Practical, field-tested guidance for managing third-party vendor and partner integrations against a CRM + SSO platform.
I'm Stephanie Dlatt, an Implementation Specialist working on Salesforce architecture: integrations, single sign-on, data migrations, and the security and permission design that decides whether a connector is trustworthy or a liability.
This playbook is a generalized version of process documentation I built over several years handling third-party vendor onboarding, security provisioning, incident response, and partner communication. It's written to be useful to anyone doing similar work against a CRM platform (Salesforce or otherwise) with an SSO layer in front of it, regardless of employer or specific tooling.
A note on genericization: every page here has been deliberately stripped of employer-specific product names, internal tooling, real client and vendor names, and any architecture detail specific to a particular company's systems. What's left is the reusable methodology: the decision frameworks, the escalation philosophy, the security posture, and the communication patterns. Where an example is needed, it uses generic placeholder names.
More background on how I think about this work: Portfolio | LinkedIn
| Page | What it covers |
|---|---|
| Vendor Onboarding | Granting a client-selected, non-partner vendor access to developer resources, with proper consent and recordkeeping. |
| Custom Application Requests | How to respond when a parent organization or local branch wants to connect a custom-built or independent-developer app, including ready-to-use messaging templates. |
| Third-Party Integrator Security Playbook | The full framework for provisioning, scoping, and securing third-party API access: the responsibility line, OAuth flow selection, least-privilege permissioning, and escalation philosophy. |
| Configuring an API-Only Integration User | Step-by-step Salesforce configuration reference for the API-only integration user license type. Pairs with the security playbook above. |
| Vendor and Integration Offboarding | Fully terminating a vendor's access when a client relationship ends: deactivation, token revocation, and closing every layer, not just the login. |
| Incident Runbook: Org Suspended or Disabled | What to do when a client's CRM production environment gets locked, most often a billing issue, and how to safely bring integrations back online afterward. |
| Responding to an API Limit Alert | Identifying and resolving runaway API consumption before it takes an entire org offline. |
| Partner Communication Templates | Reusable email templates for partner onboarding, OAuth troubleshooting, permission errors, overconsumption notices, and support case redirects. |
| Identity Keys vs. Record Keys | Why an SSO integration needs two identifiers, one to authenticate and one to match records, and why email should never be either. |
| Runbook: Records Missing from an Incremental Sync | Diagnosing records that never sync and never error, and fixing them safely without tripping automation or API limits. |
Fill-in documents that put the playbook into practice.
| Template | Use it for |
|---|---|
| Integration Scope Document | Scoping a third-party integration field by field before anything is provisioned: approvals, auth, data scope, identifiers, responsibilities, cutover. |
| Scoped Working Session Agenda | Turning "can we hop on a call?" into a focused session, with the invitation, agenda, and same-day recap. |
Reusable Claude skills built on the same methodology, ready to install and adapt.
| Skill | What it does |
|---|---|
| explain-the-why | Drafts replies that explain a technical fix so the colleague can handle it themselves next time. |
| wikijs-page-draft | Drafts publish-ready Wiki.js pages for internal wikis or external developer docs. |
| integrator-access-review | Reviews a vendor access request against least-privilege gate checks and drafts the reply. |
This work is licensed under a Creative Commons Attribution 4.0 International License. Use it, adapt it, build on it, just credit where it came from.