Brad–Sterling2HubSpot Protocols
Quick-reference system
← Brad–Sterling2 Workspace
Operations • Marketing Hub

HubSpot Protocols

A practical operating reference for creating, reviewing, publishing, testing, and governing HubSpot assets—including the critical distinction that publishing updates the automated-email asset but does not itself enroll contacts, replay completed workflow actions, or resend prior recipients. Enabled workflows remain send-adjacent because waiting, newly enrolled, or re-enrolled contacts can receive the latest version when the send action executes.

✓ Draft and live states separatedAssets and destinations verifiedUpdate/Publish can be send-adjacentLive workflows require a pre-publish interlock
Operating model

Separate proof states interact without becoming the same action

Creation, draft editing, publication, workflow connection, enrollment, sending, and delivery must be reported separately. Update/Publish changes the live email asset; workflow enrollment and action execution cause delivery. Publishing does not replay a completed send, but an enabled workflow can use the new version for contacts still waiting before that action, newly enrolled contacts, or contacts legitimately re-enrolled later.

Create assetEdit draftQAPre-publish interlockPause / isolatePublish updateVerify zero unintended sends
Before advising Brad to click Update, read every connected workflow, audience, enrollment, and pending-contact state. If the workflow is OFF, publication alone does not trigger a send. If it is ON, separate contacts who already passed the action from contacts waiting before it, newly enrolled contacts, and contacts eligible for re-enrollment.

Brad's review preference

When Brad requests specific edits, prepare and verify the pending revision. Publication is included only when Brad approves it and the connected-workflow interlock passes. An OFF workflow cannot send merely because the email is published. If a connected workflow is ON, pause/isolate it or obtain explicit approval for the exact contacts who may still reach the send action.

Verify before publication: copy, media, links, folder, email type, connected workflows, audience count, enrollment history, eligible/pending contacts, suppressions, schedule, and rollback route.

Standing safety boundary

  • Publishing does not create or activate a workflow, enroll contacts, replay a completed action, or resend prior recipients by itself.
  • Contacts who already passed the email action are not resent merely because the email is updated.
  • In an ON workflow, contacts waiting before the action, newly enrolled contacts, or legitimately re-enrolled contacts can receive the latest published version when execution reaches that action.
  • In an OFF workflow, publication alone does not trigger a send; still verify the workflow remains OFF and campaign counters do not change.
  • Publication approval is not blanket production-send approval.
  • Pause/isolate first when an ON workflow has unresolved waiting or re-enrollment exposure; publish second, verify counters third, and separately approve launch.
  • Test emails are real sends and require the exact recipient approval.
  • Credential, subscription, finance, and destructive actions require separate approval.

Navigation standard for integrated pages

Brad–Sterling2 uses one top-level left-navigation entry per operating area. Subsections live in the wrapped top tab bar and deep-link through hashes such as #emails, #qa, and #learning.

Two-place protocol maintenance

Every verified HubSpot finding updates both the baseline instructions everywhere they are affected and a dated, newest-first record in the Learning tab. Neither update is complete by itself.

Closeout gate: search for contradicted wording, correct it, add the Learning entry, deploy, and verify both live surfaces.
Verified learning L-2026-08-04-01

Function-level reconciliation binds names, IDs, execution states, and proof

August 4, 2026Comprehensive session reconciliationHistorical claims preservedNo HubSpot mutation authorized

Session evidence from July 29 through August 3 was reconciled across campaigns, automated email, publication, workflows, enrollment, audiences, permissions, files, CTAs, forms/pages, behavioral tracking, testing, sends, delivery, incident learning, and manual UI handoffs. The durable rule is to organize every action under its HubSpot function and bind display names to immutable IDs plus dated live proof.

Contradictions corrected

Forward-looking and canonical examples now start at Email 1 and continue 2, 3, 4 without zero padding. Legacy “Email 00/01” wording remains only where it is necessary to preserve July 30 incident and live-object history, and is labeled historical.

Object relationship

Campaign groups attribution; segment/list defines who qualifies; workflow owns execution; email is the versioned asset; enrollment puts a contact into the graph; campaign-run and recipient events prove send and delivery.

Approval boundary

Documentation may be edited and deployed. Publishing an email, enabling/pausing a workflow, enrolling contacts, changing credentials, mutating customer data, or sending requires its own explicit authority.

Proof standard

Read immutable object IDs, draft/live state, workflow graph and enabled state, list definition and counts, enrollment record, campaign-run IDs, and recipient outcomes separately. A name, 200 response, scope count, or ON toggle is not enough.

Failure modes

Renaming a label without remapping action IDs can make the visible sequence disagree with execution order. Publishing inside an enabled workflow can expose waiting or re-enrolled contacts. A test run can be mistaken for production when campaign IDs are not decomposed.

Source and date

Historical facts are sourced to Brad/Sterling session evidence and live-readback summaries dated July 29–August 3, 2026. Portal counts, enabled states, campaign metrics, and credential grants are time-sensitive and must be refreshed before action.

Reconciliation completed August 4, 2026. This release changes protocol documentation only; it performs no HubSpot publication, workflow, enrollment, audience, credential, or send action.
Verified learning L-2026-08-03-01

Publishing updates the email asset; workflow execution causes delivery

August 3, 2026Automated email lifecycleWorkflow ON/OFF distinctionBrad held publication until verified

While renumbering the initial announcement from 0 to 1, Brad stopped at HubSpot’s “Publish your email updates” modal. The modal states: “Any workflows using this email will get this latest version.” That is an asset-version update—not a send-now or re-enrollment command.

Workflow OFF

Publishing the revision does not trigger a send. Verify the workflow remains OFF and that no new campaign-run counters appear.

Workflow ON

Publishing still does not replay the action. Contacts waiting before the action, newly enrolled contacts, or contacts legitimately re-enrolled later can receive the latest version when the workflow executes that step.

Already received

Contacts who already completed that email action do not receive it again merely because the email is republished.

What can resend

Re-enrollment, manual enrollment, a duplicated/new send action, or another workflow path can create a second send. Publishing alone does not.

Permanent control

Classify publish state, workflow state, contact position, enrollment/re-enrollment, and campaign-run changes separately. Keep ON workflows paused or isolated when waiting-contact exposure is unresolved.

Sequence convention

Email positions begin at 1 and continue 2, 3, 4… without zero padding. Renaming 0 to 1 is metadata-only and does not itself send.

Publish updates the asset. Enrollment and workflow action execution cause delivery. A prior recipient is not resent unless a separate execution path runs again.
Failure learning L-2026-07-30-05

Workflow descriptions contradicted live state and overstated interest automation

July 30, 2026Automation auditMetadata/behavior mismatchCorrected from live JSON

The enabled nurture was described as inactive; eight disabled one-time click classifiers were called “inactive behavior trackers”; and the prior Protocols page listed property values that did not match live actions.

Live truth

One nurture ON, eight click classifiers OFF, one manual test OFF. Historical legacy Email 00’s independent dynamic segment contained 11 contacts while its field-writing workflow never ran.

Impact

Operators could infer inactivity logic, completed CRM categorization, or follow-up behavior that did not exist.

Root cause

Purpose, enabled state, event evidence, property mutation and downstream communication were collapsed into vague labels.

Permanent correction

Descriptions must state exact trigger, asset/URL, occurrence model, fields/values, segment, waits, effects, deduplication, tier/API boundary and state. Behavioral follow-up is a separate layer.

Never infer behavior from a workflow name or description. Read the full graph, segment filters, property schemas and enabled state independently.
Failure learning L-2026-07-30-04

Current-key scopes were not the complete Service-Key-linked catalog

July 30, 2026Post-deployment reviewScope inventoryCorrected before credential changes

This entry distinguishes what Sterling currently has from everything HubSpot documents as an available scope.

What Brad requested

A full listing of every HubSpot API ability relevant to the Account Service Key—not only the permissions already granted.

What Sterling first published

The first API Permissions release contained all 93 active current-key scopes and 17 observed unavailable scopes. That was a complete current-key inventory but not the complete official catalog.

What the official review found

HubSpot's current Service-Key-linked scope catalog contains 148 active rows. HubSpot documents no REST endpoint that enumerates the scopes selectable for Account Service Keys; key-specific selection must be verified in the authenticated UI. The reconciliation also found 20 current-key active scopes absent from the catalog's active table, so UI and documentation evidence must remain separate.

Impact

The launch matrix was operationally usable, but the permission-upgrade view undercounted cataloged possibilities and could have made the audit appear more exhaustive than it was.

Root cause

“Complete current key” and “complete credential-type catalog” were not labeled as separate inventories.

Permanent correction

Permissions documentation now maintains three layers: full official catalog, exact current-key grants, and live portal-specific availability. They are reconciled but never collapsed.

Failure learning L-2026-07-30-03

Broad API access did not equal launch-complete capability

July 30, 2026Afternoon ETAPI permissionsManual dependencies discovered late

This entry records why draft-authoring access and a large scope count did not establish end-to-end launch authority.

What Brad expected

Sterling should know before execution which HubSpot steps can be completed through the current key and which steps Brad must perform manually.

What Sterling assumed

Broad Service Key coverage plus proven draft creation/editing was treated as a reasonable indicator that adjacent final actions—especially email publication—would also be available.

What HubSpot actually requires

Scope, endpoint writability, commercial entitlement, credential type, UI exposure, and Brad's approval are independent gates. Draft CRUD uses content; publish/unpublish uses a separate gate. Campaign hs_owner is read-only even with Campaign write access.

Impact

Brad's manual steps were discovered during execution instead of being declared at campaign preflight, creating avoidable uncertainty around launch readiness.

Root cause

The earlier capability model was scope-centered rather than operation-centered. It did not require a launch matrix for every final action.

Permanent correction

The API Permissions tab is now a launch-control artifact. Every preflight identifies technical capability, entitlement, approval authority, manual owner, proof status, and fallback.

A large scope count is not launch proof. Never say “Sterling can launch this” until every critical final action is classified and every manual handoff is assigned.
Failure learning L-2026-07-30-02

Campaign owner is readable but not writable through the Campaign API

July 30, 2026Afternoon ETCampaign metadataNo live mutation occurred

This entry records the difference between a visible Campaign property and an API-writable Campaign property.

