opsmarshal
Workflow 13 — RevOps Infrastructure

RevOps Data Janitor

Every GTM AI initiative dies on the same rock: the CRM has three records for the same buyer, the MAP disagrees with all of them, and the warehouse trusts none of it. This workflow runs identity resolution, dedupe, and enrichment governance as a continuous, gated, reversible process — the least glamorous agent in the stack, and the one everything else depends on.

At a glance

The RevOps Data Janitor runs identity resolution, deduplication and enrichment governance as a continuous, gated and reversible process, because merges are destructive and every other agent in the stack depends on the records being right. It is one of fifteen workflows in the Enterprise GTM Agent Stack, an Opsmarshal series on GTM stack architecture.

Owned by
RevOps (primary) + Data Eng (escalation)
Writes back to
CRM, MAP, Warehouse identity table, Audit log
Held to
< 0.5% — Wrong-merge rate
Gate
Permission → Evidence → Approval → Audit
Merges are reversible Writes to: CRM, MAP, warehouse Approval: RevOps below 92% confidence
Business Pain

Garbage identity, garbage everything downstream

The status quo

Duplicate contacts split engagement history, so lead scoring undercounts. Company records fragment across legal names, domains, and subsidiaries, so territory rules misfire and attribution double-counts. Quarterly "data cleanup projects" fix a snapshot; the rot resumes Monday.

What this workflow changes

Identity becomes a continuously reconciled graph, not a quarterly project. High-confidence merges execute automatically and reversibly; ambiguous ones queue for a human with the evidence laid out. Enrichment writes obey a field-level authority matrix — no vendor overwrites a human-verified value, ever.

Architecture

Match → adjudicate → gated merge → sync

Inputs
CRM contacts & accountsrecords, field history
MAP databaseleads, activity, consent state
Warehouseproduct users, billing entities
Enrichment vendorsfirmographic + contact data
Agent Layer
Match Agentdeterministic keys first (email, domain), probabilistic second (name+company+geo)
Adjudicatorscores match confidence, assembles evidence for borderline pairs
Field Authority Resolverper-field survivorship: which source wins, with recency and verification rank
Governance
Gate: permission → evidence → approval → audit≥92% confidence auto-merges (reversible) · 70–92% queues to RevOps · <70% no action · consent fields never auto-merged
Systems of Record
CRMgolden record + merge lineage
MAPsynced identity, consent preserved
Warehouse identity tablepersistent IDs for attribution
Audit logevery merge, skip, and reversal
DecisionChoiceRationale
Merges are reversible Full pre-merge snapshots, 90-day unwind window The catastrophic failure of dedupe automation is a wrong merge you can't undo. Reversibility converts a career-ending risk into a Tuesday ticket, which is what lets confidence thresholds be aggressive.
Consent is sacred Opt-out/consent fields excluded from auto-merge Merging an opted-out record into an opted-in one is a compliance incident, not a data quality issue. These fields always route to a human, regardless of match confidence.
Field-level survivorship Authority matrix: human-verified > 1st-party > vendor Record-level "newest wins" destroys curated data. Each field carries a source rank and timestamp; enrichment vendors can fill nulls but never overwrite higher-authority values.
Continuous, not batch Event-driven on record create/update + nightly sweep Quarterly cleanups treat symptoms. Catching a duplicate 30 seconds after form-fill costs one merge; catching it 90 days later costs broken attribution, misrouted leads, and a confused buyer.
Live Demo

Adjudicate a match queue

Three candidate pairs from a real-world-shaped queue. Run the janitor: watch one auto-merge, one route to human review, and one get correctly left alone — with the reasoning logged for each.

Identity Resolution Queue — 3 candidate pairs

Pair A — probable duplicate

rec_0041: priya.sharma@meridianlog.com · Meridian Logistics · VP Ops
rec_2210: p.sharma@meridianlog.com · Meridian Logistics Pvt Ltd · VP Operations

Pair B — ambiguous

rec_0788: j.chen@gmail.com · (no company) · signed up for webinar
rec_1904: james.chen@vertexhealth.com · Vertex Health · Dir. Analytics · opted out

Pair C — lookalike, not a duplicate

rec_0902: a.rao@nimbuspay.com · NimbusPay · CFO
rec_3315: a.rao@nimbuspay.io · NimbusPay Labs · Founder

Governance audit log

[ready] janitor idle — 3 pairs queued
Eval Metrics

What this workflow is held to

< 0.5%
Wrong-merge rate
sampled audits of auto-merges; any wrong merge triggers threshold review
< 2%
Duplicate density
estimated dupes / total records, measured monthly per object
< 60s
Event-to-resolution lag
new record created → identity decision logged
0
Consent-field auto-writes
hard invariant — verified from the audit log, not the config
Operator Control Panel

Someone has to run this thing

Identity automation without an operator console is how CRMs get destroyed at 2 a.m. This spec defines the watch rotation, the alarms, and the undo.

Data Janitor — Ops Console

Owner: RevOps (primary) + Data Eng (escalation)

Daily monitors

  • Review queue depth — 70–92% pairs awaiting adjudication vs. SLO
  • Merge volume anomaly — auto-merges vs. 30-day baseline; spikes usually mean an upstream import, not real dupes
  • Authority violations — vendor writes over higher-rank values; target zero, any hit investigated same day

Weekly / monthly reviews

  • Wrong-merge sample — 25 random auto-merges hand-verified (<0.5% target)
  • Unwind log review — every reversal examined: what did the matcher miss?
  • Monthly threshold recalibration — precision/recall on a labeled sample; thresholds shipped as versioned config

Alert thresholds → who gets paged

  • Consent-field auto-write detected → sev-1, RevOps + compliance, immediately
  • Auto-merge volume >3× baseline in 1 hour → auto-pause merges, page RevOps
  • Review queue breaches SLO 3 days running → RevOps manager (staffing or threshold decision)

Manual controls

  • One-click unwind — any merge, 90-day window, restores both records with lineage intact
  • Domain / entity blocklist — known-tricky hierarchies excluded from probabilistic matching
  • Kill switch — halts all merges and syncs; matching continues in shadow mode so the queue is warm on restart
Failure Modes

How it breaks, and what catches it

Subsidiary collapse

Probabilistic matching merges a parent company with its subsidiary; territory and attribution both break. Mitigation: corporate-hierarchy signals (distinct billing entities, distinct domains, legal suffixes) act as merge blockers, not just score reducers.

Vendor overwrite creep

An enrichment sync misconfigured once quietly overwrites thousands of human-verified titles. Mitigation: field authority matrix enforced at the write layer, not in sync settings — plus a daily diff report of authority-rank violations (target: zero).

Threshold drift

A 92% threshold tuned on last year's data performs differently after an acquisition doubles record volume from a new region. Mitigation: monthly precision/recall recalibration on a labeled sample; thresholds are versioned config with change approval, like code.

Review-queue bankruptcy

The 70–92% queue grows faster than RevOps can clear it; ambiguous pairs rot. Mitigation: queue-depth SLO with alerting; batch-adjudication UI groups similar pairs; sustained overflow auto-raises the review threshold and reports the trade-off.

Opsmarshal builds workflows like this one inside client stacks — see GTM stack architecture and AI enablement and agentic workflows, or book a call to walk through your own.

opsmarshal

Revenue Operations and AI Agentic Workflows for B2B companies in transformation. We build the machine. You run the company.

Services

Company

© 2026 Opsmarshal. All rights reserved. Privacy  ·  Terms