How do I get new sales software through IT approval?
When the head of sales wants to roll out new sales software, the IT and security team often makes the final call. The fastest path to approval: give IT the three things it checks from the start — what data the tool sees, where that data is processed, and how access is technically secured. For LavaLoft that means concretely: EU hosting in Frankfurt, access via OAuth instead of password sharing, data minimization (LavaLoft primarily reads and replaces no CRM), and GDPR-compliant processing. Prepare this security package proactively and you cut approval from weeks to days.
Why IT approval kills deals inside your own company
Modern B2B buying decisions happen in committees: complex purchases involve 6 to 8 people on average (per RAIN Group) — and IT checks security, Legal checks compliance, Finance checks ROI. Even when the head of sales is convinced, IT often blocks the last step: unclear data access, missing GDPR evidence, fear of yet another uncontrolled tool in the stack.
The mistake that stalls your own rollout: going to IT with "we want this tool" — instead of with the answers IT will demand anyway. Anticipate the checklist and you flip the script.
The 7 questions your IT asks — and LavaLoft's starting position
| IT question | What IT wants to hear | LavaLoft's starting position |
|---|---|---|
| What data does the tool see? | Clearly scoped, minimal access | Access to CRM sales data, primarily read — data minimization, not full access |
| Where is the data processed? | EU hosting, GDPR compliance | Processing in the EU (Frankfurt), no data storage outside the EU |
| How does it access the CRM? | No password sharing, revocable | OAuth 2.0 — revocable in the CRM anytime, granular permissions |
| Does it change or replace our CRM? | No disruption of the system of record | No — a control layer over the CRM, primarily reading, replaces nothing |
| Is there a DPA / GDPR record? | Data processing agreement in place | As a German provider: request the DPA and data-protection documentation |
| How does authentication work? | Controlled, team-based access | Team-based access; clarify auth details in the security call |
| What happens on termination? | Clean access removal, data deletion | OAuth connection can be severed; request the deletion concept |
The right-hand cells that say "request" are worded that way on purpose: get these records in writing before approval — a serious vendor delivers them, and IT checks them off.
The three arguments that make IT's decision easy
1. OAuth instead of password sharing
LavaLoft connects to the CRM (e.g. HubSpot, Salesforce, Pipedrive) via OAuth 2.0. That means: no credential sharing, granularly controlled permissions, and access that IT can revoke in the CRM with a single click anytime. That is exactly what any security team wants to hear.
2. EU hosting and data minimization
Processing happens in the EU (Frankfurt) — a core GDPR argument. And because LavaLoft acts as a control layer that primarily reads and does not replace the CRM, the attack surface is small: no second, competing data silo is created.
3. A control layer, not another island tool
The most common IT objection to sales tools is "another system we have to secure." LavaLoft turns that around: it is not another island but a steering layer over the existing infrastructure. For IT that means less sprawl, not more.
How to shorten approval concretely
- Deliver the security package before the first IT meeting — hosting region, OAuth principle, DPA, deletion concept bundled.
- Name the access exactly: primarily read, via OAuth, revocable anytime.
- Remove IT's silo worry: control layer, no CRM replacement, no second data silo.
- Let IT test the access itself — the anytime-revocable OAuth connection builds trust.
Read next: What is an Autonomous Sales Execution Ecosystem? and 86% of all B2B deals stall — how to spot at-risk deals early
Bottom line
IT is not the enemy of your sales rollout but its gatekeeper — and gatekeepers open up for whoever has already answered their questions. Present LavaLoft with EU hosting, OAuth access, data minimization, and requested GDPR records, and you turn a weeks-long review into a formality. The champion who delivers the security package gets the approval — and the deal inside their own company.
About the authors
Matthias Maier and Christopher Ganser are the founders of LavaLoft. Drawing on years of B2B sales experience, including in demanding industries like cybersecurity, they build the Autonomous Sales Execution Ecosystem, the control layer every CRM needs.
The blind spot in your pipeline?
In a demo, see where your sales motion is leaking revenue — and how LavaLoft changes that.
Book a demo