Verification research
The AI SDR Pre-Flight Checklist: Permissions, Email Verification Docs, and Intent Data Checks Every RevOps Team Should Run
2026-09-10 · Julian Hartwell
-
A quick story about why this checklist exists
- 1. Get the permission matrix before the demo ends
- 2. Read the email verification documentation like your sender reputation depends on it
-
3. Test the pipeline with a sample from your own list
-
4. Test intent data against accounts you already closed
-
5. Define the human-in-the-loop flow before you press send
-
6. Watch the logs for one full week, not just the dashboard
-
Common mistakes I still see teams make
I've spent the past six years in revenue operations, mostly at B2B SaaS companies. During that time, I've personally made—and documented—four significant mistakes with AI sales tools. Combined, they cost roughly $35,000 in wasted budget when you count cleanup time, unused seats, and the sender reputation I had to rebuild. That's why I now maintain a pre-flight checklist that our team runs before any AI SDR gets access to our stack.
If you're currently comparing Okki Go vs. Artisan AI, or evaluating AI SDR platforms for the first time, this article is for you. It's not a comparison of sequence builders or template libraries. It's the operational checklist I wish someone had handed me before my first rollout.
A quick story about why this checklist exists
In September 2022, I connected an AI SDR platform to our Salesforce org two days before a campaign launch. I approved every permission on the OAuth screen because I was in a hurry and thought, what are the odds the tool does something destructive? The odds were 100%.
Within hours, it created thousands of tasks on accounts nobody had touched in years. Meanwhile, the email campaign went out to a list we hadn't verified. The bounce rate landed near 19%, which damaged our sending reputation for weeks. The cleanup cost us about $2,300 in engineering time and four very awkward standups.
Here's the checklist I use now. It won't replace a proper security review, but it will catch the expensive problems before they become incidents.
1. Get the permission matrix before the demo ends
Most AI SDR demos focus on personalization and reply rates. I now ask for the permission matrix in the first meeting. If the vendor can't explain exactly what the tool will access, that's a red flag, regardless of how impressive the demo looks.
What permissions does Okki Go require?
In our evaluation, Okki Go's permission requests fell into three groups:
- Mailbox access: permission to send emails and read replies from the connected mailbox. That's core to any AI SDR that runs sequences for you.
- CRM access: object-level read and write permissions, usually to log activities, update lead statuses, and sync campaign outcomes.
- LinkedIn access: needed when the agent is doing LinkedIn prospecting in addition to email outreach.
Look for scopes that are specific to the job. A tool that asks for full mailbox history or admin-level CRM access should have a very good explanation. If it doesn't, ask for least-privilege scopes instead. And always test in a sandbox before connecting a production workspace.
2. Read the email verification documentation like your sender reputation depends on it
This is the step most teams skip, and it's the one that bit me hardest. I once trusted a demo that showed a clean dashboard, but the API documentation didn't explain how it handled catch-all domains. That gap cost us a 19% bounce rate.
What should revenue operations teams evaluate in API email verification documentation?
- Response definitions: does the API return distinct statuses like deliverable, risky, and undeliverable, or does it just say valid or invalid?
- Catch-all handling: some verification tools mark catch-all addresses as deliverable because they technically accept mail. That's not the same as reaching a real human inbox.
- Failure behavior: if the verification service times out or returns an error, does the integration fail safe, or does it assume the email is valid?
- Rate limits and batch processing: if you're planning to upload 50,000 leads, the documentation should clearly show how batch verification works and what the retry limits are.
- Data handling: does the documentation state how email addresses are stored, processed, or retained?
No verification provider can guarantee 100% accuracy—anyone who says otherwise is overselling. But the documentation should tell you exactly where the uncertainty lives.
3. Test the pipeline with a sample from your own list
Before you launch an email campaign to your full list, run 200 to 500 records through the actual pipeline. Use your own CRM data, not the vendor's sample dataset.
Check that the verification step correctly flags known bad addresses, and confirm the enrichments fill missing fields without overwriting good data. Then send a small batch and watch what happens at the mailbox level. A nine-out-of-ten email campaign starts with list quality, not subject lines.
4. Test intent data against accounts you already closed
Intent data sounds great in a pitch. The question is whether it actually describes your buyers. So we pull the 20 to 30 accounts we won in the past 90 days and load them into the platform. Then we ask: would this tool's intent data have flagged these accounts as in-market?
If it misses most of your closed-won deals, treat the intent data as a suggestion, not a filtering mechanism. It's useful for prioritization, but it shouldn't be the only reason you skip a good account. Also ask where the intent signals come from and how often they're updated. That matters more than the number of topics the platform claims to track.
5. Define the human-in-the-loop flow before you press send
Okki Go's approach is agent-native, which means it can draft research, write outreach, and take actions autonomously. That's powerful, but it only works if you define what happens when a human is actually needed.
Who reviews replies in the first 24 hours? Who handles unsubscribe requests quickly? Who has the authority to pause a campaign if the AI starts sending something off-brand? In a past rollout, a prospect replied the most important thing a prospect can reply: 'please remove me from your list.' The sequence didn't stop because we hadn't assigned ownership. That's how compliance issues start.
Draw the escalation path on paper before the launch. It should be more specific than 'someone monitors the inbox.'
6. Watch the logs for one full week, not just the dashboard
Dashboards are optimistic. Logs tell the truth. During the first week of any AI SDR rollout, I check the raw event logs for each email campaign: when messages were sent, when they bounced, when someone replied, and when a recipient marked the message as spam.
Look for patterns the dashboard won't show you. Maybe the AI is sending identical messages despite claiming personalization. Maybe the verification step is silently failing on a specific email provider. Maybe the tool is logging duplicate activities in Salesforce. You won't see any of that in a weekly performance summary.
Set a simple internal alert for unusual bounce rates and spam complaints. If something looks wrong in the first week, it's much easier to fix before it scales.
Common mistakes I still see teams make
- Approving broad permissions to save time in the sales cycle.
- Trusting a vendor's sample data instead of testing with their own verified list.
- Connecting a shared or primary mailbox to an AI SDR. Use a dedicated mailbox or alias so you can isolate issues.
- Waiting until after rollout to assign human ownership for replies, errors, and pauses.
The goal isn't to slow down your evaluation. It's to make sure the only surprises you find are good ones—better deliverability, cleaner CRM data, and outreach that actually reflects your brand. Because every email you send is an impression of your company, and once that reputation is damaged, no AI tool can fix it for you.
