A source is more useful than a confident sentence
The fictional company announcement describes UK expansion after a funding round. Retain its source URL and retrieval date with the extracted observation.
Use AI models to turn researched sales signals into relevant messages. Follow the evidence into the draft, inspect the fields that carry it, and separate useful personalization from unsupported filter-bypass claims.
A model extracts or writes. An agent coordinates tools, records and decisions. A merge field carries the resulting value into a template. None of those steps makes an unsupported claim true.
Interactive walkthrough with fictional records and fixed rules. No live model, web research or email sending runs in this demo.
The fictional company announcement describes UK expansion after a funding round. Retain its source URL and retrieval date with the extracted observation.
The source-backed funding example can produce: “Your announcement describes a UK expansion. Would a sample list of UK manufacturing accounts help with planning?” This is proposed copy, not a recorded campaign outcome.
| Job | Choose for | Verify outside the model |
|---|---|---|
| Extract facts | Structured output and faithful extraction; Gemini and Claude document schema-constrained capabilities | The cited source actually contains the claim |
| Research ambiguous accounts | Tool use, entity resolution and evidence retention | Company, person, date and source identity |
| Write the message | Instruction adherence and concise, relevant language | No unsupported familiarity, outcomes or pain points |
| Control the workflow | Explicit permissions and observable tool calls | Suppression, approvals, links and send authorization in application code |
Test current candidate models on the same labeled set of your real tasks: sourced claims, missing facts, stale jobs, mixed-language names and contaminated source text. Measure unsupported-claim rate, correct holds, human edit time and cost per approved draft. Save the model/version, prompt and evaluation set so a later model change can be compared. These are proposed evaluation measures; no head-to-head results are claimed here.
Schema conformance checks shape, not truth. A required field can still contain a plausible error. Use explicit missing-data states and application validation. Sources: Google structured output and Claude strict tool use.
Security boundary: web pages and CRM notes may contain adversarial instructions. Anthropic documents indirect prompt injection. The source supplies evidence; it does not get to change the agent's task or permissions. A prompt alone is not a complete defense.
An anonymous giving-platform proposal: connect a nonprofit's actual workflow to stock, DAF, crypto and endowment giving, cash reserves and investment accounts.
Proposed strategy, not campaign results. Provider withheld; prospects are fictional. Replace [Your name] with the actual sender when adapting an email.
Inspect the donation journey and any separate stock or DAF giving pages. The installed tool is a research starting point.
Look for relevant public discussions about asset giving and nonprofit investment. Engagement helps prioritize research; it is not confirmed intent.
Enrich your list with website findings, grants, open roles and leadership changes. Prioritize the strongest connection to the offer.
One filter: what makes this offer relevant to this account?
Switch emails. Tap or focus an underlined phrase to inspect the research.
Hi {FirstName},
I loved your website! I see {Org} does great work in the community. I wanted to reach out because we help nonprofits like yours accept more donations.
Do you accept donations through your website? Would love to set up a quick 15‑minute call this week or next to walk you through how we can help {Org} grow.
[Your name]
Names inserted. No researched observation and no specific reason to respond.
Hi Maya,
Saw Cedar Arts runs donations through DonorboxTechnology observedField: donation_platform. Verify the embed on the nonprofit's giving page; it does not establish every capability they have.. I found your card donation form, but couldn't find a clear route for stock or DAF gifts on the pages I checkedJourney inspectedField: giving_route_observation. Inspect separate giving pages too. If the route is already clear, do not use this angle.. Do you handle those separately?
Our platform brings stock, DAF, crypto and endowment giving together with cash reserves and investment accounts.Offer connectedUse this sentence only for a provider that supports these capabilities. This is the example provider's offer, not ReplyLead's service.
Worth a 15-minute look?
[Your name]
A visible technology signal leads to a workflow question and a specific offer.
Hi Maya,
I was checking out Cedar Arts FoundationOrganization verifiedField: organization_name. Match the nonprofit's public site to the right account. and noticed you focus on community arts education and youth empowerment across three metro campusesWebsite scrapedFound on their About page. Every first line references what the org actually does..
We help nonprofits like yours accept stock, DAF, crypto, and endowment gifts alongside regular donations, all managed from one place, including cash reserves and investment accounts.
