Home › Use cases › Marketing
CMO · campaigns that generate sales leads

Marketing agents: 5 use cases

Marketing agents live in HubSpot but reach into Salesforce and Atlassian. Cross-boundary writes and sensitive scopes are the watch-list.

ServiceNowSalesforceHubSpotAtlassian Each step lists the resource and the exact permission or role the agent uses.

M1

Campaign brief-to-launch orchestration

  1. TriggerCampaign brief approved on a Confluence page
  2. Atlassian1Read approved briefread:page:confluence
  3. Atlassian2Create production taskswrite:issue:jira
  4. HubSpot3Build audiencecrm.lists.read, crm.segments.write
  5. HubSpot4Schedule the sendmarketing.email.write
  6. ParapetSegments outside the brief are denied.Deny excess
Why Parapet

crm.segments.write lets the agent create net-new segments beyond the brief. Parapet keeps segment creation inside the approved audience definition, so an opted-out contact cannot land back in a live send list.

− granted: crm.segments.write, unbounded
+ needed: Segments limited to the approved audience
M2

Lead capture & CRM handoff to Sales

  1. TriggerNew registrant in HubSpot marketing_events
  2. HubSpot1Read registrantcrm.objects.marketing_events.read / .write
  3. HubSpot2Update contact & companycontacts read/write · companies.write
  4. Salesforce3Create LeadLead: PermissionsCreate
  5. Salesforce4Attribute to campaignCampaignMember: PermissionsCreate
  6. ParapetCross-boundary write surfaced for RevOps approval.Gate / review
Why Parapet

A HubSpot-scoped marketing agent writing to salesforce:Lead — a system Sales owns — is a cross-boundary write that stays invisible without discovery. Parapet maps the path so RevOps can approve it.

− granted: Undocumented marketing → Salesforce write path
+ needed: Path declared and approved by RevOps
M3

Email nurture performance reporting

  1. TriggerWeekly reporting job
  2. HubSpot1Read emailscrm.objects.emails.read
  3. HubSpot2Read send / open / clickmarketing.email.read
  4. HubSpot3Read content performancecontent_tools.analytics.read
  5. HubSpot4Read account scoringbuyer_intent.read
  6. Atlassian5Publish reportwrite:page:confluence
  7. ParapetAlert if the credential requests any write scope.Gate / review
Why Parapet

buyer_intent.read is a sensitive, easily over-granted scope. Parapet flags any holder not constrained to read-only aggregate reporting, and alerts if the same credential ever requests a write scope.

− granted: buyer_intent.read with open-ended usage
+ needed: Read-only aggregate reporting
M4

Content publishing & landing-page compliance gate

  1. TriggerNew landing page drafted for a live campaign
  2. HubSpot1Read page and blog draftscms.pages.landing_pages.read, cms.blogs.blog_posts.read
  3. Atlassian2Confirm legal / brand approvalread:page:confluence, read:content.restriction:confluence
  4. Atlassian3Log go-live taskwrite:issue:jira
  5. ParapetPublish blocked until approval resolves.Deny excess
Why Parapet

Publishing proceeds only if the approval page’s restriction resolves to “approved.” This closes the gap where an agent without proper Confluence access assumes a draft is final.

− granted: Publish on assumed approval
+ needed: Publish only after verified approval
M5

Campaign-to-revenue attribution close-loop

  1. TriggerQuarter-end ROI analysis
  2. Salesforce1Read converted membersCampaignMember: PermissionsRead, PermissionsViewAllRecords
  3. HubSpot2Cross-reference dealscrm.objects.deals.read
  4. HubSpot3Cross-reference eventscrm.objects.marketing_events.read
  5. Atlassian4Write summarywrite:page:confluence
  6. ParapetScoped to campaign-linked records; quarterly re-audit.Deny excess
Why Parapet

ViewAllRecords on CampaignMember exposes every member org-wide, including those tied to confidential enterprise deals. Parapet scopes it to campaign-linked records and re-audits the grant quarterly.

− granted: ViewAllRecords on CampaignMember org-wide
+ needed: Campaign-linked records only

See what your agents actually hold.

Discover, inventory and enforce across every connected SaaS system.