Define what this Outreach migration owns
This page owns the complete exit and cutover artifact. It does not repeat the Outreach CRM sync test, which validates integration truth; Outreach versus Salesloft, which selects between vendors; or the sales engagement platform guide, which builds a shortlist. The migration begins after the destination decision and ends only when retained evidence proves the new system is correct, rollback is closed deliberately, and the old environment is decommissioned under policy.
Write the decision charter: source instance, destination environments, business units, countries, data classes, legal holds, owners, contract end, last safe export date, final-send time, freeze, cutover, rollback window, retention, deletion, and acceptance signatories. Identify CRM, identity provider, email, calendar, dialer, meeting, warehouse, consent master, archiving, and BI dependencies.
Gangly did not execute an Outreach migration or inspect a customer tenant. This is a documentation-informed buyer checklist. Live product behavior, plan entitlements, API access, support timing, export scope, and destination import behavior require buyer testing and written confirmation.
Freeze scope, contract rights, and retention deadlines
Open the order form, master agreement, data-processing terms, support plan, API terms, renewal notice, post-termination clauses, retention policy, legal-hold instructions, and deletion commitments. Ask: who may request exports; which methods and formats are included; field, attachment, recording, and history scope; rate and volume limits; assistance cost; request lead time; download window; encryption; post-service access; deletion schedule; and certificate or ticket evidence.
Outreach’s current one-time export documentation describes Data Sharing, API, reports, and an admin-requested raw compressed JSON export with named tables. It says the delivered download link lasts 12 hours and former-customer instance data is deleted 60 days after services conclude. Reconfirm those details in the signed contract and support ticket; do not schedule the migration on a web-page promise alone.
Outreach’s retention documentation says configured deletion can permanently remove email data and related reporting. Freeze and document retention settings before evidence disappears. Qualified privacy, security, and legal owners must decide what may be transferred, retained, deleted, or held; this checklist is not legal advice.
Inventory every governed Outreach asset
Create one row per asset class with source count, owner, authority, export method, key, relationships, destination, required history, retention, sensitivity, test, and status. Inventory:
- Identity and access: users, roles, profiles, teams, duties, permissions, SSO, service accounts, API clients, webhooks, tokens, inactive users, and ownership queues.
- Communication endpoints: mailboxes, aliases, calendars, phone numbers, dialer settings, call purposes, meeting settings, recording state, and provider IDs.
- People and companies: prospects, accounts, opportunities, personas, stages, tags, email/phone values, CRM IDs, parent-child links, opportunity roles, owners, and custom fields.
- Content and orchestration: sequences, steps, rulesets, templates, snippets, content categories, variables, schedules, task priorities, smart views, and validation rules.
- Work and evidence: active enrollments, tasks, mailings, activities, recipients, events, calls, meetings, recordings, notes, outcomes, replies, failures, opt-outs, suppression, consent source/time/scope, audit logs, and reporting extracts.
Do not equate “listed in an export table” with “portable into the destination.” Derived scores, reports, relationships, rich content, attachments, recordings, configuration semantics, audit trails, and sequence execution state may require separate extraction or may not round-trip. Label every unknown undocumented—vendor/contract confirmation required.
Build the source-to-destination asset crosswalk
For each source object and field, record source table/field, business meaning, source ID, parent and relationship keys, type, allowed values, null meaning, time zone, encoding, destination object/field, transformation, authority, collision rule, history rule, retention, evidence, and owner. Version this crosswalk and require approval for changes.
| Source artifact | Destination contract | Hard question |
|---|---|---|
| Prospect/account | Stable source ID plus CRM ID; field-level mapping | How are duplicates and missing parents quarantined? |
| Active sequence enrollment | Explicit complete, cancel, or restart decision | Can step position and wait time be represented safely? |
| Email/call/meeting history | Immutable archive or governed destination activity | Are recipients, timestamps, outcome, content, and attachments retained? |
| Suppression/consent | Strongest stop state with source, time, scope, basis | Can any import, retry, or automation weaken it? |
| Template/sequence content | Versioned content plus variable and schedule mapping | Which syntax or automation semantics cannot translate? |
Link narrower destination tests where useful. For a Salesloft destination, the Salesloft cadence migration test covers target-specific cadence behavior. The generic CRM migration checklist covers CRM source-of-truth changes; do not let this platform exit overwrite authoritative CRM data.