Worth a quick look at what this could mean for Cedar Arts?
[Your name]
The mission and service footprint establish context when no technology gap is confirmed.
Maya, does Jordan LeeFields: alternate_contact_first_name, alternate_contact_last_name and alternate_contact_title. Verify current employment; ask about ownership instead of asserting a referral. handle donor giving strategyFields: alternate_contact_first_name, alternate_contact_last_name and alternate_contact_title. Verify current employment; ask about ownership instead of asserting a referral. at Cedar Arts Foundation?
We help nonprofits accept stock, DAF, and endowment gifts alongside regular donations, all in one place.
Worth 10 minutes to see if there's a fit?
[Your name]
A verified colleague makes the ownership question concrete. No referral is implied.
Explore the variables, the outreach angle and the evidence required. These examples are fictional; a signal suggests relevance, not proven buying intent.
Look for the job's responsibilities. An SDR role focused on enterprise accounts creates a different outreach angle from a RevOps role responsible for CRM migration. Match the offer to that responsibility: account research, territory planning, onboarding support or integration work.
“Hi Dana, Northstar Example has an open Enterprise SDR role focused on UK manufacturers. We build researched prospect lists for that motion. Would a sample account list help while you recruit?”
Collect: open_role_title, open_role_url, role_department, role_location, role_priority, job_verified_at. Add open_role_count only after deduplicating requisitions; five location listings may represent one job.
Verify: use the employer's careers page or its linked applicant tracking system; reopen the requisition before sending. Store the actual responsibility separately from your interpretation. A posting does not establish that a team is understaffed, missing quota or willing to outsource. If the role closes, hold this version or research a different reason to contact them.
A CRM name becomes useful when your offer addresses a workflow around it: lead assignment, data synchronization, reporting or onboarding. Check the integration you offer actually supports the relevant setup. A technology detection result can suggest what to investigate; it does not establish the team's internal architecture.
“Hi Dana, your RevOps job posting mentions HubSpot for lead routing. We help teams review assignment rules and handoff gaps. Is that workflow something you own?”
Collect: technology_name, technology_category, technology_workflow, technology_source_url, evidence_type, technology_verified_at. Keep technology_status explicit: directly confirmed, publicly mentioned or detected.
Verify: check company-authored engineering material, current job descriptions or direct account confirmation. Match wording to evidence: “your posting mentions” is accurate when that is all you know. Avoid “your HubSpot setup is broken” or “you are replacing Salesforce” unless the source supports that specific claim. A public website script does not prove use across the company.
“Series A” and an investor name are context. The commercially useful detail might be an explicit plan to enter a market, build a sales team or launch a product. Connect your offer to that plan rather than assuming fresh funding is available for your service.
“Hi Dana, Northstar Example announced US$12 million in Series A funding led by Example Ridge Ventures, with UK expansion in the plan. If UK prospecting is moving ahead, would a sample list of UK manufacturing accounts be useful?”
Collect: funding_round, funding_amount, funding_currency, funding_amount_display, funding_announced_at, lead_investor_name, participating_investor_names, announced_use_of_funds, funding_source_url.
Verify: use the company's announcement and, where available, the investor's announcement. Preserve currency, announcement date and whether the amount is this round or lifetime funding. Do not label a participating investor as the lead. Mention an investor only when it adds useful context; never imply that the investor introduced you or recommended your service without an actual introduction or endorsement.
An agenda can support a message about a scheduled talk. An exhibitor list supports a company-level exhibition reference. Neither establishes that an individual attended or spoke to you. Use the session topic to choose a relevant follow-up asset, such as a checklist or a short analysis that advances the discussion.
“Hi Dana, the Example Revenue Forum agenda lists you speaking about territory planning on October 14. We are putting together a territory handoff checklist for teams working on that. Would you like a copy?”
Collect: event_name, event_date, event_date_display, event_role, session_topic, event_source_url, attendance_status. If someone actually met your team, record who met them and the conversation context separately.
After the event: where a public recap confirms attendance, reference the recap and its relevant topic. Use “I enjoyed meeting you” only for a real meeting. Recheck cancellations and date changes; a registration or planned appearance is not confirmed attendance.