What Brad requested

Assign Brad Stevens as campaign owner and establish a repeatable owner/start/end-date standard for future campaigns.

What Sterling assumed

Because Campaign readback exposed hs_owner, Sterling initially assumed the same property could be updated through the Campaign PATCH endpoint.

What HubSpot actually did

HubSpot returned HTTP 400 and identified hs_owner as forbidden/read-only for Campaign updates. The endpoint separately confirmed hs_start_date and hs_end_date are writable.

Impact

The updater stopped after the first rejection. Zero owners were changed, no partial bulk update occurred, and the before-state inventory was preserved.

Root cause

Readability was incorrectly treated as write capability. Capability must be proven per property and per operation—not inferred from a successful GET.

Permanent correction

For each new campaign, set dates through the supported Campaign API and assign Brad through an authenticated HubSpot UI session. Read back owner and dates before completion.

New campaign standard

Owner and campaign-date convention

  1. Owner: Brad Stevens at brad@outsourceaccess.com; verify the active owner record.
  2. Start date: the verified campaign creation/launch date in HubSpot's account timezone.
  3. End date: the actual scheduled date of the final campaign email or action, calculated from delays, allowed weekdays/times, blocked dates, and timezone.
  4. If the schedule changes, update and verify the end date.
  5. Do not retroactively bulk-change historical campaigns without separate approval.
Owner assignment is UI-only under the currently proven integration. Never report an owner update from a rejected API call.
Failure learning L-2026-07-30-01

Publishing historical legacy Email 00 released the existing-client production audience

July 30, 2026Approximately 1:31 PM ETClient Command CenterCustomer-facing send occurred

This record preserves the failure mechanism, impact, and permanent operating correction. It is a reference point for future HubSpot work—not a replacement for refreshing live workflow and audience state.

What Brad intended

Brad opened the saved historical legacy Email 00 revision, confirmed the nomenclature and the intentional dashboard/walkthrough GIFs, and clicked Update believing he was applying content edits to the automated email.

What Sterling believed

Sterling incorrectly applied the blanket rule that publishing an automated-email revision was content-only and would not send, activate a workflow, or enroll contacts.

What the live configuration actually was

The production workflow was already enabled, historical legacy Email 00 was its first send action, and the populated production audience was already attached. Eligible or pending contacts therefore existed behind the editing action.

What happened

At approximately 1:31 PM ET, Update/Publish made the revised automated email current and immediately coincided with a new production campaign run. HubSpot delivered historical legacy Email 00 to 187 production recipients. With the earlier one-recipient controlled test, HubSpot displayed 188 aggregate sends and deliveries.

Failure

Sterling advised Brad that Update would not trigger the campaign and failed to pause/isolate the connected workflow or prove a no-send state before publication. The error was in the operating guidance and safety gate—not in Brad's interpretation of the editor.

Observed campaign detail

The production run reported 187 delivered, 34 dropped, and 2 deferred. At the verification checkpoint it also showed 46 opens and 10 clicks. Engagement totals are time-sensitive; the send/delivery event is the durable incident fact.

Permanent correction

Connected-workflow pre-publish interlock

  1. Identify the exact automated email ID and every workflow that references it.
  2. Read each workflow's enabled state, action graph, delays, time window, suppressions, goals, and exit behavior.
  3. Read the attached audience/list by immutable ID; verify visible, eligible, suppressed, enrolled, queued, and pending counts separately.
  4. If any connected workflow is ON, pause/isolate it or establish a verified no-send state before Update/Publish—unless Brad explicitly approves the exact audience release.
  5. Publish only the approved revision.
  6. Immediately read the live email, workflow state, enrollment history, and every new campaign-run ID.
  7. Require zero unintended counter changes before calling the edit safe. Launch remains a separate approval.
Update/Publish is always treated as send-adjacent for an automated email connected to an enabled workflow.

Proof language going forward

  • Draft saved — pending editor revision exists.
  • Published — live revision updated.
  • Workflow ON/OFF — execution permission state.
  • Eligible / enrolled / pending — audience execution states.
  • Sent / delivered / dropped / deferred — campaign-run outcomes.

Learning-log and baseline standard

Every future entry records date/time, intended action, Sterling's prior model, actual behavior, impact, root cause, corrected control, proof, and owner. Entries are newest-first with immutable IDs. The same finding must also correct every affected baseline tab, checklist, decision table, diagram, and skill reference.

Visual operating architecture

How HubSpot campaign execution fits together

Campaign
Attribution umbrella
Segment
Who qualifies
Workflow
Trigger, timing, logic
Email / CTA / Form
Customer interaction
Contact fields
Durable CRM state
Reports
Behavior and outcome
Automation is the operating area. Workflows are the executable automation objects inside it. Do not create a separate object type or naming prefix called “Automation.”

What each HubSpot element means

ElementDefinitionIt does not…
AutomationHubSpot’s top-level capability/navigation area for automated execution.Represent one independently named campaign object.
CampaignAttribution/reporting umbrella with separately managed owner, start date, end date, notes, goals, and associated assets. Owner is currently UI-assigned; dates are API-writable.Infer owner/dates from email activity or control audience eligibility, delays, or sends.
Segment / ListRule-based or static population defining inclusion, exclusion, suppression, or behavioral interest.Send an email by itself.
WorkflowExecutable logic owning enrollment, delays, branching, actions, field changes, suppression, and exit behavior.Prove an email was delivered merely because it is active.
Marketing emailOne recipient-facing message at a defined sequence position.Authorize its own audience or send.
FormCaptures a request, registration, preference, qualification, or conversion event.Replace the workflow that processes the submission.
Landing pageDestination for one campaign promise or conversion action.Become a campaign merely because campaign parameters are present.
CTATracked call-to-action object with a defined destination and purpose.Serve as proof of conversion without downstream evidence.
Contact propertyDurable CRM field storing status, source, score, preference, or last-known state.Preserve multiple interests when designed as a single overwriteable value.
Report / DashboardAnswers a measurement question or groups related measurements.Change execution state.

Campaign ownership

A campaign groups the assets and reporting for one initiative. It should include the relevant emails, pages, forms, CTAs, files, and reports, while the workflow independently controls execution.

Segment ownership

Use separate segments for source audiences, production audiences, suppressions, status populations, and durable interest behavior. A source system such as Apollo is a dimension—not the audience’s identity.

Nesting and reference model

What lives inside what

This is an operating map—not a claim that HubSpot stores every object as a literal child. Solid containment shows true internal structure; dashed boundaries show campaign association or workflow references.

HubSpot architecture nesting and reference mapThe HubSpot portal contains campaigns, lists, workflows, emails, CRM properties and reporting. Workflows reference lists and automated emails. Emails contain published and draft revisions, modules and links.HubSpot portalCampaign association • strategic reporting umbrellaSegments / listssource • eligible • suppressionbehavior • production audienceConversion assetsforms • pages • CTAsfiles • campaign mediaWorkflow • executable automationEnrollmentcriteria • re-enrollmentSafety logicsuppress • goal • exitAction graphsend email IDs • delays • branches • property writestasks • notifications • lifecycle changes • webhooksAutomated marketing email • one immutable email IDPublished revisioncurrent sendable contentperformance/details surfacePending draftEdit Email surfacesame email ID; not live yetEmail contentmodules • GIFs/images • copy • hyperlinks • CTA • footerCRM contact stateproperties • lifecycle • ownersubscriptions • consent sourcedurable interest segmentsProof and reportingcampaign-run IDs • enrollmentsent • delivered • droppeddeferred • clicks • conversions
Source/eligibilityExecutable or conversion objectLive state/proofPending or guarded state
Outsource Access operating examples

Function-by-function If/Then map

Each row states the purpose, object relationship, approval boundary, proof, and common failure mode. Examples are practical operating patterns, not permission to change live HubSpot state.

HubSpot functionIf / Then Outsource Access exampleObject relationshipApproval and proofFailure mode
CampaignIf OA launches a Client Command Center adoption initiative, then create one campaign umbrella with Brad as owner and dated start/end boundaries.Associates emails, pages, CTAs, forms, files, and reporting; does not control sends.Creation requires approved scope. Prove campaign ID, owner, dates, and associations. Owner assignment remains UI-verified under July 30 evidence.Reporting association is mistaken for enrollment or execution.
Marketing emailIf Email 1 announces the Client Command Center, then draft, QA, and publish that exact automated-email ID only after the workflow interlock passes.Versioned asset referenced by a workflow send action.Draft work and publication are separate gates. Prove AUTOMATED_EMAIL type, live timestamp, semantic content, media, and links.Draft is called live, or publication is treated as harmless while waiting contacts can reach the action.
WorkflowIf Email 2 should follow after three days, then verify action order by immutable email ID, delay, weekday window, exits, suppression, and re-enrollment.Owns trigger, enrollment, timing, branches, property writes, and send actions.Build, enable, pause, reorder, or edit each require exact authorization. Prove graph revision, enabled state, and before/after action IDs.Visible labels are renumbered but action references still point to the prior sequence.
Audience / segmentIf OA wants existing clients only, then define inclusion, suppression, valid-email, marketable, opt-out, and bounce rules before release.Feeds enrollment eligibility; a list alone does not send.Brad approves immutable list ID and expected eligible count. Prove definition, total, email-bearing, suppressed, eligible, enrolled, and pending counts separately.A friendly list name is trusted while its definition or membership changed.
Forms, pages, CTAs, filesIf a GIF and button promise a dashboard walkthrough, then both must point to the same uniquely verified destination and use durable HubSpot-hosted media.Conversion assets feed tracked events and campaign attribution.Content/link changes require approval. Prove file MIME/animation, element-to-destination matrix, unique page marker, form/CTA ID, and rendered output.A homepage fallback returns 200 for a missing path, or an old CTA destination survives a copy update.
Behavioral automationIf a known contact clicks a proposal calculator link, then record the exact event, wait, exit on reply/meeting/opt-out, and send only an approved follow-up.Event → segment/property evidence → workflow decision → governed action.Tracking may be read-only; property writes and follow-up sends are separately gated. Prove exact URL predicate, internal property values, re-enrollment, deduplication, and outcome.Any-link click is mislabeled as topic intent, or a multi-select property is overwritten.
Testing and QAIf Brad approves a test to one controlled inbox, then use the exact email/version and recipient without enrolling the production audience.Test campaign-run is separate from production workflow execution.Recipient approval is required. Prove live/draft semantic parity, inbox render, links, GIF animation, campaign-run ID, and zero unrelated counters.One test delivery is reported as a production launch.
Send and deliveryIf the production audience is approved and enrolled, then reconcile selected, enrolled, sent, delivered, dropped, deferred, suppressed, and pending states.Enrollment executes workflow; send creates provider events; delivery is a later outcome.Exact audience, timing, content, and consequence require approval. Prove per-run IDs and timestamps after activation.Workflow ON, enrollment, send, and delivery are collapsed into “launched.”

