Marketing agents: 5 use cases
Marketing agents live in HubSpot but reach into Salesforce and Atlassian. Cross-boundary writes and sensitive scopes are the watch-list.
ServiceNowSalesforceHubSpotAtlassian Each step lists the resource and the exact permission or role the agent uses.
Campaign brief-to-launch orchestration
- TriggerCampaign brief approved on a Confluence page
- Atlassian1Read approved brief
read:page:confluence - Atlassian2Create production tasks
write:issue:jira - HubSpot3Build audience
crm.lists.read, crm.segments.write - HubSpot4Schedule the send
marketing.email.write - ParapetSegments outside the brief are denied.Deny excess
crm.segments.write lets the agent create net-new segments beyond the brief. Parapet keeps segment creation inside the approved audience definition, so an opted-out contact cannot land back in a live send list.
Lead capture & CRM handoff to Sales
- TriggerNew registrant in HubSpot marketing_events
- HubSpot1Read registrant
crm.objects.marketing_events.read / .write - HubSpot2Update contact & company
contacts read/write · companies.write - Salesforce3Create Lead
Lead: PermissionsCreate - Salesforce4Attribute to campaign
CampaignMember: PermissionsCreate - ParapetCross-boundary write surfaced for RevOps approval.Gate / review
A HubSpot-scoped marketing agent writing to salesforce:Lead — a system Sales owns — is a cross-boundary write that stays invisible without discovery. Parapet maps the path so RevOps can approve it.
Email nurture performance reporting
- TriggerWeekly reporting job
- HubSpot1Read emails
crm.objects.emails.read - HubSpot2Read send / open / click
marketing.email.read - HubSpot3Read content performance
content_tools.analytics.read - HubSpot4Read account scoring
buyer_intent.read - Atlassian5Publish report
write:page:confluence - ParapetAlert if the credential requests any write scope.Gate / review
buyer_intent.read is a sensitive, easily over-granted scope. Parapet flags any holder not constrained to read-only aggregate reporting, and alerts if the same credential ever requests a write scope.
Content publishing & landing-page compliance gate
- TriggerNew landing page drafted for a live campaign
- HubSpot1Read page and blog drafts
cms.pages.landing_pages.read, cms.blogs.blog_posts.read - Atlassian2Confirm legal / brand approval
read:page:confluence, read:content.restriction:confluence - Atlassian3Log go-live task
write:issue:jira - ParapetPublish blocked until approval resolves.Deny excess
Publishing proceeds only if the approval page’s restriction resolves to “approved.” This closes the gap where an agent without proper Confluence access assumes a draft is final.
Campaign-to-revenue attribution close-loop
- TriggerQuarter-end ROI analysis
- Salesforce1Read converted members
CampaignMember: PermissionsRead, PermissionsViewAllRecords - HubSpot2Cross-reference deals
crm.objects.deals.read - HubSpot3Cross-reference events
crm.objects.marketing_events.read - Atlassian4Write summary
write:page:confluence - ParapetScoped to campaign-linked records; quarterly re-audit.Deny excess
ViewAllRecords on CampaignMember exposes every member org-wide, including those tied to confidential enterprise deals. Parapet scopes it to campaign-linked records and re-audits the grant quarterly.
See what your agents actually hold.
Discover, inventory and enforce across every connected SaaS system.