Separate proof states interact without becoming the same action
Creation, draft editing, publication, workflow connection, enrollment, sending, and delivery must be reported separately. Update/Publish changes the live email asset; workflow enrollment and action execution cause delivery. Publishing does not replay a completed send, but an enabled workflow can use the new version for contacts still waiting before that action, newly enrolled contacts, or contacts legitimately re-enrolled later.
Brad's review preference
When Brad requests specific edits, prepare and verify the pending revision. Publication is included only when Brad approves it and the connected-workflow interlock passes. An OFF workflow cannot send merely because the email is published. If a connected workflow is ON, pause/isolate it or obtain explicit approval for the exact contacts who may still reach the send action.
Standing safety boundary
- Publishing does not create or activate a workflow, enroll contacts, replay a completed action, or resend prior recipients by itself.
- Contacts who already passed the email action are not resent merely because the email is updated.
- In an ON workflow, contacts waiting before the action, newly enrolled contacts, or legitimately re-enrolled contacts can receive the latest published version when execution reaches that action.
- In an OFF workflow, publication alone does not trigger a send; still verify the workflow remains OFF and campaign counters do not change.
- Publication approval is not blanket production-send approval.
- Pause/isolate first when an ON workflow has unresolved waiting or re-enrollment exposure; publish second, verify counters third, and separately approve launch.
- Test emails are real sends and require the exact recipient approval.
- Credential, subscription, finance, and destructive actions require separate approval.
Navigation standard for integrated pages
Brad–Sterling2 uses one top-level left-navigation entry per operating area. Subsections live in the wrapped top tab bar and deep-link through hashes such as #emails, #qa, and #learning.
Two-place protocol maintenance
Every verified HubSpot finding updates both the baseline instructions everywhere they are affected and a dated, newest-first record in the Learning tab. Neither update is complete by itself.
Function-level reconciliation binds names, IDs, execution states, and proof
Session evidence from July 29 through August 3 was reconciled across campaigns, automated email, publication, workflows, enrollment, audiences, permissions, files, CTAs, forms/pages, behavioral tracking, testing, sends, delivery, incident learning, and manual UI handoffs. The durable rule is to organize every action under its HubSpot function and bind display names to immutable IDs plus dated live proof.
Contradictions corrected
Forward-looking and canonical examples now start at Email 1 and continue 2, 3, 4 without zero padding. Legacy “Email 00/01” wording remains only where it is necessary to preserve July 30 incident and live-object history, and is labeled historical.
Object relationship
Campaign groups attribution; segment/list defines who qualifies; workflow owns execution; email is the versioned asset; enrollment puts a contact into the graph; campaign-run and recipient events prove send and delivery.
Approval boundary
Documentation may be edited and deployed. Publishing an email, enabling/pausing a workflow, enrolling contacts, changing credentials, mutating customer data, or sending requires its own explicit authority.
Proof standard
Read immutable object IDs, draft/live state, workflow graph and enabled state, list definition and counts, enrollment record, campaign-run IDs, and recipient outcomes separately. A name, 200 response, scope count, or ON toggle is not enough.
Failure modes
Renaming a label without remapping action IDs can make the visible sequence disagree with execution order. Publishing inside an enabled workflow can expose waiting or re-enrolled contacts. A test run can be mistaken for production when campaign IDs are not decomposed.
Source and date
Historical facts are sourced to Brad/Sterling session evidence and live-readback summaries dated July 29–August 3, 2026. Portal counts, enabled states, campaign metrics, and credential grants are time-sensitive and must be refreshed before action.
Publishing updates the email asset; workflow execution causes delivery
While renumbering the initial announcement from 0 to 1, Brad stopped at HubSpot’s “Publish your email updates” modal. The modal states: “Any workflows using this email will get this latest version.” That is an asset-version update—not a send-now or re-enrollment command.
Workflow OFF
Publishing the revision does not trigger a send. Verify the workflow remains OFF and that no new campaign-run counters appear.
Workflow ON
Publishing still does not replay the action. Contacts waiting before the action, newly enrolled contacts, or contacts legitimately re-enrolled later can receive the latest version when the workflow executes that step.
Already received
Contacts who already completed that email action do not receive it again merely because the email is republished.
What can resend
Re-enrollment, manual enrollment, a duplicated/new send action, or another workflow path can create a second send. Publishing alone does not.
Permanent control
Classify publish state, workflow state, contact position, enrollment/re-enrollment, and campaign-run changes separately. Keep ON workflows paused or isolated when waiting-contact exposure is unresolved.
Sequence convention
Email positions begin at 1 and continue 2, 3, 4… without zero padding. Renaming 0 to 1 is metadata-only and does not itself send.
Workflow descriptions contradicted live state and overstated interest automation
The enabled nurture was described as inactive; eight disabled one-time click classifiers were called “inactive behavior trackers”; and the prior Protocols page listed property values that did not match live actions.
Live truth
One nurture ON, eight click classifiers OFF, one manual test OFF. Historical legacy Email 00’s independent dynamic segment contained 11 contacts while its field-writing workflow never ran.
Impact
Operators could infer inactivity logic, completed CRM categorization, or follow-up behavior that did not exist.
Root cause
Purpose, enabled state, event evidence, property mutation and downstream communication were collapsed into vague labels.
Permanent correction
Descriptions must state exact trigger, asset/URL, occurrence model, fields/values, segment, waits, effects, deduplication, tier/API boundary and state. Behavioral follow-up is a separate layer.
Current-key scopes were not the complete Service-Key-linked catalog
This entry distinguishes what Sterling currently has from everything HubSpot documents as an available scope.
What Brad requested
A full listing of every HubSpot API ability relevant to the Account Service Key—not only the permissions already granted.
What Sterling first published
The first API Permissions release contained all 93 active current-key scopes and 17 observed unavailable scopes. That was a complete current-key inventory but not the complete official catalog.
What the official review found
HubSpot's current Service-Key-linked scope catalog contains 148 active rows. HubSpot documents no REST endpoint that enumerates the scopes selectable for Account Service Keys; key-specific selection must be verified in the authenticated UI. The reconciliation also found 20 current-key active scopes absent from the catalog's active table, so UI and documentation evidence must remain separate.
Impact
The launch matrix was operationally usable, but the permission-upgrade view undercounted cataloged possibilities and could have made the audit appear more exhaustive than it was.
Root cause
“Complete current key” and “complete credential-type catalog” were not labeled as separate inventories.
Permanent correction
Permissions documentation now maintains three layers: full official catalog, exact current-key grants, and live portal-specific availability. They are reconciled but never collapsed.
Broad API access did not equal launch-complete capability
This entry records why draft-authoring access and a large scope count did not establish end-to-end launch authority.
What Brad expected
Sterling should know before execution which HubSpot steps can be completed through the current key and which steps Brad must perform manually.
What Sterling assumed
Broad Service Key coverage plus proven draft creation/editing was treated as a reasonable indicator that adjacent final actions—especially email publication—would also be available.
What HubSpot actually requires
Scope, endpoint writability, commercial entitlement, credential type, UI exposure, and Brad's approval are independent gates. Draft CRUD uses content; publish/unpublish uses a separate gate. Campaign hs_owner is read-only even with Campaign write access.
Impact
Brad's manual steps were discovered during execution instead of being declared at campaign preflight, creating avoidable uncertainty around launch readiness.
Root cause
The earlier capability model was scope-centered rather than operation-centered. It did not require a launch matrix for every final action.
Permanent correction
The API Permissions tab is now a launch-control artifact. Every preflight identifies technical capability, entitlement, approval authority, manual owner, proof status, and fallback.
Campaign owner is readable but not writable through the Campaign API
This entry records the difference between a visible Campaign property and an API-writable Campaign property.
What Brad requested
Assign Brad Stevens as campaign owner and establish a repeatable owner/start/end-date standard for future campaigns.
What Sterling assumed
Because Campaign readback exposed hs_owner, Sterling initially assumed the same property could be updated through the Campaign PATCH endpoint.
What HubSpot actually did
HubSpot returned HTTP 400 and identified hs_owner as forbidden/read-only for Campaign updates. The endpoint separately confirmed hs_start_date and hs_end_date are writable.
Impact
The updater stopped after the first rejection. Zero owners were changed, no partial bulk update occurred, and the before-state inventory was preserved.
Root cause
Readability was incorrectly treated as write capability. Capability must be proven per property and per operation—not inferred from a successful GET.
Permanent correction
For each new campaign, set dates through the supported Campaign API and assign Brad through an authenticated HubSpot UI session. Read back owner and dates before completion.
Owner and campaign-date convention
- Owner: Brad Stevens at
brad@outsourceaccess.com; verify the active owner record. - Start date: the verified campaign creation/launch date in HubSpot's account timezone.
- End date: the actual scheduled date of the final campaign email or action, calculated from delays, allowed weekdays/times, blocked dates, and timezone.
- If the schedule changes, update and verify the end date.
- Do not retroactively bulk-change historical campaigns without separate approval.
Publishing historical legacy Email 00 released the existing-client production audience
This record preserves the failure mechanism, impact, and permanent operating correction. It is a reference point for future HubSpot work—not a replacement for refreshing live workflow and audience state.
What Brad intended
Brad opened the saved historical legacy Email 00 revision, confirmed the nomenclature and the intentional dashboard/walkthrough GIFs, and clicked Update believing he was applying content edits to the automated email.