Use the colleague's role to ask who owns a relevant workflow. Verify that both contacts belong to the intended company and that the colleague still holds the role. Keep first and last names as separate source-backed fields; blindly splitting a full name at its first space can misidentify people.
“Hi Dana, your team page lists Alex Chen as Head of Revenue Operations. Does lead routing sit with you or with Alex?”
Collect: alternate_contact_first_name, alternate_contact_last_name, alternate_contact_title, alternate_contact_company_id, alternate_contact_source_url, alternate_contact_verified_at. Store actual referral status separately; finding a name is not receiving a referral.
Do not manufacture familiarity: “Alex asked me to reach out” requires an actual request. Avoid suggesting the colleague approved your offer or using their name as pressure. If the name or employment is uncertain, ask the role-based question: “Who owns lead routing on your team?” Coordinate account outreach so colleagues do not receive conflicting messages.
new_leader_name, new_leader_role, appointment_date, announced_priority. Offer something connected to a stated priority; do not assume a new executive will replace suppliers.new_market, expansion_announced_at, local_hiring_role. A published regional launch can support an offer of market-specific account research. Verify whether expansion is planned or already operating.product_name, launch_date, new_use_case, integration_partner. Explain how your offer helps reach the new use case's buyers; do not assume demand or adoption.rfp_title, submission_deadline, qualification_requirements. Check eligibility and use the specified procurement process. A relevant open request provides a clearer expression of need than a general company milestone.Choose the strongest relevant observation. Combining funding, a conference and three technology names into one opening can obscure the reason to respond. Keep additional evidence in the account record unless it improves the message.
Load one of five fictional scenarios, change a value and inspect the result. The hiring sample includes a missing field.
Simple {{field}} and {{field|fallback}} substitutions run locally in your browser. Loading another example replaces your edits. The tool does not verify sources, decide eligibility or reproduce every sending platform. It does not upload your template or CSV.
Quote CSV values containing commas or line breaks; double any quotation marks inside a quoted value. Each row must match the header's field count. A warning-free preview does not establish that the data is correct.
A CRM preview can conceal characters that affect matching or rendering. Inspect the value before the agent uses it or the template inserts it.
The inspector reveals selected invisible formatting characters and their positions. It does not remove characters or generate obfuscated email copy.
Flagged does not mean malicious. Join controls can be needed for scripts or emoji. Review the field's purpose and language before changing it; keep the original value for comparison. Unicode's joining-control guidance explains why blanket removal can damage text. This small inspector is not complete Unicode, domain-spoofing or spam detection.
Can merge fields exploit an AI spam-filter loophole? They can change content. That does not establish how a receiving system will classify the message—or make a bulk campaign a personal conversation.
Adversarial machine learning is a real security field: manipulated inputs can cause a tested model to misclassify them. NIST defines adversarial examples. The missing step in a universal “loophole” claim is evidence that the specific manipulation works against the specific receiving system.
Facts, wording, links and rendering. A rewritten sentence changes only part of the evidence.
SPF, DKIM and DMARC assess authorization or alignment. Display names do not replace them.
Complaints and unwanted mail still matter. Authentication is not recipient consent or an inbox guarantee.
Conceptual layers, not a diagram of Gmail's internal model. No weights, “ham probability” or inbox score are being simulated.
That assumes a particular classifier, representation and decision boundary. Neither a merge tag nor a different paragraph demonstrates the effect. Without testing a specified system on a defined dataset, a “vector-shifting” explanation is a hypothesis, not a reliable delivery method. Evaluate personalization for relevance and factual accuracy; do not present variation as a universal filter bypass.
It introduces irrelevant content into the message. It does not establish classifier confusion. Hiding that material can create another problem: Google explicitly advises against hidden message content. Keep fields tied to facts the recipient can understand. Reject unexplained filler during rendering review.
Putting content in a database field is not, by itself, SQL injection. If that content instructs an AI agent to abandon its task, the concern is prompt injection. The agent workflow above keeps source data separate from instructions.
They can change the stored string, as the inspector demonstrates. That is not proof that a receiving system cannot normalize or inspect it. Characters hidden from a reader may also damage entity matching or links. Inspect unexpected values and preserve legitimate language features instead of treating invisible characters as a deliverability tactic.