Source basis: verified Brad/Sterling session history and HubSpot readbacks dated July 29–August 3, 2026; reconciled August 4, 2026. Refresh every time-sensitive portal fact before action.

Permission architecture

Every launch action passes five independent gates

Scope
Granted
Endpoint
Writable
Entitlement
Tier/add-on
Approval
Authorized
Proof
Read back

A failure at any gate blocks the action. See API permissions for the object-by-object matrix.

Launch-control matrix

API permissions, entitlement, approval, and manual handoffs

This tab records what July 30, 2026 evidence proved for Service Key 47206867, what is merely documented, what is blocked by the current key or HubSpot plan, what requires Brad's approval, and what Brad must do manually.

93 active scopes17 observed unavailableLive reads reprobed July 30, 2026No credential change authorized
Critical: scope presence is not proof of a writable endpoint, subscription entitlement, live canary, or action approval.

Brad's current critical manual steps

  1. Campaign owner: select Brad Stevens in HubSpot UI. The Campaign API makes hs_owner read-only.
  2. Automated email publication: use Review and publish in HubSpot UI. The current Service Key does not have marketing-email, and API publish/unpublish is separately entitlement-gated.
  3. CTA authoring: create/edit/publish CTAs in UI until a write scope and endpoint are proven.
  4. HubSpot report/dashboard construction: use the UI; no current cataloged API scope documents creating or editing HubSpot analytics reports or dashboards.
  5. Credential, app, user, or permission administration: approve the exact change; HubSpot UI/MFA may require Brad or a super admin.
Not manual: campaign start and end dates are API-writable. Sterling sets start to launch/creation and end to the final scheduled action, then verifies both.

Execution matrix

Architecture element / actionRelevant scope or surfaceSterling todayTechnical / approval gateBrad manual action
Campaign — create, name, notes, status, audiencemarketing.campaigns.writeYes — documented and scope activeCreate/update allowed; deletion remains destructive and approval-gated.None for ordinary creation after campaign approval.
Campaign ownermarketing.campaigns.read + crm.objects.owners.readRead onlyHubSpot documents hs_owner as a read-only Campaign property. More Campaign scope will not make it writable.Brad selects Brad Stevens in HubSpot UI, or Sterling uses an authenticated UI session after explicit approval.
Campaign start and end datesmarketing.campaigns.writeYes — API writableUse YYYY-MM-DD; derive end date from the actual final scheduled action.None. Brad approves the schedule; Sterling writes and verifies the dates.
Campaign asset association and reportingmarketing.campaigns.write / .read / .revenue.readRead proven; write documentedAssociation is attribution metadata, not enrollment or sending.Only if a specific association endpoint fails its canary.
Segments / listscrm.lists.read + crm.lists.writeRead proven; create/update availableFinal audience definition, suppression and release remain approval-gated.No technical step; Brad approves the exact list and exclusions.
Contacts and campaign propertiescrm.objects.contacts.read/write + schema scopesTechnically availableLive customer-data mutation requires explicit approval.None when the exact mutation is approved.
Marketing email — create, clone, edit draftcontentYes — read/create/edit provenDraft write does not publish, send or prove the live revision changed.Brad reviews content; no technical editor step is required.
Marketing email — publish / unpublishmarketing-email OR transactional-emailNo with current keymarketing-email is unavailable on this Service Key. HubSpot also requires Marketing Hub Enterprise or the Transactional Email add-on for API publish/unpublish.Brad must use Review and publish in HubSpot UI until both entitlement and a supported credential route are verified.
Regular marketing email — schedule / sendmarketing-emailNo with current keyFinal send is distinct from draft authoring; recipients, sender, time and copy require approval.Brad completes the supported UI send/schedule unless a separately approved API path is proven.
Automated email — workflow deliveryautomation after the email is publishedYes, technically, after publicationWorkflow enablement/enrollment can release recipients; exact audience approval is mandatory.Brad currently publishes the email; Sterling may activate/enroll only under explicit launch approval.
Workflow — read, build and editautomationRead proven; create/update previously provenEditing an active workflow or connected email is send-adjacent.No technical step; Brad approves live execution changes.
Workflow — activate, deactivate, enrollautomationTechnically availableActivation and enrollment are guarded live-customer actions.None after Brad approves exact workflow, audience and timing; manual UI remains fallback.
Sequencesautomation.sequences.read + enrollments.writeRead and enrollment available; authoring blockedautomation.sequences.write is unavailable on the current Service Key.Brad authors/edits the sequence in UI; approved enrollment may be automated.
Files and email mediafiles + forms-uploaded-filesRead proven; upload previously provenPublic asset use and replacement still require content approval.None for ordinary approved uploads.
FormsformsRead proven; create/update/delete documentedOne broad forms scope covers definitions. external_integrations.forms.access is WordPress-plugin-specific, not the general Forms API scope.No required manual build step after approval; run one harmless write canary before first production mutation.
CTAsctas.readRead onlyNo CTA write scope is active on this key.Brad creates/edits/publishes CTAs until a supported write scope and endpoint are proven.
Landing pages / site pagescontentRead proven; create/edit/publish/schedule documentedCurrent page endpoints accept cataloged content. The separate content.landing_pages.write appears in endpoint security but not the current scope catalog.No required manual publication after approval; run an exact-operation canary before first production use.
Owners, users and permissionscrm.objects.owners.read + crm.objects.users.readRead onlyUser creation, permission changes and account administration are not granted.Brad or a HubSpot super admin performs user and permission administration.
Subscription preferencescommunication_preferences.readRead onlyNo preference-write scope is active; recipient consent cannot be overridden.Recipients manage preferences; Brad/admin manages subscription-type configuration.
Analytics, campaign revenue and email metricsmarketing.campaigns.read / revenue.read / contentRead/reporting available by surfaceCampaign metrics and revenue are read-only APIs. No current cataloged scope documents creating/editing HubSpot reports or dashboards.Brad builds or edits native HubSpot reports/dashboards in UI; Sterling can retrieve proven API metrics.
Social publishingsocialUnavailablesocial is unavailable on the current Service Key and public posting remains approval-gated.Brad uses HubSpot/social UI unless a separately approved social integration is established.
Transactional emailtransactional-emailUnavailableRequires the Transactional Email add-on and is not a marketing-nurture workaround.Use ordinary marketing-email UI for nurture; transactional capability requires a separate business case and approval.
Webhooks, UI extensions, custom workflow actionsProject-based app capabilitiesNot supported by Service KeysHubSpot states Service Keys are REST-only and cannot authenticate webhooks or UI extensions.Brad must approve creation/installation of a project-based app or OAuth/static-token integration.
Change Service Key scopes / create another credentialDevelopment → Keys / ProjectsPossible only with credential approvalCredential changes alter blast radius and may require app install/reinstall.Brad approves exact scopes, key/app type and account; UI/MFA may require Brad.

Could additional permission solve the blocked items?

Blocked capabilityWould more scope solve it?Safest next path
Campaign ownerNo. hs_owner is documented read-only.Keep UI assignment in campaign creation.
Email publish/unpublishPossibly, but not by scope alone. It requires an accepted publication scope plus Marketing Hub Enterprise or the Transactional Email add-on.Verify product tier first; then evaluate an isolated app/static-token or OAuth route. Keep UI publication as the immediate path.
Sequence authoringPossibly. automation.sequences.write was unavailable on this key.Verify entitlement and app-based scope exposure before changing credentials.
CTAsPotentially. Current key has read only; a supported write scope/endpoint must be verified.Keep CTA authoring manual until proven.
Pages and formsAlready documented through active scopes. content and forms cover the relevant writes.Run one harmless exact-operation canary before first production mutation; no new scope is presumed necessary.
Webhooks / UI extensions / custom workflow actionsNo through a Service Key.Create a project-based HubSpot app after explicit approval.

Complete active Service Key inventory

Captured from the authenticated Service Key detail page July 27, 2026; live read surfaces were reprobed July 30. Expand each group to see every active scope.

CRM — contacts, companies, deals, leads, owners and users (16) — 16crm.objects.companies.highly_sensitive.readcrm.objects.companies.readcrm.objects.companies.sensitive.readcrm.objects.companies.writecrm.objects.contacts.highly_sensitive.readcrm.objects.contacts.readcrm.objects.contacts.sensitive.readcrm.objects.contacts.writecrm.objects.deals.highly_sensitive.readcrm.objects.deals.readcrm.objects.deals.sensitive.readcrm.objects.deals.writecrm.objects.leads.readcrm.objects.leads.writecrm.objects.owners.readcrm.objects.users.read
CRM — lists, export, schemas and custom data (16) — 16crm.exportcrm.lists.readcrm.lists.writecrm.objects.custom.highly_sensitive.readcrm.objects.custom.readcrm.objects.custom.sensitive.readcrm.schemas.companies.readcrm.schemas.companies.writecrm.schemas.contacts.readcrm.schemas.contacts.writecrm.schemas.contracts.readcrm.schemas.custom.readcrm.schemas.deals.readcrm.schemas.deals.writecrm.schemas.projects.readcrm.schemas.services.read
Operations — pipelines, projects, forecasting and activity (14) — 14crm.extensions_calling_transcripts.readcrm.objects.appointments.readcrm.objects.contracts.readcrm.objects.feedback_submissions.readcrm.objects.forecasts.readcrm.objects.goals.readcrm.objects.goals.writecrm.objects.listings.readcrm.objects.projects.readcrm.objects.projects.writecrm.objects.services.readcrm.pipelines.approval.readcrm.pipelines.governance.readcrm.pipelines.stage_permissions.read
Commerce — billing, invoices, payments, products and subscriptions (17) — 17commerce.payment_links.readcrm.objects.carts.readcrm.objects.commercepayments.readcrm.objects.invoices.readcrm.objects.invoices.writecrm.objects.line_items.readcrm.objects.line_items.writecrm.objects.orders.readcrm.objects.products.readcrm.objects.quotes.readcrm.objects.subscriptions.readcrm.schemas.commercepayments.readcrm.schemas.invoices.readcrm.schemas.line_items.readcrm.schemas.orders.readcrm.schemas.quotes.readcrm.schemas.subscriptions.read
Marketing — campaigns, events, forms, CTAs, content and files (13) — 13contentcrm.objects.marketing_events.readcrm.objects.marketing_events.writectas.readexternal_integrations.forms.accessfilesformsforms-uploaded-filesmarketing.aeo.readmarketing.campaigns.readmarketing.campaigns.revenue.readmarketing.campaigns.writerecord_images.signed_urls.read
Automation — workflows and sequences (3) — 3automationautomation.sequences.enrollments.writeautomation.sequences.read
Service Hub — tickets and conversations (6) — 6conversations.custom_channels.readconversations.readconversations.writeticketstickets.highly_sensitivetickets.sensitive
CMS — domains and knowledge base (3) — 3cms.domains.readcms.knowledge_base.articles.readcms.knowledge_base.settings.read
Preferences, settings and security (3) — 3communication_preferences.readsettings.currencies.readsettings.security.security_health.read
Platform, OAuth and meetings (2) — 2oauthscheduler.meetings.meeting-link.read