What Sterling believed
Sterling incorrectly applied the blanket rule that publishing an automated-email revision was content-only and would not send, activate a workflow, or enroll contacts.
What the live configuration actually was
The production workflow was already enabled, historical legacy Email 00 was its first send action, and the populated production audience was already attached. Eligible or pending contacts therefore existed behind the editing action.
What happened
At approximately 1:31 PM ET, Update/Publish made the revised automated email current and immediately coincided with a new production campaign run. HubSpot delivered historical legacy Email 00 to 187 production recipients. With the earlier one-recipient controlled test, HubSpot displayed 188 aggregate sends and deliveries.
Failure
Sterling advised Brad that Update would not trigger the campaign and failed to pause/isolate the connected workflow or prove a no-send state before publication. The error was in the operating guidance and safety gate—not in Brad's interpretation of the editor.
Observed campaign detail
The production run reported 187 delivered, 34 dropped, and 2 deferred. At the verification checkpoint it also showed 46 opens and 10 clicks. Engagement totals are time-sensitive; the send/delivery event is the durable incident fact.
Connected-workflow pre-publish interlock
- Identify the exact automated email ID and every workflow that references it.
- Read each workflow's enabled state, action graph, delays, time window, suppressions, goals, and exit behavior.
- Read the attached audience/list by immutable ID; verify visible, eligible, suppressed, enrolled, queued, and pending counts separately.
- If any connected workflow is ON, pause/isolate it or establish a verified no-send state before Update/Publish—unless Brad explicitly approves the exact audience release.
- Publish only the approved revision.
- Immediately read the live email, workflow state, enrollment history, and every new campaign-run ID.
- Require zero unintended counter changes before calling the edit safe. Launch remains a separate approval.
Proof language going forward
- Draft saved — pending editor revision exists.
- Published — live revision updated.
- Workflow ON/OFF — execution permission state.
- Eligible / enrolled / pending — audience execution states.
- Sent / delivered / dropped / deferred — campaign-run outcomes.
Learning-log and baseline standard
Every future entry records date/time, intended action, Sterling's prior model, actual behavior, impact, root cause, corrected control, proof, and owner. Entries are newest-first with immutable IDs. The same finding must also correct every affected baseline tab, checklist, decision table, diagram, and skill reference.
How HubSpot campaign execution fits together
Attribution umbrella→Segment
Who qualifies→Workflow
Trigger, timing, logic→Email / CTA / Form
Customer interaction→Contact fields
Durable CRM state→Reports
Behavior and outcome
What each HubSpot element means
| Element | Definition | It does not… |
|---|---|---|
| Automation | HubSpot’s top-level capability/navigation area for automated execution. | Represent one independently named campaign object. |
| Campaign | Attribution/reporting umbrella with separately managed owner, start date, end date, notes, goals, and associated assets. Owner is currently UI-assigned; dates are API-writable. | Infer owner/dates from email activity or control audience eligibility, delays, or sends. |
| Segment / List | Rule-based or static population defining inclusion, exclusion, suppression, or behavioral interest. | Send an email by itself. |
| Workflow | Executable logic owning enrollment, delays, branching, actions, field changes, suppression, and exit behavior. | Prove an email was delivered merely because it is active. |
| Marketing email | One recipient-facing message at a defined sequence position. | Authorize its own audience or send. |
| Form | Captures a request, registration, preference, qualification, or conversion event. | Replace the workflow that processes the submission. |
| Landing page | Destination for one campaign promise or conversion action. | Become a campaign merely because campaign parameters are present. |
| CTA | Tracked call-to-action object with a defined destination and purpose. | Serve as proof of conversion without downstream evidence. |
| Contact property | Durable CRM field storing status, source, score, preference, or last-known state. | Preserve multiple interests when designed as a single overwriteable value. |
| Report / Dashboard | Answers a measurement question or groups related measurements. | Change execution state. |
Campaign ownership
A campaign groups the assets and reporting for one initiative. It should include the relevant emails, pages, forms, CTAs, files, and reports, while the workflow independently controls execution.
Segment ownership
Use separate segments for source audiences, production audiences, suppressions, status populations, and durable interest behavior. A source system such as Apollo is a dimension—not the audience’s identity.
What lives inside what
This is an operating map—not a claim that HubSpot stores every object as a literal child. Solid containment shows true internal structure; dashed boundaries show campaign association or workflow references.
Function-by-function If/Then map
Each row states the purpose, object relationship, approval boundary, proof, and common failure mode. Examples are practical operating patterns, not permission to change live HubSpot state.
| HubSpot function | If / Then Outsource Access example | Object relationship | Approval and proof | Failure mode |
|---|---|---|---|---|
| Campaign | If OA launches a Client Command Center adoption initiative, then create one campaign umbrella with Brad as owner and dated start/end boundaries. | Associates emails, pages, CTAs, forms, files, and reporting; does not control sends. | Creation requires approved scope. Prove campaign ID, owner, dates, and associations. Owner assignment remains UI-verified under July 30 evidence. | Reporting association is mistaken for enrollment or execution. |
| Marketing email | If Email 1 announces the Client Command Center, then draft, QA, and publish that exact automated-email ID only after the workflow interlock passes. | Versioned asset referenced by a workflow send action. | Draft work and publication are separate gates. Prove AUTOMATED_EMAIL type, live timestamp, semantic content, media, and links. | Draft is called live, or publication is treated as harmless while waiting contacts can reach the action. |
| Workflow | If Email 2 should follow after three days, then verify action order by immutable email ID, delay, weekday window, exits, suppression, and re-enrollment. | Owns trigger, enrollment, timing, branches, property writes, and send actions. | Build, enable, pause, reorder, or edit each require exact authorization. Prove graph revision, enabled state, and before/after action IDs. | Visible labels are renumbered but action references still point to the prior sequence. |
| Audience / segment | If OA wants existing clients only, then define inclusion, suppression, valid-email, marketable, opt-out, and bounce rules before release. | Feeds enrollment eligibility; a list alone does not send. | Brad approves immutable list ID and expected eligible count. Prove definition, total, email-bearing, suppressed, eligible, enrolled, and pending counts separately. | A friendly list name is trusted while its definition or membership changed. |
| Forms, pages, CTAs, files | If a GIF and button promise a dashboard walkthrough, then both must point to the same uniquely verified destination and use durable HubSpot-hosted media. | Conversion assets feed tracked events and campaign attribution. | Content/link changes require approval. Prove file MIME/animation, element-to-destination matrix, unique page marker, form/CTA ID, and rendered output. | A homepage fallback returns 200 for a missing path, or an old CTA destination survives a copy update. |
| Behavioral automation | If a known contact clicks a proposal calculator link, then record the exact event, wait, exit on reply/meeting/opt-out, and send only an approved follow-up. | Event → segment/property evidence → workflow decision → governed action. | Tracking may be read-only; property writes and follow-up sends are separately gated. Prove exact URL predicate, internal property values, re-enrollment, deduplication, and outcome. | Any-link click is mislabeled as topic intent, or a multi-select property is overwritten. |
| Testing and QA | If Brad approves a test to one controlled inbox, then use the exact email/version and recipient without enrolling the production audience. | Test campaign-run is separate from production workflow execution. | Recipient approval is required. Prove live/draft semantic parity, inbox render, links, GIF animation, campaign-run ID, and zero unrelated counters. | One test delivery is reported as a production launch. |
| Send and delivery | If the production audience is approved and enrolled, then reconcile selected, enrolled, sent, delivered, dropped, deferred, suppressed, and pending states. | Enrollment executes workflow; send creates provider events; delivery is a later outcome. | Exact audience, timing, content, and consequence require approval. Prove per-run IDs and timestamps after activation. | Workflow ON, enrollment, send, and delivery are collapsed into “launched.” |
Source basis: verified Brad/Sterling session history and HubSpot readbacks dated July 29–August 3, 2026; reconciled August 4, 2026. Refresh every time-sensitive portal fact before action.
Every launch action passes five independent gates
Granted→Endpoint
Writable→Entitlement
Tier/add-on→Approval
Authorized→Proof
Read back
A failure at any gate blocks the action. See API permissions for the object-by-object matrix.
API permissions, entitlement, approval, and manual handoffs
This tab records what July 30, 2026 evidence proved for Service Key 47206867, what is merely documented, what is blocked by the current key or HubSpot plan, what requires Brad's approval, and what Brad must do manually.
Brad's current critical manual steps
- Campaign owner: select Brad Stevens in HubSpot UI. The Campaign API makes
hs_ownerread-only. - Automated email publication: use Review and publish in HubSpot UI. The current Service Key does not have
marketing-email, and API publish/unpublish is separately entitlement-gated. - CTA authoring: create/edit/publish CTAs in UI until a write scope and endpoint are proven.
- HubSpot report/dashboard construction: use the UI; no current cataloged API scope documents creating or editing HubSpot analytics reports or dashboards.
- Credential, app, user, or permission administration: approve the exact change; HubSpot UI/MFA may require Brad or a super admin.
