Pulse ← Trainings
Sales Trainings · CRM ownership
✓ Machine Certified10/10?

When should sales operations own the CRM versus IT — and what's the handoff model?

📖 1,087 words⏱ 5 min read4/29/2024

TL;DR

SalesOps owns what the CRM does for revenue (process, fields, automation, reports, adoption); IT owns how the platform runs (identity, security, compliance, infrastructure, integrations, recovery). The handoff is at the data-and-API boundary, codified in a one-page RACI that names humans, governed by a weekly/monthly/quarterly cadence.

Without this, the predictable failure modes — shadow admin culture, six-week field tickets, and unowned integration outages — show up on schedule.

Direct Answer

Sales operations should own the day-to-day CRM business model — process design, pipeline stages, fields, layouts, automation, reports, adoption — while IT owns the platform contract — identity, security, compliance, infrastructure, integration governance, and disaster recovery. The handoff is at the data-and-API boundary: SalesOps decides what data must exist and how it flows to drive revenue; IT decides how that data is provisioned, encrypted, audited, and connected to the rest of the enterprise.

Anything genuinely shared belongs to both, with one named human accountable in writing.

Primary references. Salesforce Well-Architected (https://architect.salesforce.com/well-architected/overview), Center of Excellence decision guide (https://architect.salesforce.com/decision-guides/coe), permission set groups (https://help.salesforce.com/s/articleView?id=sf.perm_sets_groups_overview.htm), and the Salesforce Trust site (https://trust.salesforce.com/) for compliance attestations.

NIST CSF 2.0 (https://www.nist.gov/cyberframework), ISO/IEC 27001 Annex A (https://www.iso.org/standard/27001), CIS Controls v8 (https://www.cisecurity.org/controls), and OWASP API Security Top 10 (https://owasp.org/API-Security/) cover the IT side. DAMA-DMBOK (https://www.dama.org/cpages/body-of-knowledge) supplies the data-governance vocabulary.

Gartner CRM strategy (https://www.gartner.com/en/sales/insights/crm-strategy), Forrester Wave for SFA (https://www.forrester.com/research/), and Salesforce State of Sales (https://www.salesforce.com/resources/research-reports/state-of-sales/) supply the quantified evidence: 30-40% higher three-year value retention, 8-10× deployment frequency, 3-4× more tickets per admin, and roughly half the change-failure rate in fusion-team orgs.

Platform-agnostic. Microsoft Dynamics 365 (https://learn.microsoft.com/en-us/power-platform/admin/admin-documentation) and HubSpot (https://knowledge.hubspot.com/account-security) follow the same pattern with platform-specific primitives.

Related Pulse entries: /knowledge/q14 (RevOps charter), /knowledge/q34 (RevOps tooling stack), /knowledge/q41 (Salesforce admin RACI), /knowledge/q56 (forecast cadence), /knowledge/q63 (incident response for revenue systems), /knowledge/q88 (CRM data governance), /knowledge/q119 (sandbox strategy), /knowledge/q145 (data classification), /knowledge/q172 (integration platform), /knowledge/q198 (audit-readiness), /knowledge/q207 (change management), /knowledge/q241 (vendor security review).

Bull Case

SalesOps owns the Opportunity object — stages, probabilities, required fields, validation, dashboards. IT owns the org — SSO (Okta/Entra), MFA, IP allowlists, permission set groups, sandbox refresh, DevOps Center pipeline (https://help.salesforce.com/s/articleView?id=sf.devops_center_overview.htm), backup vendor, audit log retention.

SalesOps requests a new field through the joint backlog; IT security-reviews within the week; sandbox-to-prod ships in 3-5 days with automated tests. MTTD on security regressions <24h, MTTR on compliance findings <5 days, forecast accuracy >85%, admin headcount efficient because work is correctly routed at intake.

Bear Case (three concrete failure modes)

  1. SalesOps owns everything including security. Symptoms: profile sprawl, View All Data on every admin, no MFA on sandbox users, hard-coded API user, no audit log review. Outcome: SOC 2 or HIPAA findings, emergency platform lockdown freezing revenue ops for a quarter, board-level remediation. SANS guidance (https://www.sans.org/white-papers/) flags this as the most common Tier-1 finding in mid-market SaaS audits. Cost: $300K-$1.5M plus six months distraction.
  1. IT owns everything including business configuration. Symptoms: six-week field tickets, parallel spreadsheets, forecast accuracy <70%, CRO loses confidence. Outcome: 12-18 month trust-rebuild, often a CRM replacement RFP costing millions that rarely solves the organizational problem. McKinsey RevOps research (https://www.mckinsey.com/capabilities/growth-marketing-and-sales/our-insights) documents this in roughly a third of mid-market deployments.
  1. Split ownership with no written RACI. Concrete: a Pavilion-to-Salesforce sync drops leads Friday afternoon. SalesOps thinks IT owns it; IT thinks SalesOps owns it. Three days pass before paging; 1,200 leads stale. The CMO asks who is accountable; no documented answer exists. Outcome: handoff failure at the worst moment, plus a permanent confidence tax. Fix: name humans not roles, publish the runbook before the incident.

