Home › Use cases › Sales
CRO · converting leads into accounts

Sales agents: 5 use cases

Lead-to-cash agent chains: the costliest failures are ordering mistakes — skipped approvals and premature provisioning.

ServiceNowSalesforceHubSpotAtlassian Each step lists the resource and the exact permission or role the agent uses.

S1

Lead-to-opportunity qualification

  1. TriggerSalesforce Lead marked “Marketing Qualified”
  2. Salesforce1Read LeadLead: PermissionsRead
  3. HubSpot2Enrich firmographicscontacts, companies · read
  4. Salesforce3ConvertOpportunity, Account, Contact: PermissionsCreate
  5. ParapetDelete on Lead denied; alert on attempt.Deny excess
Why Parapet

Conversion is not deletion. Parapet ensures PermissionsDelete on Lead is never exercised by this agent, and alerts if the credential ever calls delete — that belongs to a data-hygiene bot.

− granted: Lead: PermissionsDelete available
+ needed: Create / Edit only
S2

Quote-to-order deal desk automation

  1. TriggerRep requests pricing on an Opportunity
  2. Salesforce1Read OpportunityOpportunity: PermissionsRead
  3. HubSpot2Create quote & line itemsquotes.read, schemas.quotes.write · line_items write
  4. Atlassian3Over threshold: open deal-desk requestwrite:request:jira-service-management, write:request.approval:jira-service-management
  5. Salesforce4Create OrderOrder: PermissionsCreate
  6. ParapetHuman approval required before Order.Gate / review
Why Parapet

The discount-approval gate is structural: the agent cannot progress to Order until the linked JsmRequest shows read:request.approval = approved. No skipping the human-in-the-loop step.

− granted: Order creatable before approval
+ needed: Order only after approval = approved
S3

Contract generation & Legal handoff

  1. TriggerOpportunity reaches “Closed Won”
  2. Salesforce1Read OpportunityOpportunity: PermissionsRead
  3. Salesforce2Generate ContractContract: PermissionsCreate
  4. Atlassian3Route to LegalJsmRequest: write:request:jira-service-management · JsmServiceDesk
  5. ParapetSales edit suspended during Legal review.Deny excess
Why Parapet

This is where Sales’ write scope must stop and Legal’s begin (see L1). Parapet suspends the Sales agent’s PermissionsEdit on that Contract once the request is filed, until Legal sets “Sales-Ready.”

− granted: Both teams’ bots can edit the Contract
+ needed: One writer at a time, by status
S4

Account health & renewal risk monitoring

  1. TriggerScheduled renewal-risk scan
  2. Salesforce1Read accounts, orders, assetsAccount, Order, Asset: PermissionsRead · Account: ViewAllRecords
  3. HubSpot2Read support tickets as churn signalcrm.objects.tickets.read
  4. Atlassian3Create renewal issue for CSMwrite:issue:jira
  5. ParapetCross-department flow inventoried and approved.Gate / review
Why Parapet

Reading hubspot:tickets pulls support-case content into a Sales-owned agent. Parapet inventories this Support → Sales data flow so it must be declared, not silently available via a shared integration user.

− granted: Undeclared Support → Sales data flow
+ needed: Declared, approved data flow
S5

Deal-desk-to-provisioning order kickoff

  1. TriggerContract fully executed by Legal and customer
  2. Salesforce1Confirm status = ActivatedContract: PermissionsRead
  3. Salesforce2Create / edit OrderOrder: PermissionsCreate, PermissionsEdit
  4. Salesforce3Create Asset for provisioningAsset: PermissionsCreate
  5. ServiceNow4Notify Finance billingsc_request · role:public
  6. ParapetOrder blocked until Contract is Activated.Deny excess
Why Parapet

Order creation only fires after the Contract read confirms Activated — preventing the race where an agent provisions and bills a deal before it is legally executed.

− granted: Order creatable at any contract status
+ needed: Order only after Contract = Activated

See what your agents actually hold.

Discover, inventory and enforce across every connected SaaS system.