A CRM integration is a business process with software in the middle. A successful API response is not enough if no person owns the new lead, duplicates pile up or a retry creates a second job.
1. Define the source and minimum fields
- List each source: website form, call, ad lead, chat, referral or order.
- Record the fields the source actually supplies and which are required.
- Keep consent and channel permission separate from basic contact identity.
- Do not ask for data that the next step does not need.
2. Define identity and duplicate rules
- Choose how phone, email, company, address, deal and order IDs are normalized.
- Decide when to update an existing contact and when to create a new record.
- Preserve provider IDs and source timestamps for readback.
- Route ambiguous matches to a person instead of silently merging them.
3. Assign the next business step
| Question | Decision to record |
|---|---|
| Who owns a new valid enquiry? | Named role or queue, with fallback |
| How soon should the first action happen? | Target based on operating hours and capacity |
| What stops automation? | Reply, opt-out, invalid data, booked step or manual hold |
| What counts as progress? | Accepted, contacted, qualified, estimate held, sold |
| What needs human review? | Duplicate, conflict, failed delivery or unclear identity |
4. Plan failures and retries
Use an idempotency key or equivalent control so the same request can be retried without creating a duplicate. A changed payload with the same key should fail visibly. Define timeouts, non-retryable errors and a manual queue.
5. Protect consent and channel boundaries
Contact capture does not authorize every channel. Store the basis and status for SMS, email or other messages separately and stop workflows when the applicable opt-out or do-not-disturb state applies.
6. Test the business behavior
- New valid contact and enquiry.
- Returning contact with a valid open opportunity.
- Duplicate click or repeat webhook.
- Same-key retry and changed-payload conflict.
- Malformed or partial provider response.
- Timeout and later safe retry.
- Validation failure followed by corrected input.
- Success reset and a second independent submission.
- Manual hold for an ambiguous match.
- Readback from the destination system.
During QA, intercept the final submission and block analytics or advertising transports. A mocked UI success proves the interface state only; it does not prove CRM capture, notification delivery or an observed inbox message.
Turn the checklist into a bounded scope
Start with one source, one target and one outcome. Add more routes only after the base flow has explicit acceptance evidence and a human exception path.