Review CRM access in sales tools: Map CRM connection accounts, objects and field mappings before live use; Check both read and write permissions for users and automated processes; Confirm data visibility and sync behaviour with controlled test data
Image: Sales Development Guide

SDR Operations

Part of Sales development tools

Reviewing sales tool access to CRM data

Map what a sales tool reads and writes in the CRM, check user visibility and plan how to revoke access.

Map what a sales tool’s CRM connection reads and writes, then check what users can see inside the tool. A successful sign-in does not establish that the data scope or permissions suit the intended work. Complete this review before importing live contacts or enabling writes to the CRM.

Map the data path

Record the CRM, tool, connection account, objects and mapped fields. Separate data entering the tool from activity or corrections flowing back. Include automated jobs, exports and administrator access.

LayerReview question
Connection identityWhich account authorises access, and who controls it?
CRM permissionsWhich objects and fields can that account read or change?
Sync configurationWhich records and mapped fields move in each direction?
Tool permissionsWhat can an ordinary user view, edit or export?
ExitHow are access, sync and retained data handled when the connection ends?

Ask why each permission is needed. A pilot using leads and contact activity does not automatically need all opportunity fields or a historical export.

Data Path Review Process

  1. Identify the connection account and its control ownerDetermine which CRM account authorises access
  2. Review CRM object and field permissions for that accountMap what data the account can read or modify
  3. Document sync configuration for both directionsList records and fields synced from CRM to tool and vice versa
  4. Assess tool-level user permissionsCheck what ordinary users can view, edit or export
  5. Plan exit strategy for connection terminationDefine how access, sync and retained data are handled post-decommissioning

Compare the documented integration models

Outreach with Salesforce uses a Salesforce system user and configurable object and field mappings. Outreach documents an optional feature that can bring Salesforce field permissions into Outreach for supported, mapped fields.

Its guidance says this requires CRM sync to be configured and the relevant objects to be pre-mapped, and that field-level governance applies only to supported objects and mapped fields. Review the connection account and Outreach user profiles together. Do not assume a CRM field restriction governs every view or export in the connected system.

LinkedIn Sales Navigator CRM Sync is documented as integrating Sales Navigator with your CRM, with features that include auto-save, activity writeback, ROI reporting, CRM badges and search filtering. LinkedIn says selected activities can be written back. This may suit CRM-linked profile research, but its data path is broader than a single contact lookup.

Ask which records and optional uses are enabled. Confirm the contractual and operational offboarding steps for your deployment. CRM integration is documented for Advanced Plus users.

These descriptions show what the vendors document, not what is enabled or safe in a particular account.

Outreach vs LinkedIn Sales Navigator CRM Integration Models

Integration Type
Outreach with Salesforce
Connection Account
Salesforce system user
Field-Level Security
Applies only to supported objects and mapped fields; optional feature
Activity Writeback
Yes, for selected activities
CRM Sync Requirement
Must be configured and objects pre-mapped
Integration Type
LinkedIn Sales Navigator CRM Sync
Connection Account
Linked to Sales Navigator account
Field-Level Security
Not explicitly documented; broader data path
Activity Writeback
Selected activities can be written back
CRM Sync Requirement
Enabled for Advanced Plus users only

Check visibility and writes

Use a non-production or otherwise controlled dataset where possible. Include records with different owners, field permissions and stop states. Ask an ordinary representative to inspect the same records in the CRM and the tool.

Change a mapped value and a restricted value, then inspect each direction of sync. Check exports separately. Record observed states, not just settings screenshots.

A connection account may need more rights than a representative. If the tool receives data through that account, verify that its own controls limit representative access. Change a CRM permission and remove a test user to see what remains visible and when access changes take effect. These are proposed checks; neither vendor’s behaviour was tested for this article.

Before approval, name who can revoke the connection, stop sync, recover from an unintended write and request return or deletion of imported data. Where the Australian Privacy Principles apply, personal information collection must meet the relevant necessity requirements and information held must be protected by reasonable steps. Approve only the access required for the documented purpose and configuration.

More from SDR Operations