Execution matrix
| Architecture element / action | Relevant scope or surface | Sterling today | Technical / approval gate | Brad manual action |
|---|---|---|---|---|
| Campaign — create, name, notes, status, audience | marketing.campaigns.write | Yes — documented and scope active | Create/update allowed; deletion remains destructive and approval-gated. | None for ordinary creation after campaign approval. |
| Campaign owner | marketing.campaigns.read + crm.objects.owners.read | Read only | HubSpot documents hs_owner as a read-only Campaign property. More Campaign scope will not make it writable. | Brad selects Brad Stevens in HubSpot UI, or Sterling uses an authenticated UI session after explicit approval. |
| Campaign start and end dates | marketing.campaigns.write | Yes — API writable | Use YYYY-MM-DD; derive end date from the actual final scheduled action. | None. Brad approves the schedule; Sterling writes and verifies the dates. |
| Campaign asset association and reporting | marketing.campaigns.write / .read / .revenue.read | Read proven; write documented | Association is attribution metadata, not enrollment or sending. | Only if a specific association endpoint fails its canary. |
| Segments / lists | crm.lists.read + crm.lists.write | Read proven; create/update available | Final audience definition, suppression and release remain approval-gated. | No technical step; Brad approves the exact list and exclusions. |
| Contacts and campaign properties | crm.objects.contacts.read/write + schema scopes | Technically available | Live customer-data mutation requires explicit approval. | None when the exact mutation is approved. |
| Marketing email — create, clone, edit draft | content | Yes — read/create/edit proven | Draft write does not publish, send or prove the live revision changed. | Brad reviews content; no technical editor step is required. |
| Marketing email — publish / unpublish | marketing-email OR transactional-email | No with current key | marketing-email is unavailable on this Service Key. HubSpot also requires Marketing Hub Enterprise or the Transactional Email add-on for API publish/unpublish. | Brad must use Review and publish in HubSpot UI until both entitlement and a supported credential route are verified. |
| Regular marketing email — schedule / send | marketing-email | No with current key | Final send is distinct from draft authoring; recipients, sender, time and copy require approval. | Brad completes the supported UI send/schedule unless a separately approved API path is proven. |
| Automated email — workflow delivery | automation after the email is published | Yes, technically, after publication | Workflow enablement/enrollment can release recipients; exact audience approval is mandatory. | Brad currently publishes the email; Sterling may activate/enroll only under explicit launch approval. |
| Workflow — read, build and edit | automation | Read proven; create/update previously proven | Editing an active workflow or connected email is send-adjacent. | No technical step; Brad approves live execution changes. |
| Workflow — activate, deactivate, enroll | automation | Technically available | Activation and enrollment are guarded live-customer actions. | None after Brad approves exact workflow, audience and timing; manual UI remains fallback. |
| Sequences | automation.sequences.read + enrollments.write | Read and enrollment available; authoring blocked | automation.sequences.write is unavailable on the current Service Key. | Brad authors/edits the sequence in UI; approved enrollment may be automated. |
| Files and email media | files + forms-uploaded-files | Read proven; upload previously proven | Public asset use and replacement still require content approval. | None for ordinary approved uploads. |
| Forms | forms | Read proven; create/update/delete documented | One broad forms scope covers definitions. external_integrations.forms.access is WordPress-plugin-specific, not the general Forms API scope. | No required manual build step after approval; run one harmless write canary before first production mutation. |
| CTAs | ctas.read | Read only | No CTA write scope is active on this key. | Brad creates/edits/publishes CTAs until a supported write scope and endpoint are proven. |
| Landing pages / site pages | content | Read proven; create/edit/publish/schedule documented | Current page endpoints accept cataloged content. The separate content.landing_pages.write appears in endpoint security but not the current scope catalog. | No required manual publication after approval; run an exact-operation canary before first production use. |
| Owners, users and permissions | crm.objects.owners.read + crm.objects.users.read | Read only | User creation, permission changes and account administration are not granted. | Brad or a HubSpot super admin performs user and permission administration. |
| Subscription preferences | communication_preferences.read | Read only | No preference-write scope is active; recipient consent cannot be overridden. | Recipients manage preferences; Brad/admin manages subscription-type configuration. |
| Analytics, campaign revenue and email metrics | marketing.campaigns.read / revenue.read / content | Read/reporting available by surface | Campaign metrics and revenue are read-only APIs. No current cataloged scope documents creating/editing HubSpot reports or dashboards. | Brad builds or edits native HubSpot reports/dashboards in UI; Sterling can retrieve proven API metrics. |
| Social publishing | social | Unavailable | social is unavailable on the current Service Key and public posting remains approval-gated. | Brad uses HubSpot/social UI unless a separately approved social integration is established. |
| Transactional email | transactional-email | Unavailable | Requires the Transactional Email add-on and is not a marketing-nurture workaround. | Use ordinary marketing-email UI for nurture; transactional capability requires a separate business case and approval. |
| Webhooks, UI extensions, custom workflow actions | Project-based app capabilities | Not supported by Service Keys | HubSpot states Service Keys are REST-only and cannot authenticate webhooks or UI extensions. | Brad must approve creation/installation of a project-based app or OAuth/static-token integration. |
| Change Service Key scopes / create another credential | Development → Keys / Projects | Possible only with credential approval | Credential changes alter blast radius and may require app install/reinstall. | Brad approves exact scopes, key/app type and account; UI/MFA may require Brad. |
Could additional permission solve the blocked items?
| Blocked capability | Would more scope solve it? | Safest next path |
|---|---|---|
| Campaign owner | No. hs_owner is documented read-only. | Keep UI assignment in campaign creation. |
| Email publish/unpublish | Possibly, but not by scope alone. It requires an accepted publication scope plus Marketing Hub Enterprise or the Transactional Email add-on. | Verify product tier first; then evaluate an isolated app/static-token or OAuth route. Keep UI publication as the immediate path. |
| Sequence authoring | Possibly. automation.sequences.write was unavailable on this key. | Verify entitlement and app-based scope exposure before changing credentials. |
| CTAs | Potentially. Current key has read only; a supported write scope/endpoint must be verified. | Keep CTA authoring manual until proven. |
| Pages and forms | Already documented through active scopes. content and forms cover the relevant writes. | Run one harmless exact-operation canary before first production mutation; no new scope is presumed necessary. |
| Webhooks / UI extensions / custom workflow actions | No through a Service Key. | Create a project-based HubSpot app after explicit approval. |
Complete active Service Key inventory
Captured from the authenticated Service Key detail page July 27, 2026; live read surfaces were reprobed July 30. Expand each group to see every active scope.
CRM — contacts, companies, deals, leads, owners and users (16) — 16
crm.objects.companies.highly_sensitive.readcrm.objects.companies.readcrm.objects.companies.sensitive.readcrm.objects.companies.writecrm.objects.contacts.highly_sensitive.readcrm.objects.contacts.readcrm.objects.contacts.sensitive.readcrm.objects.contacts.writecrm.objects.deals.highly_sensitive.readcrm.objects.deals.readcrm.objects.deals.sensitive.readcrm.objects.deals.writecrm.objects.leads.readcrm.objects.leads.writecrm.objects.owners.readcrm.objects.users.readCRM — lists, export, schemas and custom data (16) — 16
crm.exportcrm.lists.readcrm.lists.writecrm.objects.custom.highly_sensitive.readcrm.objects.custom.readcrm.objects.custom.sensitive.readcrm.schemas.companies.readcrm.schemas.companies.writecrm.schemas.contacts.readcrm.schemas.contacts.writecrm.schemas.contracts.readcrm.schemas.custom.readcrm.schemas.deals.readcrm.schemas.deals.writecrm.schemas.projects.readcrm.schemas.services.readOperations — pipelines, projects, forecasting and activity (14) — 14
crm.extensions_calling_transcripts.readcrm.objects.appointments.readcrm.objects.contracts.readcrm.objects.feedback_submissions.readcrm.objects.forecasts.readcrm.objects.goals.readcrm.objects.goals.writecrm.objects.listings.readcrm.objects.projects.readcrm.objects.projects.writecrm.objects.services.readcrm.pipelines.approval.readcrm.pipelines.governance.readcrm.pipelines.stage_permissions.readCommerce — billing, invoices, payments, products and subscriptions (17) — 17
commerce.payment_links.readcrm.objects.carts.readcrm.objects.commercepayments.readcrm.objects.invoices.readcrm.objects.invoices.writecrm.objects.line_items.readcrm.objects.line_items.writecrm.objects.orders.readcrm.objects.products.readcrm.objects.quotes.readcrm.objects.subscriptions.readcrm.schemas.commercepayments.readcrm.schemas.invoices.readcrm.schemas.line_items.readcrm.schemas.orders.readcrm.schemas.quotes.readcrm.schemas.subscriptions.readMarketing — campaigns, events, forms, CTAs, content and files (13) — 13
contentcrm.objects.marketing_events.readcrm.objects.marketing_events.writectas.readexternal_integrations.forms.accessfilesformsforms-uploaded-filesmarketing.aeo.readmarketing.campaigns.readmarketing.campaigns.revenue.readmarketing.campaigns.writerecord_images.signed_urls.readAutomation — workflows and sequences (3) — 3
automationautomation.sequences.enrollments.writeautomation.sequences.readService Hub — tickets and conversations (6) — 6
conversations.custom_channels.readconversations.readconversations.writeticketstickets.highly_sensitivetickets.sensitiveCMS — domains and knowledge base (3) — 3
cms.domains.readcms.knowledge_base.articles.readcms.knowledge_base.settings.readPreferences, settings and security (3) — 3
communication_preferences.readsettings.currencies.readsettings.security.security_health.readPlatform, OAuth and meetings (2) — 2
oauthscheduler.meetings.meeting-link.readFull official Service-Key-linked scope catalog — 148 rows
This is the complete active scope table HubSpot links from its Account Service Key documentation as of July 30, 2026. “Cataloged” does not prove selectable for this portal, granted to this key, entitled by the account, or sufficient for an endpoint.