Export immutable source evidence
Take three classes of evidence: configuration and inventory before change; a full baseline export; and a final delta at freeze. Preserve raw files unchanged in approved encrypted storage. Record request, administrator, method, parameters, time zone, source watermark, delivery time, checksums, byte size, row counts, schema, errors, exclusions, and support ticket. Parse into working copies, never the originals.
Request the vendor’s current data dictionary and relationship model. Compare the promised tables with files received. Inspect empty, missing, truncated, duplicated, and malformed tables; null versus absent values; timestamp precision; deleted/inactive records; HTML and Unicode; attachments and recordings; and ID stability. Sample source UI records against raw export before transforming.
Outreach’s documented one-time export includes many relevant tables such as users, roles, prospects, sequences, templates, snippets, tasks, events, mailbox contacts, recipients, opportunities, and rulesets, but the published list is not a promise that every buyer-required artifact or semantic relationship is present. Request missing needs explicitly and test the actual delivered schema.
NIST’s data-integrity guidance treats database records, configurations, applications, and customer data as assets requiring protection from modification and destruction. It is a control reference, not a certification of this migration.
Stop active work and freeze the delta
Build an active-work register before stopping anything: enrolled prospect, sequence/version, current step, next due time, mailbox/user, open task, reply state, meeting, account/opportunity, suppression, owner, CRM ID, and disposition. Ban new sequence enrollment and content/config changes at the announced freeze. Decide per person: complete in Outreach, cancel with no transfer, or transfer under an approved destination step.
Do not recreate pending automated messages without human review. A wait period, local send window, thread context, reply state, bounce, opt-out, or owner change may make the next touch unsafe. Freeze a final delta after all permitted source activity settles, then reconcile it to the baseline using immutable IDs.
Disconnect endpoints only after active state and history are captured. Outreach’s calendar documentation says removal can take hours. Its mailbox documentation warns historical data is removed when mailboxes are deleted. Verify live behavior and preserve required evidence first.
Migrate a golden set before bulk data
Choose a stratified golden set across regions, teams, active/inactive users, common and custom fields, parent/subsidiary accounts, duplicate people, nulls, long text, Unicode, different sequence versions, active/completed/cancelled states, replies, bounces, tasks, calls, meetings, notes, CRM associations, suppressed people, consent variants, and retained/deleted content. Use synthetic cases for dangerous actions.
For every case, store expected destination value, relationship, history, owner, allowed transformation, prohibited side effect, and evidence path. Import identities and parents first, then people/accounts, governed state, content, relationships, history, and only finally approved active work. Disable sends and workflow triggers throughout the test.
Test permission boundaries, deprovisioned owners, missing parents, invalid picklists, duplicate IDs, partial batches, API limits, retry, outage, and replay. A successful import job is insufficient; compare business state and verify zero prohibited outreach.
Reconcile counts, fields, relationships, and history
Run a full outer reconciliation by stable source ID and approved destination ID. Report source-only, destination-only, matched/equal, matched/different, duplicate, quarantined, transformed-as-approved, and excluded-with-reason. Keep four denominators:
- Record reconciliation = accepted equal or approved-transformed records ÷ eligible source records.
- Field fidelity = correct required field values ÷ eligible required field values.
- Relationship reconciliation = correct required parent/child or event/recipient links ÷ eligible required links.
- History completeness = required historical events present once with required metadata ÷ eligible source events.
- Duplicate rate = unintended extra destination records ÷ eligible source records.
- Suppression preservation = correctly non-actionable suppressed people ÷ eligible suppressed people.
Break results down by object, team, region, owner status, date range, and sensitive state. Use the CRM data-quality guide to assign ongoing correction authority. Never “fix” source data inside migration code without a logged rule and preserved original.
Dual-run, cut over, and rehearse rollback
Dual-run a bounded team with one system authorized to send. The other remains shadow-only. Compare daily enrollments, task state, sent/replied/bounced outcomes, meetings, CRM activities, owner changes, and suppression. Do not allow two platforms to contact the same person.