Full official Service-Key-linked scope catalog — 148 rows

This is the complete active scope table HubSpot links from its Account Service Key documentation as of July 30, 2026. “Cataloged” does not prove selectable for this portal, granted to this key, entitled by the account, or sufficient for an endpoint.

Catalog/UI reconciliation: 73 of the current key's 93 active scopes match the 148 catalog rows. Twenty UI-proven active scopes and nine observed-unavailable scopes do not appear in the catalog's active table. Preserve those as live UI evidence; do not silently call them invalid, deprecated, or universally unsupported.
Open the complete 148-scope comparison
Official scopeCurrent-key statusHubSpot description / entitlement
account-info.security.readNot granted / selector not re-auditedIncludes access to account activity logs and other account security information. Available to all accounts.
analytics.behavioral_events.sendNot granted / selector not re-auditedIncludes access to send custom event occurrences. Available to Professional or Enterprise accounts only.
automationActive on current keyGrants access to create and retrieve custom workflow actions, and usage of the v4 workflow APIs. Available to Professional or Enterprise accounts only.
automation.sequences.enrollments.writeActive on current keyEnroll contacts in a sequence. Available to Sales Hub or Service Hub Professional or Enterprise accounts only.
automation.sequences.readActive on current keyView details about sequences. Available to Sales Hub or Service Hub Professional or Enterprise accounts only.
behavioral_events.event_definitions.read_writeNot granted / selector not re-auditedCreate, read, update, or delete custom events. This includes behavioral event properties. Marketing Hub Enterprise accounts only.
business_units_view.readObserved unavailableView brand data, including logo information. Note that the brands functionality is the successor to business units. Available to accounts with the Brands Add-on only.
business-intelligenceObserved unavailableGrants access to the legacy v2 reporting endpoints. Available to all accounts.
cms.domains.readActive on current keyList connected domains in an account. Available to all accounts.
cms.domains.writeNot granted / selector not re-auditedCreate, update, and delete connected domains. Available to all accounts.
cms.functions.readNot granted / selector not re-auditedView all Content Hub serverless functions, any related secrets, and function execution results. Available to Content Hub Enterprise accounts only.
cms.functions.writeNot granted / selector not re-auditedGrants access to write Content Hub serverless functions and secrets. Available to Content Hub Enterprise accounts only.
cms.knowledge_base.articles.readActive on current keyView details about knowledge articles using the GraphQL API. Available to Service Hub Professional or Enterprise accounts only.
cms.membership.access_groups.readNot granted / selector not re-auditedView membership access groups and their definitions. Available to Service Hub or Content Hub Professional or Enterprise accounts only.
cms.membership.access_groups.writeNot granted / selector not re-auditedCreate, edit, and delete membership access groups. Available to Service Hub or Content Hub Professional or Enterprise accounts only.
collector.graphql_query.executeNot granted / selector not re-auditedQuery data from your HubSpot account using the GraphQL API endpoint Available to CMS Hub Professional or Enterprise accounts only.
collector.graphql_schema.readNot granted / selector not re-auditedPerform introspection queries via GraphQL application clients such as GraphiQL. Available to CMS Hub Professional or Enterprise accounts only.
communication_preferences.readActive on current keyView details of your contacts' subscription preferences. Available to all accounts.
communication_preferences.read_writeNot granted / selector not re-auditedProvides access to subscribe or unsubscribe contacts to your subscription types, as well as retrieve subscription preferences for your contacts. Available to all accounts.
communication_preferences.statuses.batch.readObserved unavailableAllows you to batch retrieve contacts based on their subscription status. Available to Marketing Hub Enterprise accounts only.
communication_preferences.statuses.batch.writeNot granted / selector not re-auditedAllows you to batch update the subscription status of multiple contacts. Available to Marketing Hub Enterprise accounts only.
communication_preferences.writeNot granted / selector not re-auditedSubscribe or unsubscribe contacts to your subscription types. Available to all accounts.
contentActive on current keyGrants access to content APIs, including website pages, landing pages, marketing email, and blog APIs. Available to CMS Hub Professional or Enterprise, or Marketing Hub Professional or Enterprise accounts only.
conversations.readActive on current keyView details about actors, messages, and threads in help desk and the conversations inbox. Available to all accounts.
conversations.visitor_identification.tokens.createNot granted / selector not re-auditedFetch identification tokens for authenticated website visitors interacting with the HubSpot chat widget. Available to Professional or Enterprise accounts only.
conversations.writeActive on current keyCreate and manage threads and messages in the conversations inbox. Available to all accounts.
conversations.custom_channels.readActive on current keyView details about custom channels for connected inboxes and help desk. Available to Sales Hub or Service Hub Enterprise accounts only.
conversations.custom_channels.writeNot granted / selector not re-auditedManage custom channels for connected inboxes and help desk. Available to Sales Hub or Service Hub Enterprise accounts only.
crm.exportActive on current keyExport records from your CRM for all CRM data types. Available to all accounts.
crm.importNot granted / selector not re-auditedAllows you to import records into your CRM. This includes creating new records or modifying any of your existing records for all CRM data types (contacts, companies, deals, tickets, etc). Available to all accounts.
crm.dealsplits.read_writeNot granted / selector not re-auditedCreate or retrieve deal splits on a deal. Available to Sales Hub Enterprise accounts only.
crm.lists.readActive on current keyView details about contact lists. Available to all accounts.
crm.lists.writeActive on current keyCreate, delete, or make changes to contact lists. Available to all accounts.
crm.objects.appointments.readActive on current keyView properties and other details about appointments. Available to all accounts.
crm.objects.appointments.sensitive.readNot granted / selector not re-auditedView Sensitive Data properties for appointments. Available to Enterprise accounts only.
crm.objects.appointments.sensitive.writeNot granted / selector not re-auditedEdit Sensitive Data properties and values for appointments. Available to Enterprise accounts only.
crm.objects.appointments.writeNot granted / selector not re-auditedCreate, delete, or make changes to appointments. Available to all accounts.
crm.objects.carts.readActive on current keyView properties and other details about carts. Available to all accounts.
crm.objects.carts.writeNot granted / selector not re-auditedCreate, delete, or make changes to carts. Available to all accounts.
crm.objects.commercepayments.readActive on current keyView details about commerce payments. Available to Starter accounts only.
crm.objects.companies.highly_sensitive.readActive on current keyView Highly Sensitive Data properties for companies. Available to Enterprise accounts only.
crm.objects.companies.highly_sensitive.writeNot granted / selector not re-auditedEdit Highly Sensitive Data properties and values for companies. Available to Enterprise accounts only.
crm.objects.companies.readActive on current keyView properties and other details about companies. Available to all accounts.
crm.objects.companies.sensitive.readActive on current keyView Sensitive Data properties for companies. Available to Enterprise accounts only.
crm.objects.companies.sensitive.writeNot granted / selector not re-auditedEdit Sensitive Data properties and values for companies. Available to Enterprise accounts only.
crm.objects.companies.writeActive on current keyView properties and create, delete, or make changes to companies. Available to all accounts.
crm.objects.contacts.highly_sensitive.readActive on current keyView Highly Sensitive Data properties for contacts. Available to Enterprise accounts only.
crm.objects.contacts.highly_sensitive.writeNot granted / selector not re-auditedEdit Highly Sensitive Data properties and values for contacts. Available to Enterprise accounts only.
crm.objects.contacts.readActive on current keyView properties and other details about contacts. Available to all accounts.
crm.objects.contacts.sensitive.readActive on current keyView Sensitive Data properties for contacts. Available to Enterprise accounts only.
crm.objects.contacts.sensitive.writeNot granted / selector not re-auditedEdit Sensitive Data properties and values for contacts. Available to Enterprise accounts only.
crm.objects.contacts.writeActive on current keyCreate, delete, and make changes to contacts. Available to all accounts.
crm.objects.courses.readNot granted / selector not re-auditedView details about courses. Available to all accounts.
crm.objects.courses.writeNot granted / selector not re-auditedCreate, delete, or make changes to courses. Available to all accounts.
crm.objects.custom.highly_sensitive.readActive on current keyView Highly Sensitive Data properties for custom objects. Available to Enterprise accounts only.
crm.objects.custom.highly_sensitive.writeNot granted / selector not re-auditedEdit Highly Sensitive Data properties and values for custom objects. Available to Enterprise accounts only.
crm.objects.custom.readActive on current keyView details about custom objects. Available to Enterprise accounts only.
crm.objects.custom.sensitive.readActive on current keyView Sensitive Data properties for custom objects. Available to Enterprise accounts only.
crm.objects.custom.sensitive.writeNot granted / selector not re-auditedEdit Sensitive Data properties and values for custom objects. Available to Enterprise accounts only.
crm.objects.custom.writeNot granted / selector not re-auditedCreate, delete, or make changes to custom objects. Available to Enterprise accounts only.
crm.objects.deals.highly_sensitive.readActive on current keyView Highly Sensitive Data properties for deals. Available to Enterprise accounts only.
crm.objects.deals.highly_sensitive.writeNot granted / selector not re-auditedEdit Highly Sensitive Data properties and values for deals. Available to Enterprise accounts only.
crm.objects.deals.readActive on current keyView properties and other details about deals. Available to all accounts.
crm.objects.deals.sensitive.readActive on current keyView Sensitive Data properties for deals. Available to Enterprise accounts only.
crm.objects.deals.sensitive.writeNot granted / selector not re-auditedEdit Sensitive Data properties and values for deals. Available to Enterprise accounts only.
crm.objects.deals.writeActive on current keyCreate, delete, or make changes to deals. Available to all accounts.
crm.objects.feedback_submission.readNot granted / selector not re-auditedView details about submissions to any of your feedback surveys. Available to Service Hub Professional or Enterprise accounts only.