Open the complete 148-scope comparison
| Official scope | Current-key status | HubSpot description / entitlement |
|---|---|---|
account-info.security.read | Not granted / selector not re-audited | Includes access to account activity logs and other account security information. Available to all accounts. |
analytics.behavioral_events.send | Not granted / selector not re-audited | Includes access to send custom event occurrences. Available to Professional or Enterprise accounts only. |
automation | Active on current key | Grants access to create and retrieve custom workflow actions, and usage of the v4 workflow APIs. Available to Professional or Enterprise accounts only. |
automation.sequences.enrollments.write | Active on current key | Enroll contacts in a sequence. Available to Sales Hub or Service Hub Professional or Enterprise accounts only. |
automation.sequences.read | Active on current key | View details about sequences. Available to Sales Hub or Service Hub Professional or Enterprise accounts only. |
behavioral_events.event_definitions.read_write | Not granted / selector not re-audited | Create, read, update, or delete custom events. This includes behavioral event properties. Marketing Hub Enterprise accounts only. |
business_units_view.read | Observed unavailable | View brand data, including logo information. Note that the brands functionality is the successor to business units. Available to accounts with the Brands Add-on only. |
business-intelligence | Observed unavailable | Grants access to the legacy v2 reporting endpoints. Available to all accounts. |
cms.domains.read | Active on current key | List connected domains in an account. Available to all accounts. |
cms.domains.write | Not granted / selector not re-audited | Create, update, and delete connected domains. Available to all accounts. |
cms.functions.read | Not granted / selector not re-audited | View all Content Hub serverless functions, any related secrets, and function execution results. Available to Content Hub Enterprise accounts only. |
cms.functions.write | Not granted / selector not re-audited | Grants access to write Content Hub serverless functions and secrets. Available to Content Hub Enterprise accounts only. |
cms.knowledge_base.articles.read | Active on current key | View details about knowledge articles using the GraphQL API. Available to Service Hub Professional or Enterprise accounts only. |
cms.membership.access_groups.read | Not granted / selector not re-audited | View membership access groups and their definitions. Available to Service Hub or Content Hub Professional or Enterprise accounts only. |
cms.membership.access_groups.write | Not granted / selector not re-audited | Create, edit, and delete membership access groups. Available to Service Hub or Content Hub Professional or Enterprise accounts only. |
collector.graphql_query.execute | Not granted / selector not re-audited | Query data from your HubSpot account using the GraphQL API endpoint Available to CMS Hub Professional or Enterprise accounts only. |
collector.graphql_schema.read | Not granted / selector not re-audited | Perform introspection queries via GraphQL application clients such as GraphiQL. Available to CMS Hub Professional or Enterprise accounts only. |
communication_preferences.read | Active on current key | View details of your contacts' subscription preferences. Available to all accounts. |
communication_preferences.read_write | Not granted / selector not re-audited | Provides access to subscribe or unsubscribe contacts to your subscription types, as well as retrieve subscription preferences for your contacts. Available to all accounts. |
communication_preferences.statuses.batch.read | Observed unavailable | Allows you to batch retrieve contacts based on their subscription status. Available to Marketing Hub Enterprise accounts only. |
communication_preferences.statuses.batch.write | Not granted / selector not re-audited | Allows you to batch update the subscription status of multiple contacts. Available to Marketing Hub Enterprise accounts only. |
communication_preferences.write | Not granted / selector not re-audited | Subscribe or unsubscribe contacts to your subscription types. Available to all accounts. |
content | Active on current key | Grants access to content APIs, including website pages, landing pages, marketing email, and blog APIs. Available to CMS Hub Professional or Enterprise, or Marketing Hub Professional or Enterprise accounts only. |
conversations.read | Active on current key | View details about actors, messages, and threads in help desk and the conversations inbox. Available to all accounts. |
conversations.visitor_identification.tokens.create | Not granted / selector not re-audited | Fetch identification tokens for authenticated website visitors interacting with the HubSpot chat widget. Available to Professional or Enterprise accounts only. |
conversations.write | Active on current key | Create and manage threads and messages in the conversations inbox. Available to all accounts. |
conversations.custom_channels.read | Active on current key | View details about custom channels for connected inboxes and help desk. Available to Sales Hub or Service Hub Enterprise accounts only. |
conversations.custom_channels.write | Not granted / selector not re-audited | Manage custom channels for connected inboxes and help desk. Available to Sales Hub or Service Hub Enterprise accounts only. |
crm.export | Active on current key | Export records from your CRM for all CRM data types. Available to all accounts. |
crm.import | Not granted / selector not re-audited | Allows you to import records into your CRM. This includes creating new records or modifying any of your existing records for all CRM data types (contacts, companies, deals, tickets, etc). Available to all accounts. |
crm.dealsplits.read_write | Not granted / selector not re-audited | Create or retrieve deal splits on a deal. Available to Sales Hub Enterprise accounts only. |
crm.lists.read | Active on current key | View details about contact lists. Available to all accounts. |
crm.lists.write | Active on current key | Create, delete, or make changes to contact lists. Available to all accounts. |
crm.objects.appointments.read | Active on current key | View properties and other details about appointments. Available to all accounts. |
crm.objects.appointments.sensitive.read | Not granted / selector not re-audited | View Sensitive Data properties for appointments. Available to Enterprise accounts only. |
crm.objects.appointments.sensitive.write | Not granted / selector not re-audited | Edit Sensitive Data properties and values for appointments. Available to Enterprise accounts only. |
crm.objects.appointments.write | Not granted / selector not re-audited | Create, delete, or make changes to appointments. Available to all accounts. |
crm.objects.carts.read | Active on current key | View properties and other details about carts. Available to all accounts. |
crm.objects.carts.write | Not granted / selector not re-audited | Create, delete, or make changes to carts. Available to all accounts. |
crm.objects.commercepayments.read | Active on current key | View details about commerce payments. Available to Starter accounts only. |
crm.objects.companies.highly_sensitive.read | Active on current key | View Highly Sensitive Data properties for companies. Available to Enterprise accounts only. |
crm.objects.companies.highly_sensitive.write | Not granted / selector not re-audited | Edit Highly Sensitive Data properties and values for companies. Available to Enterprise accounts only. |
crm.objects.companies.read | Active on current key | View properties and other details about companies. Available to all accounts. |
crm.objects.companies.sensitive.read | Active on current key | View Sensitive Data properties for companies. Available to Enterprise accounts only. |
crm.objects.companies.sensitive.write | Not granted / selector not re-audited | Edit Sensitive Data properties and values for companies. Available to Enterprise accounts only. |
crm.objects.companies.write | Active on current key | View properties and create, delete, or make changes to companies. Available to all accounts. |
crm.objects.contacts.highly_sensitive.read | Active on current key | View Highly Sensitive Data properties for contacts. Available to Enterprise accounts only. |
crm.objects.contacts.highly_sensitive.write | Not granted / selector not re-audited | Edit Highly Sensitive Data properties and values for contacts. Available to Enterprise accounts only. |
crm.objects.contacts.read | Active on current key | View properties and other details about contacts. Available to all accounts. |
crm.objects.contacts.sensitive.read | Active on current key | View Sensitive Data properties for contacts. Available to Enterprise accounts only. |
crm.objects.contacts.sensitive.write | Not granted / selector not re-audited | Edit Sensitive Data properties and values for contacts. Available to Enterprise accounts only. |
crm.objects.contacts.write | Active on current key | Create, delete, and make changes to contacts. Available to all accounts. |
crm.objects.courses.read | Not granted / selector not re-audited | View details about courses. Available to all accounts. |
crm.objects.courses.write | Not granted / selector not re-audited | Create, delete, or make changes to courses. Available to all accounts. |
crm.objects.custom.highly_sensitive.read | Active on current key | View Highly Sensitive Data properties for custom objects. Available to Enterprise accounts only. |
crm.objects.custom.highly_sensitive.write | Not granted / selector not re-audited | Edit Highly Sensitive Data properties and values for custom objects. Available to Enterprise accounts only. |
crm.objects.custom.read | Active on current key | View details about custom objects. Available to Enterprise accounts only. |
crm.objects.custom.sensitive.read | Active on current key | View Sensitive Data properties for custom objects. Available to Enterprise accounts only. |
crm.objects.custom.sensitive.write | Not granted / selector not re-audited | Edit Sensitive Data properties and values for custom objects. Available to Enterprise accounts only. |
crm.objects.custom.write | Not granted / selector not re-audited | Create, delete, or make changes to custom objects. Available to Enterprise accounts only. |
crm.objects.deals.highly_sensitive.read | Active on current key | View Highly Sensitive Data properties for deals. Available to Enterprise accounts only. |
crm.objects.deals.highly_sensitive.write | Not granted / selector not re-audited | Edit Highly Sensitive Data properties and values for deals. Available to Enterprise accounts only. |
crm.objects.deals.read | Active on current key | View properties and other details about deals. Available to all accounts. |
crm.objects.deals.sensitive.read | Active on current key | View Sensitive Data properties for deals. Available to Enterprise accounts only. |
crm.objects.deals.sensitive.write | Not granted / selector not re-audited | Edit Sensitive Data properties and values for deals. Available to Enterprise accounts only. |
crm.objects.deals.write | Active on current key | Create, delete, or make changes to deals. Available to all accounts. |
crm.objects.feedback_submission.read | Not granted / selector not re-audited | View details about submissions to any of your feedback surveys. Available to Service Hub Professional or Enterprise accounts only. |
crm.objects.goals.read | Active on current key | View all goals. Available to Sales Hub Starter, Professional, or Enterprise accounts only. |
crm.objects.invoices.read | Active on current key | View details about invoices. Available to all accounts. |
crm.objects.leads.read | Active on current key | View properties and other details about leads. Available to Sales Hub Professional or Enterprise accounts only. |
crm.objects.leads.write | Active on current key | Create, delete, or make changes to leads. Available to Sales Hub Professional or Enterprise accounts only. |