Write a minute-by-minute cutover runbook: final stop, delta export, checksum, transform, import order, reconciliation, endpoint authorization, smoke tests, approval, monitoring, incident channel, and go/no-go. Hard gates include zero prohibited sends, complete suppression, accepted reconciliation, correct permissions, stable CRM IDs, visible failures, and tested endpoint behavior.
Rollback is not “turn Outreach back on.” Preserve source configuration and licenses for the approved window; define which destination actions must stop; export the destination delta; reconcile replies, meetings, owner changes, consent, and CRM writes; reimport only approved state; and prevent duplicates. Rehearse with the golden set before production.
Decommission with deletion evidence
After sign-off, revoke API clients, webhooks, service identities, SSO assignments, tokens, mailbox/calendar/dialer access, exports, support access, warehouse shares, and automation. Archive approved configuration, raw exports, mappings, checksums, reconciliation, incidents, approvals, and required audit history under the retention policy.
Open the contract-required deletion request and track instance, backups, subprocessors, recordings, exports, and support artifacts as applicable. Outreach’s privacy compliance documentation describes access/deletion request processes but does not replace the customer’s contract, legal-hold, or proof requirements. Retain the ticket, vendor response, scope, completion date, exceptions, and internal verification.
Close rollback only after the destination survives the agreed observation window and every material exception has an owner. Record residual archive access, retention expiration, and destruction owner. A cancelled license without deletion and evidence is not a completed migration.
Apply acceptance gates to the worked example
This fictional arithmetic is not Outreach performance. An exit contains 2,000 eligible master records, 800 required relationships, and 5,000 required historical events. The destination has 1,970 accepted records, 780 correct relationships, and 4,800 complete events. Ten unintended duplicates are found. All 120 suppressed prospects remain non-actionable.
| Measure | Calculation | Result |
|---|---|---|
| Record reconciliation | 1,970 ÷ 2,000 | 98.5% |
| Relationship reconciliation | 780 ÷ 800 | 97.5% |
| History completeness | 4,800 ÷ 5,000 | 96% |
| Duplicate rate | 10 ÷ 2,000 | 0.5% |
| Suppression preservation | 120 ÷ 120 | 100% |
If precommitted gates require 100% critical relationships, zero unintended duplicates, 99.5% required history, and 100% suppression, this run fails despite perfect suppression. Quarantine the destination, correct the mapping/import behavior, rerun the same golden and bulk sets, and retain both reports. Never relax a gate after seeing the result without a named risk acceptance.
Use the printable checklist and calculate TCO
| Checklist item | Owner | Required evidence | Status |
|---|---|---|---|
| Contract, export, retention, deletion, and hold terms frozen | Procurement/legal/security | Signed terms and support confirmations | □ |
| All identities, endpoints, records, content, work, history, and suppression inventoried | RevOps/data | Versioned inventory with counts | □ |
| Source-to-destination crosswalk approved | Data owners | Mapping, transformations, keys, exceptions | □ |
| Raw baseline and delta exports preserved | Data/security | Checksums, schema, tickets, access log | □ |
| Active sequences stopped and every enrollment disposed | Sales/RevOps | Active-work register and approval | □ |
| Golden set and failures pass | QA/RevOps | Expected-versus-actual report | □ |
| Bulk records, fields, relationships, history, and suppression reconcile | Data/business owners | Signed reconciliation and exceptions | □ |
| Dual-run, cutover, and rollback rehearsed | Program owner | Runbook logs and go/no-go | □ |
| Access revoked and deletion evidence retained | IT/security/privacy | Revocation log and vendor confirmation | □ |
Migration TCO = destination license and implementation + source overlap + export/support + engineering and transformation + validation and reconciliation + training/change management + monitoring + incident reserve + archive/retention + decommission/deletion + exit contingency. A fictional transition with $30,000 overlap, $25,000 implementation, $18,000 engineering, $12,000 validation, $8,000 training, $5,000 archive/decommission, and $7,000 contingency has $105,000 migration TCO. Replace every input with signed quotes and loaded labor.
The final acceptance packet should name versions, dates, counts, exclusions, undocumented portability, contract dependencies, reconciled exceptions, rollback result, deletion state, TCO, and signatories. That packet—not a vendor logo change—is the evidence that the Outreach migration completed safely.