crm.objects.goals.readActive on current keyView all goals. Available to Sales Hub Starter, Professional, or Enterprise accounts only.
crm.objects.invoices.readActive on current keyView details about invoices. Available to all accounts.
crm.objects.leads.readActive on current keyView properties and other details about leads. Available to Sales Hub Professional or Enterprise accounts only.
crm.objects.leads.writeActive on current keyCreate, delete, or make changes to leads. Available to Sales Hub Professional or Enterprise accounts only.
crm.objects.line_items.readActive on current keyView properties and other details about line items. Available to all accounts.
crm.objects.line_items.writeActive on current keyCreate, delete, or make changes to line items. Available to all accounts.
crm.objects.listings.readActive on current keyView properties and other details about listings. Available to all accounts.
crm.objects.listings.writeNot granted / selector not re-auditedCreate, delete, or make changes to listings. Available to all accounts.
crm.objects.marketing_events.readActive on current keyView details about marketing events. Available to all accounts.
crm.objects.marketing_events.writeActive on current keyCreate, delete, or make changes to marketing events. Available to all accounts.
crm.objects.orders.readActive on current keyView properties and other details about orders. Available to all accounts.
crm.objects.orders.writeNot granted / selector not re-auditedCreate, delete, or make changes to orders. Available to all accounts.
crm.objects.owners.readActive on current keyView details about users assigned to a CRM record. Available to all accounts.
crm.objects.partner-clients.readNot granted / selector not re-auditedView details about partner clients objects. Available to all accounts.
crm.objects.partner-clients.writeNot granted / selector not re-auditedCreate, delete, or make changes to partner clients objects. Available to all accounts.
crm.objects.partner-services.readNot granted / selector not re-auditedView details about partner service objects. Available to all accounts.
crm.objects.partner-services.writeNot granted / selector not re-auditedCreate, delete, or make changes to partner service objects. Available to all accounts.
crm.objects.quotes.readActive on current keyView properties and other details about quotes and quote templates. Available to all accounts.
crm.objects.quotes.writeNot granted / selector not re-auditedCreate, delete, or make changes to quotes (including legacy quotes). Available to all accounts.
crm.objects.services.readActive on current keyView properties and other details about services. Available to all accounts.
crm.objects.services.writeNot granted / selector not re-auditedCreate, delete, or make changes to services. Available to all accounts.
crm.objects.subscriptions.readActive on current keyView properties and other details about commerce subscriptions. Available to all accounts.
crm.objects.users.readActive on current keyView properties and other details about users. Available to all accounts.
crm.objects.users.writeNot granted / selector not re-auditedCreate, delete, or make changes to users. Available to all accounts.
crm.pipelines.orders.readNot granted / selector not re-auditedView details about order pipelines. Available to all accounts.
crm.pipelines.orders.writeNot granted / selector not re-auditedCreate, delete, or make changes to order pipelines. Available to all accounts.
crm.schemas.appointments.readNot granted / selector not re-auditedView details about property settings for appointments. Available to all accounts.
crm.schemas.appointments.writeNot granted / selector not re-auditedCreate, delete, or make changes to property settings for appointments Available to all accounts.
crm.schemas.carts.readNot granted / selector not re-auditedView details about property settings for carts. Available to all accounts.
crm.schemas.carts.writeNot granted / selector not re-auditedCreate, delete, or make changes to property settings for carts. Available to all accounts.
crm.schemas.courses.readNot granted / selector not re-auditedView details about property settings for courses. Available to all accounts.
crm.schemas.courses.writeNot granted / selector not re-auditedCreate, delete, or make changes to property settings for courses. Available to all accounts.
crm.schemas.commercepayments.readActive on current keyView details about property settings for commerce payments. Available to Starter accounts only.
crm.schemas.companies.readActive on current keyView details about property settings for companies Available to all accounts.
crm.schemas.companies.writeActive on current keyCreate, delete, or make changes to property settings for companies. Available to all accounts.
crm.schemas.contacts.readActive on current keyView details about property settings for contacts. Available to all accounts.
crm.schemas.contacts.writeActive on current keyCreate, delete, or make changes to property settings for contacts. Available to all accounts.
crm.schemas.custom.readActive on current keyView details about custom object definitions in the HubSpot CRM. Available to Enterprise accounts only.
crm.schemas.deals.readActive on current keyView details about property settings for deals. Available to all accounts.
crm.schemas.deals.writeActive on current keyCreate, delete, or make changes to property settings for deals. Available to all accounts.
crm.schemas.invoices.readActive on current keyView details about property settings for invoices. Available to all accounts.
crm.schemas.invoices.writeNot granted / selector not re-auditedCreate, delete, or make changes to property settings for invoices Available to all accounts.
crm.schemas.line_items.readActive on current keyView details about line items properties. Available to all accounts.
crm.schemas.listings.readNot granted / selector not re-auditedView details about property settings for listings Available to all accounts.
crm.schemas.listings.writeNot granted / selector not re-auditedCreate, delete, or make changes to property settings for listings Available to all accounts.
crm.schemas.orders.readActive on current keyView details about property settings for orders Available to all accounts.
crm.schemas.orders.writeNot granted / selector not re-auditedCreate, manage, or make changes to property settings for orders Available to all accounts.
crm.schemas.quotes.readActive on current keyView details about quotes and quotes templates. Available to all accounts.
crm.schemas.quotes.writeNot granted / selector not re-auditedCreate, manage, or make changes to property settings for quotes Available to all accounts.
crm.schemas.services.readActive on current keyView details about property settings for services Available to all accounts.
crm.schemas.services.writeNot granted / selector not re-auditedCreate, manage, or make changes to property settings for services Available to all accounts.
crm.schemas.subscriptions.readActive on current keyView details about property settings for commerce subscriptions. Available to all accounts.
crm.schemas.subscriptions.writeNot granted / selector not re-auditedCreate, manage, or make changes to property settings for commerce subscriptions. Available to all accounts.
external_integrations.forms.accessActive on current keyIncludes the ability to rename, delete, and clone existing forms when using the HubSpot WordPress plugin. Available to all accounts.
filesActive on current keyAccess, manage, and upload files in the HubSpot file manager. Available to all accounts.
files.ui_hidden.readNot granted / selector not re-auditedAccess hidden or deleted files uploaded to the HubSpot file manager. Available to all accounts.
formsActive on current keyGrants access to the legacy and v3 forms APIs Available to all accounts.
forms-uploaded-filesActive on current keyGrants access to the legacy v1 uploaded form files API Available to all accounts.
hubdbNot granted / selector not re-auditedRetrieve and manage HubDB data. Available to CMS Hub Professional or Enterprise, or Marketing Hub Professional or Enterprise accounts only.
marketing.campaigns.readActive on current keyView details about marketing campaigns and their associated assets. Available to Marketing Hub Professional or Enterprise accounts only.
marketing.campaigns.revenue.readActive on current keyView revenue details and deal amounts attributed to a marketing campaign. Available to Marketing Hub Professional or Enterprise accounts only.
marketing.campaigns.writeActive on current keyCreate, update, and delete marketing campaigns. Available to Marketing Hub Professional or Enterprise accounts only.
marketing-emailObserved unavailableGrants access to retrieve and send marketing emails. Publishing marketing emails using this API requires Marketing Hub Enterprise. Available to all accounts.
media_bridge.readNot granted / selector not re-auditedGrants access to events and objects from the media bridge API. Available to all accounts.
media_bridge.writeNot granted / selector not re-auditedGrants access to create and update events and objects from the media bridge API. Available to all accounts.
oauthActive on current keyBasic scope required for OAuth. This scope is added by default to all apps. Available to all accounts.
sales-email-readObserved unavailableGrants access to read and manage one-to-one email engagements Available to all accounts.
scheduler.meetings.meeting-link.readActive on current keyRead metadata and booking availability for meeting links Available to Professional accounts only.
settings.billing.writeNot granted / selector not re-auditedMake changes to your account's billing settings. This includes managing and assigning paid seats for users. Available to all accounts.
settings.currencies.readActive on current keyReads existing exchange rates along with the current company currency associated with your HubSpot account. Available to all accounts.
settings.currencies.writeNot granted / selector not re-auditedCreate, update and delete exchange rates along with updating the company currency associated with your HubSpot account. Available to all accounts.
settings.users.readNot granted / selector not re-auditedView details about account users and their permissions. Available to all accounts.
settings.users.writeNot granted / selector not re-auditedManage users and user permissions on your HubSpot account. This includes creating new users, assigning permissions and roles, and deleting existing users. Available to all accounts.
settings.users.teams.readNot granted / selector not re-auditedSee details about the teams in an account. Available to all accounts.
settings.users.teams.writeNot granted / selector not re-auditedAssign users to teams on your HubSpot account. Available to all accounts.
tax_rates.readObserved unavailableView details about tax rates configured in your account. Available to all accounts.
ticketsActive on current keyRetrieve, manage, or create tickets. Available to all accounts.
tickets.highly_sensitiveActive on current keyGrants access to view and edit Highly Sensitive Data properties and values for tickets. Available to Enterprise accounts only.
tickets.sensitiveActive on current keyGrants access to view and edit Sensitive Data properties and values for tickets. Available to Enterprise accounts only.
timelineObserved unavailableGrants access to manage legacy timeline events on HubSpot CRM records. Available to all accounts.
transactional-emailObserved unavailableAccess and manage transactional emails. Available to Marketing Hub Professional or Enterprise accounts with Transactional Email Add-on only.