crm.objects.line_items.read | Active on current key | View properties and other details about line items. Available to all accounts. |
crm.objects.line_items.write | Active on current key | Create, delete, or make changes to line items. Available to all accounts. |
crm.objects.listings.read | Active on current key | View properties and other details about listings. Available to all accounts. |
crm.objects.listings.write | Not granted / selector not re-audited | Create, delete, or make changes to listings. Available to all accounts. |
crm.objects.marketing_events.read | Active on current key | View details about marketing events. Available to all accounts. |
crm.objects.marketing_events.write | Active on current key | Create, delete, or make changes to marketing events. Available to all accounts. |
crm.objects.orders.read | Active on current key | View properties and other details about orders. Available to all accounts. |
crm.objects.orders.write | Not granted / selector not re-audited | Create, delete, or make changes to orders. Available to all accounts. |
crm.objects.owners.read | Active on current key | View details about users assigned to a CRM record. Available to all accounts. |
crm.objects.partner-clients.read | Not granted / selector not re-audited | View details about partner clients objects. Available to all accounts. |
crm.objects.partner-clients.write | Not granted / selector not re-audited | Create, delete, or make changes to partner clients objects. Available to all accounts. |
crm.objects.partner-services.read | Not granted / selector not re-audited | View details about partner service objects. Available to all accounts. |
crm.objects.partner-services.write | Not granted / selector not re-audited | Create, delete, or make changes to partner service objects. Available to all accounts. |
crm.objects.quotes.read | Active on current key | View properties and other details about quotes and quote templates. Available to all accounts. |
crm.objects.quotes.write | Not granted / selector not re-audited | Create, delete, or make changes to quotes (including legacy quotes). Available to all accounts. |
crm.objects.services.read | Active on current key | View properties and other details about services. Available to all accounts. |
crm.objects.services.write | Not granted / selector not re-audited | Create, delete, or make changes to services. Available to all accounts. |
crm.objects.subscriptions.read | Active on current key | View properties and other details about commerce subscriptions. Available to all accounts. |
crm.objects.users.read | Active on current key | View properties and other details about users. Available to all accounts. |
crm.objects.users.write | Not granted / selector not re-audited | Create, delete, or make changes to users. Available to all accounts. |
crm.pipelines.orders.read | Not granted / selector not re-audited | View details about order pipelines. Available to all accounts. |
crm.pipelines.orders.write | Not granted / selector not re-audited | Create, delete, or make changes to order pipelines. Available to all accounts. |
crm.schemas.appointments.read | Not granted / selector not re-audited | View details about property settings for appointments. Available to all accounts. |
crm.schemas.appointments.write | Not granted / selector not re-audited | Create, delete, or make changes to property settings for appointments Available to all accounts. |
crm.schemas.carts.read | Not granted / selector not re-audited | View details about property settings for carts. Available to all accounts. |
crm.schemas.carts.write | Not granted / selector not re-audited | Create, delete, or make changes to property settings for carts. Available to all accounts. |
crm.schemas.courses.read | Not granted / selector not re-audited | View details about property settings for courses. Available to all accounts. |
crm.schemas.courses.write | Not granted / selector not re-audited | Create, delete, or make changes to property settings for courses. Available to all accounts. |
crm.schemas.commercepayments.read | Active on current key | View details about property settings for commerce payments. Available to Starter accounts only. |
crm.schemas.companies.read | Active on current key | View details about property settings for companies Available to all accounts. |
crm.schemas.companies.write | Active on current key | Create, delete, or make changes to property settings for companies. Available to all accounts. |
crm.schemas.contacts.read | Active on current key | View details about property settings for contacts. Available to all accounts. |
crm.schemas.contacts.write | Active on current key | Create, delete, or make changes to property settings for contacts. Available to all accounts. |
crm.schemas.custom.read | Active on current key | View details about custom object definitions in the HubSpot CRM. Available to Enterprise accounts only. |
crm.schemas.deals.read | Active on current key | View details about property settings for deals. Available to all accounts. |
crm.schemas.deals.write | Active on current key | Create, delete, or make changes to property settings for deals. Available to all accounts. |
crm.schemas.invoices.read | Active on current key | View details about property settings for invoices. Available to all accounts. |
crm.schemas.invoices.write | Not granted / selector not re-audited | Create, delete, or make changes to property settings for invoices Available to all accounts. |
crm.schemas.line_items.read | Active on current key | View details about line items properties. Available to all accounts. |
crm.schemas.listings.read | Not granted / selector not re-audited | View details about property settings for listings Available to all accounts. |
crm.schemas.listings.write | Not granted / selector not re-audited | Create, delete, or make changes to property settings for listings Available to all accounts. |
crm.schemas.orders.read | Active on current key | View details about property settings for orders Available to all accounts. |
crm.schemas.orders.write | Not granted / selector not re-audited | Create, manage, or make changes to property settings for orders Available to all accounts. |
crm.schemas.quotes.read | Active on current key | View details about quotes and quotes templates. Available to all accounts. |
crm.schemas.quotes.write | Not granted / selector not re-audited | Create, manage, or make changes to property settings for quotes Available to all accounts. |
crm.schemas.services.read | Active on current key | View details about property settings for services Available to all accounts. |
crm.schemas.services.write | Not granted / selector not re-audited | Create, manage, or make changes to property settings for services Available to all accounts. |
crm.schemas.subscriptions.read | Active on current key | View details about property settings for commerce subscriptions. Available to all accounts. |
crm.schemas.subscriptions.write | Not granted / selector not re-audited | Create, manage, or make changes to property settings for commerce subscriptions. Available to all accounts. |
external_integrations.forms.access | Active on current key | Includes the ability to rename, delete, and clone existing forms when using the HubSpot WordPress plugin. Available to all accounts. |
files | Active on current key | Access, manage, and upload files in the HubSpot file manager. Available to all accounts. |
files.ui_hidden.read | Not granted / selector not re-audited | Access hidden or deleted files uploaded to the HubSpot file manager. Available to all accounts. |
forms | Active on current key | Grants access to the legacy and v3 forms APIs Available to all accounts. |
forms-uploaded-files | Active on current key | Grants access to the legacy v1 uploaded form files API Available to all accounts. |
hubdb | Not granted / selector not re-audited | Retrieve and manage HubDB data. Available to CMS Hub Professional or Enterprise, or Marketing Hub Professional or Enterprise accounts only. |
marketing.campaigns.read | Active on current key | View details about marketing campaigns and their associated assets. Available to Marketing Hub Professional or Enterprise accounts only. |
marketing.campaigns.revenue.read | Active on current key | View revenue details and deal amounts attributed to a marketing campaign. Available to Marketing Hub Professional or Enterprise accounts only. |
marketing.campaigns.write | Active on current key | Create, update, and delete marketing campaigns. Available to Marketing Hub Professional or Enterprise accounts only. |
marketing-email | Observed unavailable | Grants access to retrieve and send marketing emails. Publishing marketing emails using this API requires Marketing Hub Enterprise. Available to all accounts. |
media_bridge.read | Not granted / selector not re-audited | Grants access to events and objects from the media bridge API. Available to all accounts. |
media_bridge.write | Not granted / selector not re-audited | Grants access to create and update events and objects from the media bridge API. Available to all accounts. |
oauth | Active on current key | Basic scope required for OAuth. This scope is added by default to all apps. Available to all accounts. |
sales-email-read | Observed unavailable | Grants access to read and manage one-to-one email engagements Available to all accounts. |
scheduler.meetings.meeting-link.read | Active on current key | Read metadata and booking availability for meeting links Available to Professional accounts only. |
settings.billing.write | Not granted / selector not re-audited | Make changes to your account's billing settings. This includes managing and assigning paid seats for users. Available to all accounts. |
settings.currencies.read | Active on current key | Reads existing exchange rates along with the current company currency associated with your HubSpot account. Available to all accounts. |
settings.currencies.write | Not granted / selector not re-audited | Create, update and delete exchange rates along with updating the company currency associated with your HubSpot account. Available to all accounts. |
settings.users.read | Not granted / selector not re-audited | View details about account users and their permissions. Available to all accounts. |
settings.users.write | Not granted / selector not re-audited | Manage users and user permissions on your HubSpot account. This includes creating new users, assigning permissions and roles, and deleting existing users. Available to all accounts. |
settings.users.teams.read | Not granted / selector not re-audited | See details about the teams in an account. Available to all accounts. |
settings.users.teams.write | Not granted / selector not re-audited | Assign users to teams on your HubSpot account. Available to all accounts. |
tax_rates.read | Observed unavailable | View details about tax rates configured in your account. Available to all accounts. |
tickets | Active on current key | Retrieve, manage, or create tickets. Available to all accounts. |
tickets.highly_sensitive | Active on current key | Grants access to view and edit Highly Sensitive Data properties and values for tickets. Available to Enterprise accounts only. |
tickets.sensitive | Active on current key | Grants access to view and edit Sensitive Data properties and values for tickets. Available to Enterprise accounts only. |
timeline | Observed unavailable | Grants access to manage legacy timeline events on HubSpot CRM records. Available to all accounts. |
transactional-email | Observed unavailable | Access and manage transactional emails. Available to Marketing Hub Professional or Enterprise accounts with Transactional Email Add-on only. |
Observed unavailable scopes
These 17 desired scopes were unavailable or not granted for this portal/key configuration. This is not a universal statement about every HubSpot account or credential type.