Risk Register (sample)

RiskLikelihoodImpactOwnerMitigation
Shadow admin grants Modify AllMediumHighIT Platform LeadQuarterly profile audit, Setup Audit Trail review
Integration outage with no on-callMediumHighIntegration EngineerSynthetic monitoring + named on-call rotation
Forecast accuracy <70%MediumHighSalesOps DirectorMonthly forecast variance review
SOC 2 finding on access controlLowCriticalIT Platform LeadPermission set groups + least-privilege review
Sandbox refresh breaks staged releaseMediumMediumDevOps LeadDocumented refresh cadence + sandbox tier strategy

Antipatterns (detection signals)

Regulated-industry overlays

Org-size scaling

Operator Playbook (30/60/90)

Days 1-30. One-page RACI naming humans. Integration inventory with named owners. Weekly 30-minute SalesOps/IT sync.

Days 31-60. Run Salesforce Optimizer and Security Health Check; close top ten findings jointly. Migrate profiles to permission set groups. Document change pipeline (sandbox tiers, deployment cadence, rollback).

Days 61-90. Monthly CRM health review and quarterly architecture review tied to GTM plan. Publish runbook for top-five incident classes. Measure MTTD/MTTR/deploy frequency; report quarterly to executive team.

Decision tree

  1. Changes how revenue is recognized, forecasted, or reported? SalesOps leads.
  2. Changes who can access what, or how data leaves the platform? IT leads.
  3. Both? Joint architecture review, single named owner, written decision log.

See /knowledge/q14 and /knowledge/q88 for templates.

Download:
Was this helpful?  
Sources cited
bvp.comhttps://www.bvp.com/atlas/state-of-the-cloud-2026news.crunchbase.comhttps://news.crunchbase.com/salesforce.comhttps://www.salesforce.com/products/sales-cloud/salesforce.comhttps://www.salesforce.com/products/einstein/joinpavilion.comhttps://www.joinpavilion.com/compensation-reportbridgegroupinc.comhttps://www.bridgegroupinc.com/blog/sales-development-report
⌬ Apply this in PULSE
Free CRM · Revenue IntelligenceAudit pipeline, score reps, ship the fixGross Profit CalculatorModel margin per deal, per rep, per territory
Deep dive · related in the library
revops · conversation-intelligenceWhat replaces call recording if AI agents auto-summarize calls?cybersecurity · consultingHow do you start a SMB cybersecurity consulting business in 2027?revops · governanceHow should RevOps teams think about governance philosophy as a leading indicator of go-to-market maturity and expansion readiness, separate from operational compliance requirements?snowflake · data-regionsWhat is Snowflake data-region strategy through 2027?oneveracity · kycHow'd you fix OneVeracity's revenue issues in 2026?mercury · fintechHow'd you fix Mercury's revenue issues in 2026?security-review · complianceWhat's the right way to handle Security review with limited resources?DPA · GDPRWhat's the playbook for staying ahead of procurement's data processing addendum (DPA) delay tactic?security-pricing · complianceHow do I price a security/compliance feature — bundled or upsell?security-reviews · it-alignmentHow do I handle a security review that looks like it'll kill the deal?
More from the library
CRO · chief-revenue-officerWhat are the must-have skill sets for a Chief Revenue Officer in 2027?CRO · chief-revenue-officerHow does a CRO partner with the CFO on bookings, ARR, and revenue translation in 2027?veterinary-clinic · small-animal-vetHow do you start a veterinary clinic in 2027?skilled-nursing · snfHow do you start a skilled nursing facility business in 2027?sales-compensation · revopsHow do you measure whether a rep comp redesign actually improved deal quality vs just hitting revenue number through the same old discounting behavior?revops · operating-modelWhat's the right operating model for deciding whether your company should be in acquisition mode or retention mode — who owns that call, and how often should it flip?CRO · chief-revenue-officerWhat AI tools should every Chief Revenue Officer actually deploy in their stack in 2027?revops · discount-governanceHow does the discount governance readiness model shift if a company has already hired a Sales Manager without a VP Sales above them — does that middle layer change when you need a VP Sales?mini-golf · putt-puttHow do you start a mini-golf venue business in 2027?escape-room · entertainment-venueHow do you start an escape room business in 2027?revops · ae-compensationHow do quantum computing startups structure their AE comp plans?starting-a-business · funeral-homeHow do you start a funeral home business in 2027?chiropractic · chiropractorHow do you start a chiropractic practice in 2027?