Observed unavailable scopes

These 17 desired scopes were unavailable or not granted for this portal/key configuration. This is not a universal statement about every HubSpot account or credential type.

Unavailable / not granted — 17cms.performance.readautomation.sequences.writecommunication_preferences.statuses.batch.readtimelinetimeline.readtimeline.writeaccountingbusiness-intelligencebusiness_units_view.readcpq.price_books.readdeveloper.platform_logs.reade-commercemarketing-emailsales-email-readsocialtax_rates.readtransactional-email

Evidence and limits

Visual architecture library

Full-funnel examples from entry signal to proof

These maps show how sources, segments, workflows, emails, links, CRM state, and reporting connect. Illustrative means a proposed blueprint—not a currently active HubSpot workflow. Every production implementation still requires live object IDs, consent/legal review, audience confirmation, suppression reconciliation, testing, and approval.

Illustrative future architecture

Pest Control cold-prospect opportunity

No activation implied
Pest control cold prospect workflow exampleVerified source cohortPest Control decision-makerssource + date + provenanceEligibility gatelawful basis / consentmarketing-contact statusopt-out • bounce • suppressionSEG | NB | DMPest Control GrowthEligible • PRODWF | NB | DMEntry → Email 1 → delayEmail 2 case study → branchEmail 3 ROI → Email 4 demogoal/exit on booking or replyre-enrollment OFFCase-study clicktopic segment + scoreDemo / calendar clickexit nurture + owner taskNo engagementcomplete quietly; no escalation
Cold-outreach guard: do not assume an acquired contact can receive HubSpot marketing email. Validate lawful basis, subscription type, jurisdiction, source terms, and suppression status before enrollment.
Illustrative future architecture

Social comment → guide opt-in → HubSpot nurture

ManyChat / approved social automation
Social comment and guide opt-in workflow exampleSocial postComment keyword: GUIDEplatform event capturedChat automationdeliver DM • explain offercollect email + consentstore source + timestampHubSpot intake gatededuplicate identitysubscription + consent proofsuppression/bounce checkGuide workflowEmail 1: guide deliverynurture by selected topicgoal: demo / qualified replyGuide link clickresource-interest segmentCase-study / topic clickdurable topic segment + scoreDemo / booking clickexit nurture + notify owner
Illustrative future architecture

Website guide request → segmented educational nurture

Inbound opt-in
Landing page
industry + offer promise
HubSpot form
email + consent + source
Deduplication / suppression gateSEG | NB | DM
Guide Request
Delivery emailTopic-click branchesDemo goal / quiet completion

Use separate durable event segments for every meaningful topic. A single “last interest” property cannot preserve multi-topic behavior.

Live precedent / incident-controlled

Existing-client Client Command Center nurture

Pre-publish interlock mandatory
Production client segment
232 attached at incident
Enabled nurture workflowHistorical legacy Email 00 Update
July 30 send-adjacent incident
187 production deliveries3-day delays
Emails 01–07
click-interest segmentsactivation / booking exits
For future revisions: pause/isolate the workflow, verify pending contacts, publish, prove zero unintended campaign-run changes, then separately approve continuation or launch.
Physical email → internal automation

How individual hyperlinks fan out inside HubSpot

Email hyperlinks mapped to HubSpot events, segments, workflow actions and reportingPhysical marketing emailTop product GIF / hero linkDestination: branded walkthrough pageEvent: exact marketing-email link clickPrimary “Book a demo” CTADestination: verified booking/form routeEvent: CTA or tracked-link conversionResource / case-study linkDestination: unique content pageEvent: topic-specific clickWalkthrough-interest pathevent segment membershipoptional approved score/property writecampaign/link reportingHigh-intent conversion pathform/booking confirmationexit nurture • owner task/alertlifecycle change only if approvedTopic-interest pathdurable topic segmentcontent preference / scorefuture branch eligibilityGoverned downstream actionsreport engagement and conversionwrite CRM state only with valid valuesnotify owner/task only if approvedenroll follow-up only with suppression gatepreserve source, timestamp and proof
A click is a signal, not outreach authority. Reporting may be automatic; property writes, lifecycle changes, tasks, alerts, new enrollment, or follow-up email require defined thresholds, valid internal property values, suppressions, ownership, and approval.
Canonical standard

Every name answers the same eight questions

<TYPE> | <LANE> | <ROLE> | <MARKET> | <INITIATIVE> | <SEQUENCE> | <PURPOSE> | <STATE-ENV>

Not every object needs every field in its visible name, but dimensions always remain in this order. Use one space on each side of the pipe. Never invent campaign-specific initials such as OACC.

Relationship lane

CodeMeaning
ECExisting-client retention, adoption, service, expansion, or advocacy.
NBNew-business awareness, demand, qualification, or acquisition.
EC+NBIntentionally shared across both motions.

Audience role

CodeRecipient capacity
CLIENTCurrent client addressed as a client.
DMProspective decision-maker or buying committee.
PARTNERReferral, channel, association, technology, or strategic partner.
INFLInfluencer, analyst, advisor, educator, or recognized voice.
MEDIAJournalist, editor, publisher, podcaster, or producer.

Lane and role are separate dimensions

CombinationExact interpretation
EC | PARTNERPartner communication supporting client delivery, adoption, retention, or expansion.
NB | PARTNERPartner communication supporting referrals or acquisition.
EC | INFLInfluencer outreach supporting client proof, education, or advocacy.
NB | INFLInfluencer outreach building credibility with prospective buyers.
EC | MEDIAMedia communication centered on client success or service adoption.
NB | MEDIAMedia communication intended to create awareness and new demand.
Important: NB describes the business motion supported—not how recently Outsource Access met the partner, influencer, or media contact.

Object prefixes and exact templates

ObjectPrefixTemplate
CampaignCMPCMP | LANE | ROLE/MULTI | MARKET | INITIATIVE | PERIOD | STATE
Segment/ListSEGSEG | LANE | ROLE | MARKET | INITIATIVE | PURPOSE | STATE-ENV
WorkflowWFWF | LANE | ROLE | MARKET | INITIATIVE | FUNCTION | PURPOSE | STATE-ENV
Marketing emailEMEM | LANE | ROLE | MARKET | INITIATIVE | N | PURPOSE | STATE-ENV
FormFRMFRM | LANE | ROLE | MARKET | INITIATIVE | PURPOSE | STATE-ENV
Landing pageLPLP | LANE | ROLE | MARKET | INITIATIVE | PURPOSE | STATE-ENV
CTACTACTA | LANE | ROLE | MARKET | INITIATIVE | PURPOSE | VARIANT | STATE-ENV
AssetASTAST | LANE | ROLE/MULTI | MARKET | INITIATIVE | PURPOSE | VARIANT | STATUS
ReportRPTRPT | LANE | ROLE | MARKET | INITIATIVE | METRIC | PERIOD
DashboardDSHDSH | LANE | ROLE/MULTI | MARKET | INITIATIVE | PURPOSE

Client Dashboard example

  • CMP | EC | CLIENT | ALL | Client Dashboard Launch | 2026-Q3 | ACTIVE
  • SEG | EC | CLIENT | ALL | Client Dashboard Launch | Eligible | ACTIVE-PROD
  • WF | EC | CLIENT | ALL | Client Dashboard Launch | Main | Nurture | ACTIVE-PROD
  • EM | EC | CLIENT | ALL | Client Dashboard Launch | 1 | Announcement | ACTIVE-PROD

Pest Control example

  • CMP | NB | MULTI | Pest Control | Pest Control Growth | 2027-Q1 | DRAFT
  • SEG | NB | DM | Pest Control | Pest Control Growth | Apollo Source | DRAFT-PROD
  • SEG | NB | MEDIA | Pest Control | Pest Control Growth | Podcast Hosts | DRAFT-PROD
  • WF | NB | DM | Pest Control | Pest Control Growth | Main | Nurture | DRAFT-PROD

Governance rules

  • Use approved prefixes and codes only
  • Use ALL for intentionally cross-industry assets
  • Start email sequences at 1 and continue with unpadded integers: 2, 3, through 10+; never use 00, 01, or other zero padding
  • Use DRAFT, REVIEW, READY, ACTIVE, PAUSED, COMPLETE, or ARCHIVED
  • Use PROD, TEST, or SBX for environment
  • Never use “final,” “final-final,” “new,” or a person’s name as version control
  • Search for the target canonical name before creating any object
  • Record owner, source, created date, campaign, and dependencies in the asset registry
Three surfaces

Published email versus pending revision

SurfaceWhat it showsCorrect use
Email name / performanceThe currently published email and reporting.Use to see what is live.
Edit EmailThe auto-saved unpublished revision on the same email ID.Use to review or modify pending changes.
Version historyHistorical published/saved versions.Use for reference only; do not restore while a newer draft is under review.

Revision protocol

  1. Read the live email and pending draft separately.
  2. Identify every connected workflow and read enabled state, attached audience, enrollment history, eligible/pending contacts, delays, and suppressions.
  3. If every connected workflow is OFF, publication alone will not send; verify it remains OFF. If any workflow is ON, pause/isolate it or obtain explicit approval for the waiting/new/re-enrolled contacts that may still reach the action.
  4. Change only the intended modules; inspect links, media, source order, folder, and AUTOMATED_EMAIL type.
  5. Publish only after the pre-publish interlock passes.
  6. Read back the live email, workflow, enrollment state, and all campaign-run IDs immediately.

Publication capability

Draft-write access and publication access are different HubSpot capabilities. A successful draft update is not proof the revision is live.

Blocked publication: state “revision prepared; authenticated Review and update still required.” Never call it published.
HubSpot’s Update button publishes the latest email asset; it does not itself enroll contacts or replay completed actions. Treat it as send-adjacent—not as a send command—when an enabled workflow has contacts still able to reach that email step.

Folder and naming

  • Place every Sterling-created email in Sterling Emails (Brad).
  • Verify the folder ID after creation or correction.
  • Do not rely on Created by Brad as authoritative for API-created assets.
  • Do not rely on contains exactly as if it were a reusable internal-name prefix filter.
Publication boundary verified July 30, 2026

Draft editing is available; API publication is not

The current Service Key can create, clone, read, and edit Marketing Email drafts through content. It cannot currently publish/unpublish because marketing-email is unavailable and HubSpot separately gates those endpoints by product entitlement. Brad performs Review and publish in the UI until both gates are proven.