Unavailable / not granted — 17
cms.performance.readautomation.sequences.writecommunication_preferences.statuses.batch.readtimelinetimeline.readtimeline.writeaccountingbusiness-intelligencebusiness_units_view.readcpq.price_books.readdeveloper.platform_logs.reade-commercemarketing-emailsales-email-readsocialtax_rates.readtransactional-emailEvidence and limits
- Credential: HubSpot Account Service Key (public beta), portal
40014162, ID47206867. - Proven live reads: campaigns, Marketing Email, workflows, lists, owners, forms, files, and site pages.
- Service Keys are REST-only; HubSpot excludes webhooks, UI extensions, and other developer-platform features.
- Official catalog: 148 active rows. HubSpot documents no REST API for enumerating Account Service Key selections; current-key grants and portal availability require authenticated UI inspection.
- Credential changes are not authorized by this audit.
- https://developers.hubspot.com/docs/apps/developer-platform/build-apps/authentication/account-service-keys
- https://developers.hubspot.com/docs/apps/developer-platform/build-apps/authentication/scopes
- https://developers.hubspot.com/docs/api-reference/latest/marketing/marketing-emails/guide
- https://developers.hubspot.com/docs/api-reference/latest/marketing/campaigns/guide
- https://knowledge.hubspot.com/marketing-email/create-automated-emails-to-use-in-workflows
Full-funnel examples from entry signal to proof
These maps show how sources, segments, workflows, emails, links, CRM state, and reporting connect. Illustrative means a proposed blueprint—not a currently active HubSpot workflow. Every production implementation still requires live object IDs, consent/legal review, audience confirmation, suppression reconciliation, testing, and approval.
Pest Control cold-prospect opportunity
Social comment → guide opt-in → HubSpot nurture
Website guide request → segmented educational nurture
industry + offer promise→HubSpot form
email + consent + source→Deduplication / suppression gate→SEG | NB | DM
Guide Request→Delivery email→Topic-click branches→Demo goal / quiet completion
Use separate durable event segments for every meaningful topic. A single “last interest” property cannot preserve multi-topic behavior.
Existing-client Client Command Center nurture
232 attached at incident→Enabled nurture workflow→Historical legacy Email 00 Update
July 30 send-adjacent incident→187 production deliveries→3-day delays
Emails 01–07→click-interest segments→activation / booking exits
How individual hyperlinks fan out inside HubSpot
Every name answers the same eight questions
<TYPE> | <LANE> | <ROLE> | <MARKET> | <INITIATIVE> | <SEQUENCE> | <PURPOSE> | <STATE-ENV>
Not every object needs every field in its visible name, but dimensions always remain in this order. Use one space on each side of the pipe. Never invent campaign-specific initials such as OACC.
Relationship lane
| Code | Meaning |
|---|---|
EC | Existing-client retention, adoption, service, expansion, or advocacy. |
NB | New-business awareness, demand, qualification, or acquisition. |
EC+NB | Intentionally shared across both motions. |
Audience role
| Code | Recipient capacity |
|---|---|
CLIENT | Current client addressed as a client. |
DM | Prospective decision-maker or buying committee. |
PARTNER | Referral, channel, association, technology, or strategic partner. |
INFL | Influencer, analyst, advisor, educator, or recognized voice. |
MEDIA | Journalist, editor, publisher, podcaster, or producer. |
Lane and role are separate dimensions
| Combination | Exact interpretation |
|---|---|
EC | PARTNER | Partner communication supporting client delivery, adoption, retention, or expansion. |
NB | PARTNER | Partner communication supporting referrals or acquisition. |
EC | INFL | Influencer outreach supporting client proof, education, or advocacy. |
NB | INFL | Influencer outreach building credibility with prospective buyers. |
EC | MEDIA | Media communication centered on client success or service adoption. |
NB | MEDIA | Media communication intended to create awareness and new demand. |
NB describes the business motion supported—not how recently Outsource Access met the partner, influencer, or media contact.Object prefixes and exact templates
| Object | Prefix | Template |
|---|---|---|
| Campaign | CMP | CMP | LANE | ROLE/MULTI | MARKET | INITIATIVE | PERIOD | STATE |
| Segment/List | SEG | SEG | LANE | ROLE | MARKET | INITIATIVE | PURPOSE | STATE-ENV |
| Workflow | WF | WF | LANE | ROLE | MARKET | INITIATIVE | FUNCTION | PURPOSE | STATE-ENV |
| Marketing email | EM | EM | LANE | ROLE | MARKET | INITIATIVE | N | PURPOSE | STATE-ENV |
| Form | FRM | FRM | LANE | ROLE | MARKET | INITIATIVE | PURPOSE | STATE-ENV |
| Landing page | LP | LP | LANE | ROLE | MARKET | INITIATIVE | PURPOSE | STATE-ENV |
| CTA | CTA | CTA | LANE | ROLE | MARKET | INITIATIVE | PURPOSE | VARIANT | STATE-ENV |
| Asset | AST | AST | LANE | ROLE/MULTI | MARKET | INITIATIVE | PURPOSE | VARIANT | STATUS |
| Report | RPT | RPT | LANE | ROLE | MARKET | INITIATIVE | METRIC | PERIOD |
| Dashboard | DSH | DSH | LANE | ROLE/MULTI | MARKET | INITIATIVE | PURPOSE |
Client Dashboard example
CMP | EC | CLIENT | ALL | Client Dashboard Launch | 2026-Q3 | ACTIVESEG | EC | CLIENT | ALL | Client Dashboard Launch | Eligible | ACTIVE-PRODWF | EC | CLIENT | ALL | Client Dashboard Launch | Main | Nurture | ACTIVE-PRODEM | EC | CLIENT | ALL | Client Dashboard Launch | 1 | Announcement | ACTIVE-PROD
Pest Control example
CMP | NB | MULTI | Pest Control | Pest Control Growth | 2027-Q1 | DRAFTSEG | NB | DM | Pest Control | Pest Control Growth | Apollo Source | DRAFT-PRODSEG | NB | MEDIA | Pest Control | Pest Control Growth | Podcast Hosts | DRAFT-PRODWF | NB | DM | Pest Control | Pest Control Growth | Main | Nurture | DRAFT-PROD
Governance rules
- Use approved prefixes and codes only
- Use
ALLfor intentionally cross-industry assets - Start email sequences at
1and continue with unpadded integers:2,3, through10+; never use00,01, or other zero padding - Use
DRAFT,REVIEW,READY,ACTIVE,PAUSED,COMPLETE, orARCHIVED - Use
PROD,TEST, orSBXfor environment - Never use “final,” “final-final,” “new,” or a person’s name as version control
- Search for the target canonical name before creating any object
- Record owner, source, created date, campaign, and dependencies in the asset registry
Published email versus pending revision
| Surface | What it shows | Correct use |
|---|---|---|
| Email name / performance | The currently published email and reporting. | Use to see what is live. |
| Edit Email | The auto-saved unpublished revision on the same email ID. | Use to review or modify pending changes. |
| Version history | Historical published/saved versions. | Use for reference only; do not restore while a newer draft is under review. |
Revision protocol
- Read the live email and pending draft separately.
- Identify every connected workflow and read enabled state, attached audience, enrollment history, eligible/pending contacts, delays, and suppressions.
- If every connected workflow is OFF, publication alone will not send; verify it remains OFF. If any workflow is ON, pause/isolate it or obtain explicit approval for the waiting/new/re-enrolled contacts that may still reach the action.
- Change only the intended modules; inspect links, media, source order, folder, and
AUTOMATED_EMAILtype. - Publish only after the pre-publish interlock passes.
- Read back the live email, workflow, enrollment state, and all campaign-run IDs immediately.
Publication capability
Draft-write access and publication access are different HubSpot capabilities. A successful draft update is not proof the revision is live.
Folder and naming
- Place every Sterling-created email in Sterling Emails (Brad).
- Verify the folder ID after creation or correction.
- Do not rely on Created by Brad as authoritative for API-created assets.
- Do not rely on contains exactly as if it were a reusable internal-name prefix filter.
Draft editing is available; API publication is not
The current Service Key can create, clone, read, and edit Marketing Email drafts through content. It cannot currently publish/unpublish because marketing-email is unavailable and HubSpot separately gates those endpoints by product entitlement. Brad performs Review and publish in the UI until both gates are proven.
Distinct visual roles
- Product animation: demonstrates the dashboard or product experience.
