CRM System 120A further includes Authentication Logic 320 configured to authenticate a source of a customer service request, e.g., to authenticate Access Device 110A. Authentication Logic 320 is configured for this task by including logic to, for example, receive a customer service request from Access Device 110A, determine that the customer service request may require access to secure customer data, send a authentication request for digital identification data to Access Device 110A, receive the requested digital identification data and forward the digital identification data to GateKeeper 125. As discussed elsewhere herein, GateKeeper 125 is configured to ratify the digital identification data by comparing the received digital identification data and previously stored customer authentication data, and based on this comparison approve or disallow the authentication of Access Device 110A. The authentication is typically associated with a particular account and secure customer data within that account. In some embodiments, Access Device 110A must have previously been registered as an authorized access device for the particular account. If the authentication is approved, the approval is communicated to Authentication Logic 320.