Distinct visual roles

  • Product animation: demonstrates the dashboard or product experience.
  • Presenter walkthrough: shows Brad speaking in the Loom walkthrough.
  • Do not silently replace one with the other.
  • Place captions immediately above the intended visual.

File hosting

  • Email images and animated GIFs must be copied into HubSpot Files; the Mac mini is an authoring source, never the recipient-facing host.
  • Use a content-hash-qualified filename, intentional public-but-not-indexed access, and the final hubspotusercontent URL.
  • Require anonymous HTTP 200, expected MIME, safe bytes, dimensions, frame count, looping behavior, and meaningful alt text.
  • A successful upload, filename, or old module reference is not proof the email visibly renders the asset.
Permanent storage map

Where Sterling-created media belongs

AssetWorking sourceDurable destination
Email image or animated GIFMay be created temporarily on the Mac miniHubSpot Files in the correct portal/folder
Full generated videoTemporary Mac master onlyBrad's personal Vimeo Team Library → Sterling videos (folder 30060478)
Generated non-email imageTemporary Mac working fileSterling Media on Brad's personal Cloudflare account
Never embed: file://, /Users/..., localhost, or another Mac-local path. Do not use Mac-local or general Cloudflare hosting for generated videos unless Brad changes the standing rule.

Animated GIF persistence and visibility gate

  1. QA the source GIF: safe first frame, more than one frame, appropriate dimensions/weight, no private data.
  2. Close every open Edit Email session before an external draft write.
  3. Upload with a content-hash-qualified filename and replace the intended module with the exact new HubSpot URL.
  4. Preserve alt text, responsive dimensions, click destination, caption, and required source order.
  5. Require two delayed, identical draft readbacks after the autosave window.
  6. Render the exact saved block; verify natural dimensions and capture two different frames to prove animation.
  7. Visually inspect the result. A blank gap or broken placeholder fails the gate.

Landing-page destination gate

  1. Deploy the page first.
  2. Verify the canonical path renders the intended unique content.
  3. Verify the embedded media and CTA destination.
  4. Check the immutable deployment and custom domain.
  5. Only then update email images or CTAs to that page.
A marketing-site homepage fallback can return HTTP 200 for a missing subpath. A 200 response alone is not sufficient.

Client Command Center precedent

The flagship announcement uses three separate clickable elements—the top dashboard animation, Brad's Loom-preview GIF under “A quick walkthrough of the dashboard.”, and the primary button. Brad directed all three to the branded Cloudflare walkthrough page. The full interactive demo remains available from that landing page.

Workflow status must be explicit

ClaimRequired proof
Workflow builtWorkflow graph, actions, branches, and referenced email IDs.
Workflow activeisEnabled: true or equivalent live UI proof.
Contact enrolledEnrollment record for the exact contact/list and timestamp.
Email sentDelivery/event or recipient inbox proof—not publication.

Safe publication behavior

Publishing makes the latest automated-email version available to referencing workflows. It does not replay the action or resend prior recipients. If the workflow is OFF, publication alone does not send. If it is ON, contacts waiting before the action, newly enrolled, or re-enrolled can receive the latest version when the action executes; pause/isolate or prove that exposure safe before publishing. If HubSpot offers a new workflow attachment, choose I'll do this later unless attachment is separately approved.

Inactive-by-default rule

Builds, drafts, lists, and workflow graphs remain disconnected from production audiences. For an existing live workflow, confirm it is paused or isolated before publishing an email revision, then re-read workflow state, enrollment history, pending contacts, and campaign counters after publication.

Testing sequence

Static readbackPreview/editor QAApproved test recipientDelivery proofBrad reviewSeparate activation decision
Permission preflight

Workflow build/edit/activation capability does not erase the separate email-publication gate. Before launch, verify the connected email is published, the exact audience is approved, and the API Permissions handoff is complete.

Behavioral workflow reference

Three distinct workflow classes

ClassPurposeDefault state
Main nurtureAudience, cadence, sends and completion.Default OFF until exact release. Historical July 30 evidence showed the Client Dashboard nurture ON; refresh live state before action.
Interest capturePreserve behavior and update governed CRM state.OFF until event/property canary.
Behavioral follow-upWait, branch and send context-aware resources.OFF until copy, deduplication, suppression and audience approval.

See Behavioral automation.

Live audit · July 30, 2026

Interest tracking & behavioral automation

This reference architecture turns identified customer or prospect behavior into durable CRM evidence and governed follow-up. It separates measurement, classification, and customer-facing action so a click never silently becomes authority to send.

Historical live audit · July 30, 2026

All 10 Client Dashboard Launch workflows

Historical labels: zero-padded names below are preserved only because they identify the exact live objects audited on July 30. New and renamed sequences use 1, 2, 3 with no zero padding. Refresh enabled states and counts before operational use.
WorkflowStateActual purposeEnrollment triggerActionsDurable segment
1858142032
WF | EC | CLIENT | Client Dashboard Launch | Nurture | PROD
ONProduction nurture sequenceSegment 4633oa_cc_activation_status=not_started
oa_cc_nurture_status=completed
1858125171
WF | EC | CLIENT | Client Dashboard Launch | Interest Capture | 00 Overview | PROD | OFF
OFFOne-time email-click classifierAny tracked-link click
430377925
oa_cc_engagement_score=10
oa_cc_activation_status=active_explorer
4632 · 11 contacts
1858126107
WF | EC | CLIENT | Client Dashboard Launch | Interest Capture | 01 Team & Performance | PROD | OFF
OFFOne-time email-click classifierAny tracked-link click
430377940
oa_cc_engagement_score=20
oa_cc_activation_status=active_explorer
oa_cc_last_module_engaged=performance
oa_cc_interest_track=performance
4571 · contacts
1858142980
WF | EC | CLIENT | Client Dashboard Launch | Interest Capture | 02 Financial Visibility | PROD | OFF
OFFOne-time email-click classifierAny tracked-link click
430377934
oa_cc_engagement_score=30
oa_cc_activation_status=active_explorer
oa_cc_last_module_engaged=roi
oa_cc_interest_track=roi
4572 · contacts
1858142981
WF | EC | CLIENT | Client Dashboard Launch | Interest Capture | 03 Process Control | PROD | OFF
OFFOne-time email-click classifierAny tracked-link click
430379523
oa_cc_engagement_score=40
oa_cc_activation_status=active_explorer
oa_cc_last_module_engaged=playbook
oa_cc_interest_track=playbook
4573 · contacts
1858142982
WF | EC | CLIENT | Client Dashboard Launch | Interest Capture | 04 Strategic Advisory | PROD | OFF
OFFOne-time email-click classifierAny tracked-link click
430377221
oa_cc_engagement_score=50
oa_cc_activation_status=active_explorer
oa_cc_last_module_engaged=strategic
oa_cc_interest_track=strategic
4574 · contacts
1858142985
WF | EC | CLIENT | Client Dashboard Launch | Interest Capture | 05 Market Intelligence | PROD | OFF
OFFOne-time email-click classifierAny tracked-link click
430380615
oa_cc_engagement_score=60
oa_cc_activation_status=active_explorer
oa_cc_last_module_engaged=intelligence
oa_cc_interest_track=intelligence
4575 · contacts
1858125648
WF | EC | CLIENT | Client Dashboard Launch | Interest Capture | 06 Human + AI | PROD | OFF
OFFOne-time email-click classifierAny tracked-link click
430379516
oa_cc_engagement_score=70
oa_cc_activation_status=active_explorer
oa_cc_last_module_engaged=human_ai
oa_cc_interest_track=human_ai
4576 · contacts
1858125172
WF | EC | CLIENT | Client Dashboard Launch | Interest Capture | 07 Mobile Access & Support | PROD | OFF
OFFOne-time email-click classifierAny tracked-link click
430380619
oa_cc_engagement_score=80
oa_cc_activation_status=active_explorer
oa_cc_last_module_engaged=mobile_support
oa_cc_interest_track=mobile_support
4577 · contacts
1858119352
Historical live label: WF | INT | TEST | Client Dashboard Launch | Email 00 | MANUAL
OFFHistorical Brad-only manual Email 00 testManual enrollmentSend 218124282752
Critical contradiction: workflow 1858142032 is ON while its description says “Inactive production nurture.” The eight middle workflows are OFF click-interest classifiers—not inactivity trackers.

Historical legacy Email 00: what actually happened

  • The historical legacy Email 00 field-writing workflow is OFF; it did not write score or activation status.
  • Dynamic segment 4632 independently preserves the click event and contained 11 contacts at audit time.
  • Click evidence exists, but the disabled workflow did not categorize those contacts through CRM property actions.
  • The segment count is time-sensitive and must be refreshed before operational use.

What the old classifiers do—and do not do

  • Trigger on any tracked link in one email-event group, not a specific CTA.
  • No re-enrollment; repeat clicks do not rerun them.
  • Overwrite scores with 10/20/30…80; this is sequence position, not cumulative scoring.
  • No delay, branch, follow-up email, task, owner alert, webhook, or custom code.
  • Multi-topic history is preserved separately through dynamic click segments.

