on records, and how to disconnect.

  • Audit logs & evidence

    Events you need, retention on your plan, and an export you pulled yourself.

  • Access reviews

    Cadence, inputs, signer, and remediation tracked to closure.

  • Client-book reviews (FS)

    Optional rows for advisor books, export attestations, and leaver reassignment.

What this tool helps you do

  • A written CRM access model

    Roles, object visibility, and sensitive fields are documented rather than assumed.

  • Plan-true identity and export controls

    Every control is confirmed on the commercial plan you would actually buy.

  • Export discipline on contacts and deals

    Who can extract customer and pipeline data is limited, named, and preferably auditable.

  • A review cadence that outlives go-live

    Access reviews have inputs, an owner, a signer, and remediation tracked to closure.

How to use this checklist

Five-stage security workflow: identity, roles, export controls, audit logs, quarterly review.
Identity, roles, export controls, audit logs, then a review you repeat.
  1. 1

    Draft the access map

    Roles against view, edit, export, and admin on accounts, contacts, deals, and activities.

  2. 2

    Identity

    Confirm SSO and MFA on the quoted plan, plus joiner and leaver paths.

  3. 3

    Roles

    Configure least privilege in trial and test visibility as each persona.

  4. 4

    Export controls

    Limit contact and deal extraction, inventory connected apps, and document sync privacy.

  5. 5

    Audit logs

    List the events you need and pull a sample evidence export yourself.

  6. 6

    Access reviews

    Schedule the recurring review with defined inputs, an owner, and a signer.

Preview the checklist

Download Excel

Representative rows from the downloadable artifact. Full workbook includes Test / Scenario, Evidence, and Result columns.

#Check itemWhy it mattersRequired?EvidenceResult
1. Identity: SSO & MFA on the quoted plan
1.1SSO availability confirmed on the quoted planIdentity features shown in demos are frequently sold on a higher tier than the quote.Must-haveNot tested
1.2MFA expectation written“SSO handles it” is not a policy until you name where MFA is enforced.Must-haveNot tested
1.3Joiner and leaver paths definedMost stale CRM access starts with a manual joiner-leaver process nobody owns.Must-haveNot tested
1.4Same-day leaver disablement testedA leaver keeping access to the customer book is the sharpest risk CRM carries.Must-haveNot tested
2. Roles & object visibility
2.1Access map drafted: roles against objectsEverything else in this checklist is guesswork until visibility is written down.Must-haveNot tested
2.2Production role list matches the mapRoles that exist only in production drift away from the design immediately.Must-haveNot tested
2.3Contact visibility tested per personaBroad contact visibility is the most common oversharing default.Must-haveNot tested
2.4Deal visibility tested per personaPipeline amounts are visible to more people than most teams intend.Must-haveNot tested

Worked example

Hypothetical Vendor A / Vendor B scenario for teaching the artifact — not a SoftwareGlimpse case study.

Requirement

Only named roles can export contacts and deals, and exports leave an audit record we can pull on the quoted plan.

  • Vendor A

    PASS

    Export permission was role-scoped in trial, and export events appeared in an audit extract the buyer pulled themselves.

  • Vendor B

    PARTIAL

    Export restriction works, but export audit events are only available on a tier above the quoted plan.

Evidence: Persona test in trial plus a written vendor answer naming the plan on the quote.

What counts as evidence?

Counts

  • Written vendor answer naming the plan on your quote
  • Official documentation for that plan or edition
  • Configuration observed in trial or sandbox (persona test)
  • A sample audit export you pulled yourself
  • A runbook that has been tested at least once

Does not count

  • Compliance badge or trust-page logo
  • Sales assurance with no plan scope
  • A control demonstrated on a higher tier than you would buy
  • Roadmap commitment
  • “Your data is stored securely” with no control named

Related resource journey

FAQ

How is this different from the evaluation checklist?

The evaluation checklist keeps light gates — can a seller do admin actions, is SSO needed, how much admin effort is there. This checklist is the deeper pass: a written access map, plan-scoped identity answers, export controls on contacts and deals, sync privacy, audit evidence you pulled yourself, and a review cadence.

Is this legal or compliance advice?

No. It is an operational checklist for evaluating and running CRM access controls. Bring in your security, legal, or compliance partners for regulatory interpretation, particularly for the client-book section.

When should we run it?

During validation, sending identical questions to every finalist, and again as a pre-go-live gate. Re-run it after changes to SSO, the role model, email sync, or integrations.

What if a vendor cannot audit contact and deal exports?

Record it as a gap with an owner and a compensating control, or treat it as a disqualifier based on your access map. Note the answer next to the plan on your quote — unread storage is not a control.

Do we need a financial-services-specific CRM?

Not automatically. Many teams meet their needs with a general CRM that supports roles, sharing rules, export controls, and auditability, plus disciplined process. Use the client-book section when advisor visibility and export attestations matter, and verify each answer with the vendor and your own owners.

How does this relate to the training plan?

Training teaches people how to work contacts and deals; this checklist decides what they can see, export, and reveal through mailbox sync. Keep role names identical across both so the curriculum matches least privilege.

Ready to use the CRM Security Checklist?

Download the artifact, or continue with a related tool or guide.

SoftwareGlimpse Updates

Want clearer software shortlists? Get buying guides and comparisons by email.

Newsletter coming soon.