Overview

One deduped pool of people, fed by your apps at process completion. Cold data stays quarantined until someone engages.

Pool composition by owning team
How a person moves through the pool
The rules in force

Contacts — the engaged pool

One golden record per person. Deduped on phone → email. Every row carries its owning team, sources, and consent.

PersonContactOwner teamSources (provenance)ConsentStatusAccess

Cold Prospects — quarantined

Unknown-source data (scraped, sourced, bought). Not marketable. Promotes into Contacts only when the person engages.

PersonContactSource appAcquiredAction

Suppression — do not contact

Absolute blocklist. Overrides every share and every campaign. Nobody can message these people, ever.

PersonContactReasonSince

Lists — every imported list

An import is a list (ADR-002). All teams' lists in one place — who imported it, from which app, and when.

ListTeamSource appImported byImportedContacts

Access & Governance

Group-based (Odoo-style, via Authentik groups) · the data owner controls sharing · consent & suppression always override.

Every campaign send passes this gate

Apps

Shared engagement apps that sit on top of the pool. Any team can use them — but every send draws from the central CRM and passes the consent + suppression + purpose gate.