Verified live property writes

EmailScoreStatusLatest module / interestSegment count
00 Announcement10active_explorerNot written11
01 Team & Performance20active_explorerperformance0
02 Financial Visibility30active_explorerroi0
03 Process Control40active_explorerplaybook0
04 Strategic Advisory50active_explorerstrategic0
05 Market Intelligence60active_explorerintelligence0
06 Human + AI70active_explorerhuman_ai0
07 Mobile & Support80active_explorermobile_support0
Release blocker: oa_cc_interest_track is a multi-checkbox field. Canary-test whether the action appends or replaces values before enabling any tracker.
Reusable signal catalog

Documented HubSpot behavioral triggers

SignalSupported patternConstraint
Email openedEvent or filter triggerWeak signal: privacy opens, scanners and pixel blocking distort intent.
Any email-link clickAny qualifying tracked link in a selected emailDoes not identify topic unless the email context is narrow.
Specific email + URL clickRefine by email and Original/Raw URLUse URL contains, not tracked-URL equality; forwarded clicks may attribute to the original recipient.
Repeat clickRe-enroll per event, increment numeric property, branch at thresholdComposed counter; no documented native “clicked N times” email trigger.
CTA click/viewCurrent and legacy CTA eventsCount/date refinements vary by CTA generation and tier.
Page visitURL event/filter; count or date refinementKnown contact required; no anonymous-history replay; downloads are not page views.
Form interaction/submissionView, field interaction, or submissionSubmission is higher-confidence evidence.
Segment membershipAdded/removed event or membership filterActive lists are criteria-driven; workflow list actions change static lists.
Property changedExact CRM property transitionValidate internal values before writes or branches.
Custom eventVisited URL, clicked element, or custom eventKnown contact required; codeless event supports up to 30 URLs/elements.
Ad interactionNetwork and interaction-type refinementsConnected ad data required.
Meeting / replyBooked meeting, outcome change, marketing-email replyHigh-confidence signals; do not generalize to arbitrary inbox replies.
Non-occurrenceDelay, then test whether event/state occurredNot a direct event trigger.

Orchestration and action palette

WAITDuration, weekday-aware, date/property date, event-or-timeout.
DECIDEAND/OR branch, property/output branch, random split, goal, suppression, exit.
COMMUNICATEApproved automated email, in-app/internal notification.
OPERATETask; set, append, replace, clear, copy or increment properties.
ROUTEStatic-list action or another same-object workflow.
INTEGRATEConnected app; webhook/custom code with Data Hub Pro/Enterprise.
Processing buffers: allow about five minutes before branching on a just-sent email or form-dependent property. Analytics-dependent page-view branches may need 80 minutes.
Target nurture model

Canonical sequence: announcement + six follow-ups

PositionCategoryReplacement interest architecture
1AnnouncementTrack demo and walkthrough links separately.
2Team & PerformancePeople, accountability, performance and team-value signals.
3Financial VisibilityROI, billing, margin, WIP, invoicing and calculator signals.
4Process ControlPlaybooks, SOPs, controls and improvement signals.
5Strategic AdvisoryPlanning, advisory and next-best-action signals.
6Market IntelligenceResearch, opportunities, competitors and initiative signals.
7Human + AI, Mobile Access & SupportCanonical consolidation of the two historical legacy categories formerly labeled Emails 06 and 07.
Do not rename old trackers as if this is live. Build and prove the consolidated emails/events first, then replace or remap trackers by immutable ID.
Marketing Machine reference scenario

Custom proposal click → two-day calculator follow-up

Specific proposal-link clickTimestamp + topic + countWait 2 daysExit checksCalculator emailVisit · submit · meeting
  1. Match the exact company-proposal path through normalized URL-contains logic.
  2. Write first-click timestamp/topic; increment a numeric counter only if repeat scoring is required.
  3. Wait two days.
  4. Exit if the contact replied, booked, converted, opted out, became suppressed, hit contact-pressure limits, or already received the calculator.
  5. Send the approved calculator email to the primary address.
  6. Write calculator-sent timestamp/status to prevent duplication; optionally create a task or static-segment membership.
  7. Measure calculator visit/submission and business outcome—not open alone.

Reusable behavioral workflow

ENTRY
event · state · schedule
QUALIFY
identity · asset · URL · confidence
WAIT
duration · date · event/timeout
DECIDE
branch · goal · suppress · exit
EFFECT
email · task · field · route
PROVE
event · action · outcome
Every node carries enabled state, tier, tracking/consent dependency, re-enrollment, deduplication, API/UI support, approval, stop owner and rollback proof.
Naming, description and release controls

Every behavioral workflow must explain itself

Name: WF | <LANE> | <ROLE> | <MARKET> | <INITIATIVE> | Behavior | <SIGNAL→OUTCOME> | <STATE-ENV>

Description: exact event and asset/URL; interpretation; occurrence rule; fields/internal values; durable segment; wait; branches/exits; customer/internal actions; deduplication; suppression/contact pressure; tier; API/UI boundary; enabled state.

Metadata edits: UI name/description changes are behavior-neutral when no trigger, action, setting or enabled state changes. The API update is a full PUT requiring the latest revision; omitted fields are removed. Description updates are API-uncertain. Use UI for description-only corrections and compare complete before/after workflow graphs.
  1. Read workflow, email, segment and property schemas.
  2. Validate event/URL identity and every internal property value.
  3. Confirm tier and API/UI capability.
  4. Keep new trackers and branches OFF.
  5. Run one approved test-contact canary.
  6. Verify event, field, segment, delay, branch, send and deduplication separately.
  7. Obtain exact activation/audience approval.
  8. Activate with monitoring, stop owner and rollback.

API and product boundaries

CapabilityBoundary
Workflow read/create/update/deleteautomation scope; Professional/Enterprise. Full PUT updates; API delete is destructive.
Automated email, random split, page/CTA trigger, codeless eventMarketing Hub Professional/Enterprise and applicable permissions.
Webhook / JavaScript custom codeData Hub Professional/Enterprise; UI availability does not prove v4 API construction.
Activation, enrollment, customer emailSeparate approval plus exact audience, suppression and send proof.
Name/description correctionsUI metadata; never issue a name-only API PUT.

See API permissions for current-key versus official-catalog evidence.

Audience confirmation

  • Inventory list metadata without exporting unnecessary member data.
  • Verify inclusion, exclusion, suppression, and actual email-bearing counts.
  • Never infer the production audience from a list name alone.
  • Require Brad to confirm the exact audience before enrollment or sending.

Send authority

  • A preview is not a send.
  • A test email is a real external send.
  • A workflow simulation is not delivery.
  • Publication is a separate proof state and does not replay completed sends. In an enabled workflow, waiting, newly enrolled, or re-enrolled contacts can receive the latest version when the send action executes.
  • Production release requires the exact email, audience, account, timing, approved content, workflow state, and enrollment consequence.
Guarded action

Before any test or production delivery

  • Exact recipient or audience approved
  • Subject, preview text, body, sender identity, and subscription type verified
  • Every link and image checked
  • Suppression and exclusion rules read back
  • Every connected workflow paused/isolated or exact live-release consequence approved
  • Eligible, enrolled, pending, suppressed, dropped, and deferred states reconciled
  • Post-publication campaign-run IDs and delivery proof captured

Pre-publication checklist

  • Visible brand copy says Outsource Access as two words
  • Typography is restrained and mobile-safe
  • Requested product and presenter GIFs are distinct and correctly ordered
  • Email images/GIFs use content-hash-qualified HubSpot Files URLs—not Mac-local paths
  • Image URLs return expected MIME types and safe bytes
  • Exact saved GIF blocks visibly render at natural dimensions and change frames
  • Two delayed draft readbacks are stable after the editor is closed
  • Destinations render the intended unique pages
  • Tracking parameters are present once—never duplicated
  • Folder and automated-email type are correct
  • API Permissions matrix reviewed; every manual handoff has an owner and timing
  • Scope, endpoint writability, entitlement, approval and proof were evaluated separately
  • Campaign owner is Brad Stevens and was verified through the UI
  • Campaign start date matches launch/creation date; end date matches the final scheduled action
  • Published and draft objects were read separately
  • Every connected workflow, audience, enrollment history, re-enrollment setting, and contact position relative to the email action was read before publication
  • Enabled workflows were paused/isolated or the exact release was explicitly approved
  • Rollback/continuation route is documented

After publication

  1. Read the authoritative live email object.
  2. Verify subject, preview text, modules, media, alt text, and CTA URLs.
  3. Confirm the publish timestamp and exact connected workflow states.
  4. Read enrollment history and decompose every new allEmailCampaignIds run.
  5. Report sent, delivered, dropped, deferred, suppressed/not-sent, and pending separately.
  6. If any unintended send occurred, notify Brad immediately and do not silently continue the workflow.

Evidence language

Use precise labels:

  • Draft prepared
  • Published update verified
  • Workflow inactive
  • No contact enrolled
  • No email sent — campaign-run and event counters verified unchanged

Never compress these into “campaign complete.”

Fast decision table

If Brad asks…Default operating response
“What must I do manually?”Open API permissions; use the current manual-step list and never infer capability from scope count.
“Create a campaign.”Create the campaign with canonical naming; set start to the verified launch/creation date and end to the final scheduled action; assign Brad Stevens as owner through HubSpot UI; read back all three.
“Edit this published email.”Edit and QA the pending revision. If connected workflows are OFF, publishing alone does not send; verify OFF state and unchanged counters. If any workflow is ON, distinguish completed recipients from waiting/new/re-enrolled contacts and pause/isolate unresolved execution paths before publication.
“Let me review it.”Clarify whether Brad wants the live version or pending editor revision; provide the direct link.
“Test it.”Confirm the exact approved recipient; send only after approval and verify delivery.
“Turn it on.”Confirm immutable workflow/list IDs, exact eligible count, suppressions, sender/content, timing, exits, rollback, and post-launch proof before activation or enrollment.
“Use this image.”Host it, HTTP/MIME-check it, inspect safety/animation, then update the intended module.
“Link to this page.”Deploy and unique-page verify first; then patch and read back the destination.

Current permanent conventions

  • Email folder: Sterling Emails (Brad)
  • Email images/GIFs: HubSpot Files with content-hash-qualified names
  • Generated videos: Vimeo → Sterling videos (30060478)
  • Generated non-email images: Sterling Media Cloudflare project
  • Review: normal email view shows published version
  • Pending revision: open through Edit Email
  • Historical content: Version history; do not restore casually
  • Internal page subsections: wrapped top tabs with deep links
  • API permissions: scope, endpoint, entitlement, approval, manual owner, and proof are separate
  • Learning log: immutable date/time, failure, prior model, actual behavior, impact, and correction
  • Campaign owner: Brad Stevens; UI-assigned and verified
  • Campaign dates: launch/creation through final scheduled email/action

Authority summary

May prepare: drafts, assets, lists, workflow foundations, QA evidence.

Requires direct approval: publication after the connected-workflow interlock, test sends, workflow activation, contact enrollment, production sends, credentials, destructive cleanup, and customer-data mutations. An explicit edit request never overrides the pause/isolation requirement for an enabled workflow unless Brad explicitly approves the exact live audience release.