- Presenter walkthrough: shows Brad speaking in the Loom walkthrough.
- Do not silently replace one with the other.
- Place captions immediately above the intended visual.
File hosting
- Email images and animated GIFs must be copied into HubSpot Files; the Mac mini is an authoring source, never the recipient-facing host.
- Use a content-hash-qualified filename, intentional public-but-not-indexed access, and the final
hubspotusercontentURL. - Require anonymous HTTP 200, expected MIME, safe bytes, dimensions, frame count, looping behavior, and meaningful alt text.
- A successful upload, filename, or old module reference is not proof the email visibly renders the asset.
Where Sterling-created media belongs
| Asset | Working source | Durable destination |
|---|---|---|
| Email image or animated GIF | May be created temporarily on the Mac mini | HubSpot Files in the correct portal/folder |
| Full generated video | Temporary Mac master only | Brad's personal Vimeo Team Library → Sterling videos (folder 30060478) |
| Generated non-email image | Temporary Mac working file | Sterling Media on Brad's personal Cloudflare account |
file://, /Users/..., localhost, or another Mac-local path. Do not use Mac-local or general Cloudflare hosting for generated videos unless Brad changes the standing rule.Animated GIF persistence and visibility gate
- QA the source GIF: safe first frame, more than one frame, appropriate dimensions/weight, no private data.
- Close every open Edit Email session before an external draft write.
- Upload with a content-hash-qualified filename and replace the intended module with the exact new HubSpot URL.
- Preserve alt text, responsive dimensions, click destination, caption, and required source order.
- Require two delayed, identical draft readbacks after the autosave window.
- Render the exact saved block; verify natural dimensions and capture two different frames to prove animation.
- Visually inspect the result. A blank gap or broken placeholder fails the gate.
Landing-page destination gate
- Deploy the page first.
- Verify the canonical path renders the intended unique content.
- Verify the embedded media and CTA destination.
- Check the immutable deployment and custom domain.
- Only then update email images or CTAs to that page.
Client Command Center precedent
The flagship announcement uses three separate clickable elements—the top dashboard animation, Brad's Loom-preview GIF under “A quick walkthrough of the dashboard.”, and the primary button. Brad directed all three to the branded Cloudflare walkthrough page. The full interactive demo remains available from that landing page.
Workflow status must be explicit
| Claim | Required proof |
|---|---|
| Workflow built | Workflow graph, actions, branches, and referenced email IDs. |
| Workflow active | isEnabled: true or equivalent live UI proof. |
| Contact enrolled | Enrollment record for the exact contact/list and timestamp. |
| Email sent | Delivery/event or recipient inbox proof—not publication. |
Safe publication behavior
Publishing makes the latest automated-email version available to referencing workflows. It does not replay the action or resend prior recipients. If the workflow is OFF, publication alone does not send. If it is ON, contacts waiting before the action, newly enrolled, or re-enrolled can receive the latest version when the action executes; pause/isolate or prove that exposure safe before publishing. If HubSpot offers a new workflow attachment, choose I'll do this later unless attachment is separately approved.
Inactive-by-default rule
Builds, drafts, lists, and workflow graphs remain disconnected from production audiences. For an existing live workflow, confirm it is paused or isolated before publishing an email revision, then re-read workflow state, enrollment history, pending contacts, and campaign counters after publication.
Testing sequence
Workflow build/edit/activation capability does not erase the separate email-publication gate. Before launch, verify the connected email is published, the exact audience is approved, and the API Permissions handoff is complete.
Three distinct workflow classes
| Class | Purpose | Default state |
|---|---|---|
| Main nurture | Audience, cadence, sends and completion. | Default OFF until exact release. Historical July 30 evidence showed the Client Dashboard nurture ON; refresh live state before action. |
| Interest capture | Preserve behavior and update governed CRM state. | OFF until event/property canary. |
| Behavioral follow-up | Wait, branch and send context-aware resources. | OFF until copy, deduplication, suppression and audience approval. |
Interest tracking & behavioral automation
This reference architecture turns identified customer or prospect behavior into durable CRM evidence and governed follow-up. It separates measurement, classification, and customer-facing action so a click never silently becomes authority to send.
All 10 Client Dashboard Launch workflows
| Workflow | State | Actual purpose | Enrollment trigger | Actions | Durable segment |
|---|---|---|---|---|---|
1858142032WF | EC | CLIENT | Client Dashboard Launch | Nurture | PROD | ON | Production nurture sequence | Segment 4633 | oa_cc_activation_status=not_startedoa_cc_nurture_status=completed | — |
1858125171WF | EC | CLIENT | Client Dashboard Launch | Interest Capture | 00 Overview | PROD | OFF | OFF | One-time email-click classifier | Any tracked-link click430377925 | oa_cc_engagement_score=10oa_cc_activation_status=active_explorer | 4632 · 11 contacts |
1858126107WF | EC | CLIENT | Client Dashboard Launch | Interest Capture | 01 Team & Performance | PROD | OFF | OFF | One-time email-click classifier | Any tracked-link click430377940 | oa_cc_engagement_score=20oa_cc_activation_status=active_exploreroa_cc_last_module_engaged=performanceoa_cc_interest_track=performance | 4571 · contacts |
1858142980WF | EC | CLIENT | Client Dashboard Launch | Interest Capture | 02 Financial Visibility | PROD | OFF | OFF | One-time email-click classifier | Any tracked-link click430377934 | oa_cc_engagement_score=30oa_cc_activation_status=active_exploreroa_cc_last_module_engaged=roioa_cc_interest_track=roi | 4572 · contacts |
1858142981WF | EC | CLIENT | Client Dashboard Launch | Interest Capture | 03 Process Control | PROD | OFF | OFF | One-time email-click classifier | Any tracked-link click430379523 | oa_cc_engagement_score=40oa_cc_activation_status=active_exploreroa_cc_last_module_engaged=playbookoa_cc_interest_track=playbook | 4573 · contacts |
1858142982WF | EC | CLIENT | Client Dashboard Launch | Interest Capture | 04 Strategic Advisory | PROD | OFF | OFF | One-time email-click classifier | Any tracked-link click430377221 | oa_cc_engagement_score=50oa_cc_activation_status=active_exploreroa_cc_last_module_engaged=strategicoa_cc_interest_track=strategic | 4574 · contacts |
1858142985WF | EC | CLIENT | Client Dashboard Launch | Interest Capture | 05 Market Intelligence | PROD | OFF | OFF | One-time email-click classifier | Any tracked-link click430380615 | oa_cc_engagement_score=60oa_cc_activation_status=active_exploreroa_cc_last_module_engaged=intelligenceoa_cc_interest_track=intelligence | 4575 · contacts |
1858125648WF | EC | CLIENT | Client Dashboard Launch | Interest Capture | 06 Human + AI | PROD | OFF | OFF | One-time email-click classifier | Any tracked-link click430379516 | oa_cc_engagement_score=70oa_cc_activation_status=active_exploreroa_cc_last_module_engaged=human_aioa_cc_interest_track=human_ai | 4576 · contacts |
1858125172WF | EC | CLIENT | Client Dashboard Launch | Interest Capture | 07 Mobile Access & Support | PROD | OFF | OFF | One-time email-click classifier | Any tracked-link click430380619 | oa_cc_engagement_score=80oa_cc_activation_status=active_exploreroa_cc_last_module_engaged=mobile_supportoa_cc_interest_track=mobile_support | 4577 · contacts |
1858119352Historical live label: WF | INT | TEST | Client Dashboard Launch | Email 00 | MANUAL | OFF | Historical Brad-only manual Email 00 test | Manual enrollment | Send 218124282752 | — |
1858142032 is ON while its description says “Inactive production nurture.” The eight middle workflows are OFF click-interest classifiers—not inactivity trackers.Historical legacy Email 00: what actually happened
- The historical legacy Email 00 field-writing workflow is OFF; it did not write score or activation status.
- Dynamic segment
4632independently preserves the click event and contained 11 contacts at audit time. - Click evidence exists, but the disabled workflow did not categorize those contacts through CRM property actions.
- The segment count is time-sensitive and must be refreshed before operational use.
What the old classifiers do—and do not do
- Trigger on any tracked link in one email-event group, not a specific CTA.
- No re-enrollment; repeat clicks do not rerun them.
- Overwrite scores with 10/20/30…80; this is sequence position, not cumulative scoring.
- No delay, branch, follow-up email, task, owner alert, webhook, or custom code.
- Multi-topic history is preserved separately through dynamic click segments.