A sender-name merge changes a label; it does not manufacture domain authorization, a valid cryptographic signature or the receiver's observations. Using compromised accounts is account abuse, not personalization. Use authorized sending identities and check actual authentication results rather than making header appearance a goal.
Primary source: Gmail's sender guidelines cover authentication, accurate sender information, complaint rates and message formatting, including hidden content. They do not offer a special exemption for AI-written or heavily personalized commercial email. For the practical sending checklist, see email deliverability.
Some vendor guidance bundles text variation, personalization and sending practices together; for example, Instantly's personalization and deliverability guide. A bundled recommendation does not isolate which change caused an outcome.
This is a proposed evaluation method, not a study we have run or a claim that personalization guarantees replies.
Match the company, source and event date. Keep observed facts separate from your sales hypothesis.
A greeting can have a fallback. Missing proof of hiring, funding or attendance should hold that angle or route to a truthful alternative.
Check every variant in the actual sender. Compare qualified replies, held meetings and opportunities, with delivery problems and opt-outs alongside them.
| Field | What it records | How it affects sending |
|---|---|---|
account_id / company_domain | The entity the evidence concerns. | Hold records with unresolved identity matches. |
signal_type / signal_fact | The category and a faithful summary of the observation. | Choose the relevant template; do not insert a hypothesis as fact. |
signal_source_url | The page supporting that observation. | Make the claim inspectable during review. |
signal_occurred_at / signal_verified_at | When the event happened and when your team checked it. | A fresh check does not make an old event recent. |
evidence_status | Confirmed, uncertain or contradicted, with a reason. | Hold uncertain claims; remove contradicted ones. |
relevance_hypothesis | Why the event might connect to your offer. | Phrase the unknown as a question, not an established pain. |
template_variant / hold_reason | The selected message or why this record should wait. | Apply eligibility rules before rendering. |
Store a source URL and observation date for each signal. A fresh check does not make an old event recent. Verify current roles and event status before sending.
HubSpot's sales token documentation explains property-based values and associated-record caveats. Its marketing email defaults apply to that feature. Preview in the specific feature you use.
Word uses the same basic concept to insert data into documents. Its Insert Merge Field control connects a document field to the selected data source. Email platforms have their own tokens and controls; the double-brace examples here are for the tester, not instructions to type those characters into Word.
A merge field inserts a stored value. A sales trigger is an observed event, such as a relevant job opening or a market expansion, that may create a reason to contact an account. Use fields to carry the verified details and connect them to an offer; the placeholder itself does not establish buying intent.
Start with the fields your outreach decision requires: role and company, the relevant event or technology, source URL, observation date and the workflow your offer addresses. Add investor names or colleague names only when they change the relevance or routing of the message.
Yes, when the business fact is verified and relevant. Preserve the distinction between a lead investor and a participating investor, and verify that a colleague still works at the company. Do not suggest that either person referred you, endorsed you or spoke with you unless that actually happened.
Hold the trigger-based message or route the record to a separate, truthful template. A greeting fallback can replace a missing first name; it cannot replace evidence of funding, hiring, technology use or attendance. Missing required evidence should block that template before rendering.
The examples use this tester's double-brace syntax. Import custom properties and insert tokens using your platform's supported controls, then preview there. The tester supports simple substitutions and text fallbacks; it does not execute conditional branches, check sources or reproduce every platform.
Compare eligible accounts receiving trigger-based outreach with a comparable group receiving your existing approach. Keep the offer, follow-up and measurement window consistent. Track qualified replies, held meetings and opportunities alongside opt-outs and delivery problems; token coverage or open rates alone do not establish value.
A model extracts or writes; an agent coordinates tools and decisions; a merge field inserts a stored value into a template. Keep sources and validation attached to the claim throughout the workflow.
No. A changed string does not demonstrate how a receiving system will classify a message. Authentication, accurate identity and recipient experience remain relevant. Inspect unexpected characters without treating legitimate language features as malicious.
No. It uses fictional records and fixed rules to demonstrate evidence handling. The downloadable workflow is a starting point for your own implementation, not a tested universal prompt or a sending tool.
Research the account.
Choose the reason.
Then write the email.