Confirm that a merge is appropriate
Published September 10, 2026.
Two records with similar names are not automatically duplicates. Compare verified contact details, account identifiers, organization relationships, active orders, and consent settings. If the evidence conflicts, pause the merge and route the case to the system owner.
Protect access and customer history
Choose the surviving record under a written rule. Inventory open cases, credits, subscriptions, saved addresses, permissions, and communication preferences before making a change. Never expand one person's access simply because another profile is being retired.
Record the source and destination identifiers, the fields moved, the operator, and the completion time. Keep an approved recovery path for mistaken merges. A short permission review helps teams catch access risks before they become incidents.
Use the NIST Digital Identity Guidelines as security context, and align handoffs with the customer authentication workflow.
Close the loop
Check that open work, customer promises, and notification settings still appear correctly. Tell the customer what changed without exposing internal identifiers or another person's data. Sample completed merges monthly for missing history, duplicate entitlements, and repeat contacts.
FAQ
Should agents merge records when identity evidence is incomplete?
No. Preserve both records and escalate through the documented identity and data-quality path.
What is the minimum audit note?
Record why the records qualified, what moved, who approved the action, and how the result was checked.
