Runtime
Confirm Node and npx availability, package policy, agent compatibility, and whether the first run belongs in a sandbox. Inspect package identity and terminal prompts before allowing changes. Copying changes only the clipboard; running invokes the installer.
Connections
Use approved sources and destinations, with secrets stored outside prompts and files. Review API scopes, rate limits, browser-automation risk, logging, retention, revocation, and current provider terms before granting access.
First task
Choose a small authorized sample. Define ICP, exclusions, geography, evidence threshold, suppression, message purpose, and the reviewer responsible for targeting, wording, export, and every external action.
Run, configured, and first result are also separate states. Configuration grants selected access; a first result returns research for review. Neither state establishes permission to contact someone or guarantees delivery, reply, or pipeline.
Inspect provenance, checked time, identity uncertainty, and sensitive inference. Reject context a recipient would not reasonably recognize. Test reply routing, opt-out, suppression, correction, and deletion. Removing a package does not automatically remove records from agent logs, files, a CRM, or an engagement tool.
Rehearse failure conditions: an unavailable source, uncertain contact match, rate limit, changed browser interface, or draft outside the approved tone. The workflow should pause visibly. Assign an owner to review provider terms, connector updates, sender warnings, suppression, and complaints.
For the first result, record which fields were observed, inferred, or unavailable. Ask the reviewer to explain one acceptance and one rejection, then refine the brief before expanding the sample. This feedback loop improves the operating instructions without pretending that a larger list is automatically better.