Verified live property writes
| Score | Status | Latest module / interest | Segment count | |
|---|---|---|---|---|
| 00 Announcement | 10 | active_explorer | Not written | 11 |
| 01 Team & Performance | 20 | active_explorer | performance | 0 |
| 02 Financial Visibility | 30 | active_explorer | roi | 0 |
| 03 Process Control | 40 | active_explorer | playbook | 0 |
| 04 Strategic Advisory | 50 | active_explorer | strategic | 0 |
| 05 Market Intelligence | 60 | active_explorer | intelligence | 0 |
| 06 Human + AI | 70 | active_explorer | human_ai | 0 |
| 07 Mobile & Support | 80 | active_explorer | mobile_support | 0 |
oa_cc_interest_track is a multi-checkbox field. Canary-test whether the action appends or replaces values before enabling any tracker.Documented HubSpot behavioral triggers
| Signal | Supported pattern | Constraint |
|---|---|---|
| Email opened | Event or filter trigger | Weak signal: privacy opens, scanners and pixel blocking distort intent. |
| Any email-link click | Any qualifying tracked link in a selected email | Does not identify topic unless the email context is narrow. |
| Specific email + URL click | Refine by email and Original/Raw URL | Use URL contains, not tracked-URL equality; forwarded clicks may attribute to the original recipient. |
| Repeat click | Re-enroll per event, increment numeric property, branch at threshold | Composed counter; no documented native “clicked N times” email trigger. |
| CTA click/view | Current and legacy CTA events | Count/date refinements vary by CTA generation and tier. |
| Page visit | URL event/filter; count or date refinement | Known contact required; no anonymous-history replay; downloads are not page views. |
| Form interaction/submission | View, field interaction, or submission | Submission is higher-confidence evidence. |
| Segment membership | Added/removed event or membership filter | Active lists are criteria-driven; workflow list actions change static lists. |
| Property changed | Exact CRM property transition | Validate internal values before writes or branches. |
| Custom event | Visited URL, clicked element, or custom event | Known contact required; codeless event supports up to 30 URLs/elements. |
| Ad interaction | Network and interaction-type refinements | Connected ad data required. |
| Meeting / reply | Booked meeting, outcome change, marketing-email reply | High-confidence signals; do not generalize to arbitrary inbox replies. |
| Non-occurrence | Delay, then test whether event/state occurred | Not a direct event trigger. |
Orchestration and action palette
Canonical sequence: announcement + six follow-ups
| Position | Category | Replacement interest architecture |
|---|---|---|
| 1 | Announcement | Track demo and walkthrough links separately. |
| 2 | Team & Performance | People, accountability, performance and team-value signals. |
| 3 | Financial Visibility | ROI, billing, margin, WIP, invoicing and calculator signals. |
| 4 | Process Control | Playbooks, SOPs, controls and improvement signals. |
| 5 | Strategic Advisory | Planning, advisory and next-best-action signals. |
| 6 | Market Intelligence | Research, opportunities, competitors and initiative signals. |
| 7 | Human + AI, Mobile Access & Support | Canonical consolidation of the two historical legacy categories formerly labeled Emails 06 and 07. |
Custom proposal click → two-day calculator follow-up
- Match the exact company-proposal path through normalized URL-contains logic.
- Write first-click timestamp/topic; increment a numeric counter only if repeat scoring is required.
- Wait two days.
- Exit if the contact replied, booked, converted, opted out, became suppressed, hit contact-pressure limits, or already received the calculator.
- Send the approved calculator email to the primary address.
- Write calculator-sent timestamp/status to prevent duplication; optionally create a task or static-segment membership.
- Measure calculator visit/submission and business outcome—not open alone.
Reusable behavioral workflow
event · state · schedule→QUALIFY
identity · asset · URL · confidence→WAIT
duration · date · event/timeout→DECIDE
branch · goal · suppress · exit→EFFECT
email · task · field · route→PROVE
event · action · outcome
Every behavioral workflow must explain itself
Name: WF | <LANE> | <ROLE> | <MARKET> | <INITIATIVE> | Behavior | <SIGNAL→OUTCOME> | <STATE-ENV>
Description: exact event and asset/URL; interpretation; occurrence rule; fields/internal values; durable segment; wait; branches/exits; customer/internal actions; deduplication; suppression/contact pressure; tier; API/UI boundary; enabled state.
- Read workflow, email, segment and property schemas.
- Validate event/URL identity and every internal property value.
- Confirm tier and API/UI capability.
- Keep new trackers and branches OFF.
- Run one approved test-contact canary.
- Verify event, field, segment, delay, branch, send and deduplication separately.
- Obtain exact activation/audience approval.
- Activate with monitoring, stop owner and rollback.
API and product boundaries
| Capability | Boundary |
|---|---|
| Workflow read/create/update/delete | automation scope; Professional/Enterprise. Full PUT updates; API delete is destructive. |
| Automated email, random split, page/CTA trigger, codeless event | Marketing Hub Professional/Enterprise and applicable permissions. |
| Webhook / JavaScript custom code | Data Hub Professional/Enterprise; UI availability does not prove v4 API construction. |
| Activation, enrollment, customer email | Separate approval plus exact audience, suppression and send proof. |
| Name/description corrections | UI metadata; never issue a name-only API PUT. |
See API permissions for current-key versus official-catalog evidence.
Audience confirmation
- Inventory list metadata without exporting unnecessary member data.
- Verify inclusion, exclusion, suppression, and actual email-bearing counts.
- Never infer the production audience from a list name alone.
- Require Brad to confirm the exact audience before enrollment or sending.
Send authority
- A preview is not a send.
- A test email is a real external send.
- A workflow simulation is not delivery.
- Publication is a separate proof state and does not replay completed sends. In an enabled workflow, waiting, newly enrolled, or re-enrolled contacts can receive the latest version when the send action executes.
- Production release requires the exact email, audience, account, timing, approved content, workflow state, and enrollment consequence.
Before any test or production delivery
- Exact recipient or audience approved
- Subject, preview text, body, sender identity, and subscription type verified
- Every link and image checked
- Suppression and exclusion rules read back
- Every connected workflow paused/isolated or exact live-release consequence approved
- Eligible, enrolled, pending, suppressed, dropped, and deferred states reconciled
- Post-publication campaign-run IDs and delivery proof captured
Pre-publication checklist
- Visible brand copy says Outsource Access as two words
- Typography is restrained and mobile-safe
- Requested product and presenter GIFs are distinct and correctly ordered
- Email images/GIFs use content-hash-qualified HubSpot Files URLs—not Mac-local paths
- Image URLs return expected MIME types and safe bytes
- Exact saved GIF blocks visibly render at natural dimensions and change frames
- Two delayed draft readbacks are stable after the editor is closed
- Destinations render the intended unique pages
- Tracking parameters are present once—never duplicated
- Folder and automated-email type are correct
- API Permissions matrix reviewed; every manual handoff has an owner and timing
- Scope, endpoint writability, entitlement, approval and proof were evaluated separately
- Campaign owner is Brad Stevens and was verified through the UI
- Campaign start date matches launch/creation date; end date matches the final scheduled action
- Published and draft objects were read separately
- Every connected workflow, audience, enrollment history, re-enrollment setting, and contact position relative to the email action was read before publication
- Enabled workflows were paused/isolated or the exact release was explicitly approved
- Rollback/continuation route is documented
After publication
- Read the authoritative live email object.
- Verify subject, preview text, modules, media, alt text, and CTA URLs.
- Confirm the publish timestamp and exact connected workflow states.
- Read enrollment history and decompose every new
allEmailCampaignIdsrun. - Report sent, delivered, dropped, deferred, suppressed/not-sent, and pending separately.
- If any unintended send occurred, notify Brad immediately and do not silently continue the workflow.
Evidence language
Use precise labels:
- Draft prepared
- Published update verified
- Workflow inactive
- No contact enrolled
- No email sent — campaign-run and event counters verified unchanged
Never compress these into “campaign complete.”
Fast decision table
| If Brad asks… | Default operating response |
|---|---|
| “What must I do manually?” | Open API permissions; use the current manual-step list and never infer capability from scope count. |
| “Create a campaign.” | Create the campaign with canonical naming; set start to the verified launch/creation date and end to the final scheduled action; assign Brad Stevens as owner through HubSpot UI; read back all three. |
| “Edit this published email.” | Edit and QA the pending revision. If connected workflows are OFF, publishing alone does not send; verify OFF state and unchanged counters. If any workflow is ON, distinguish completed recipients from waiting/new/re-enrolled contacts and pause/isolate unresolved execution paths before publication. |
| “Let me review it.” | Clarify whether Brad wants the live version or pending editor revision; provide the direct link. |
| “Test it.” | Confirm the exact approved recipient; send only after approval and verify delivery. |
| “Turn it on.” | Confirm immutable workflow/list IDs, exact eligible count, suppressions, sender/content, timing, exits, rollback, and post-launch proof before activation or enrollment. |
| “Use this image.” | Host it, HTTP/MIME-check it, inspect safety/animation, then update the intended module. |
| “Link to this page.” | Deploy and unique-page verify first; then patch and read back the destination. |
Current permanent conventions
- Email folder: Sterling Emails (Brad)
- Email images/GIFs: HubSpot Files with content-hash-qualified names
- Generated videos: Vimeo → Sterling videos (
30060478) - Generated non-email images: Sterling Media Cloudflare project
- Review: normal email view shows published version
- Pending revision: open through Edit Email
- Historical content: Version history; do not restore casually
- Internal page subsections: wrapped top tabs with deep links
- API permissions: scope, endpoint, entitlement, approval, manual owner, and proof are separate
- Learning log: immutable date/time, failure, prior model, actual behavior, impact, and correction
- Campaign owner: Brad Stevens; UI-assigned and verified
- Campaign dates: launch/creation through final scheduled email/action
Authority summary
May prepare: drafts, assets, lists, workflow foundations, QA evidence.
Requires direct approval: publication after the connected-workflow interlock, test sends, workflow activation, contact enrollment, production sends, credentials, destructive cleanup, and customer-data mutations. An explicit edit request never overrides the pause/isolation requirement for an enabled workflow unless Brad explicitly approves the exact live audience release.