Admin, Settings, and Integrations
Audience: Workspace admins and Aventora operators configuring Client Growth Hub.
Goal: Explain administration, trust controls, workflows, and product-level integrations.
Related: Overview, Research Campaigns, Security Overview
Users and roles
- There is no public self-registration.
- The first admin is provisioned for the organization; that admin manages users from Settings → User management.
- Edit updates a user's name, role, language, active status, and password. Email and organization cannot be changed after the user is created. Leave the new-password field blank to keep the current password.
- Typical roles: admin (settings, users, providers) and user (day-to-day growth work).
- Platform super admins create organizations and set per-tenant entitlements. Optional B2B prospect and B2C contact unit prices (CAD by default) enable Square lead unlock checkout; unset prices mean unlimited free access.
- Users must be active and belong to the correct organization to see workspace data.
Campaigns
Platform super admins open Campaigns next to Repository and Settings.
- Move changes which organization owns the campaign definition. Existing research runs stay with the organization that launched them.
- Clone copies the current definition (campaign fields, current research brief, current specification, and current signal policy) into the target organization as a new draft. Runs, prospects, and performance stay behind.
- Share lets another organization open and run the same definition. That organization cannot edit the interview, brief, specification, or signal policy. Future runs use the current definition. Past runs stay frozen on the policy version stored on the job. Also share prospects found by this campaign is optional and applies only to that Share. When it is checked, the target organization gets its own copy of each prospect the owning organization's runs have already found, except companies it already has. Each copy carries company details only (name, website, industry, geography, description), starts as new, and has no evaluation, contacts, outreach, or link to the source campaign. Prospects found later are not included. When it is unchecked, only the campaign definition is shared.
- Unshare removes that organization's access to launch new runs. Their existing runs remain listed.
- Delete permanently removes the campaign and every run attached to it. Prospects already discovered stay in the database, with their assignments, so they can be assigned again later. The confirmation names the campaign and the number of runs. This is separate from a tenant user removing a campaign from their Research list, which only hides it.
- Open a record in Repository and use Assign to an organization. That creates the organization's own prospect with company details only and does not require the campaign. The organization sees that prospect on Prospects. It never sees the original record, who found it, or that organization's evaluation, contacts, or outreach. Accept, reject, and outreach stay on the organization's own prospect, and the assignment row shows its decision. Assigning the same organization again keeps the existing assignment.
- Identical research across organizations. Tenants are only warned about an identical specification already running in their own organization. To see identical research running in other organizations, a super admin calls
GET /api/v1/platform/campaigns/{campaign_id}/research-overlaps, then shares or assigns explicitly if wanted. - Global prospect reuse is off by default. When the worker sets
GLOBAL_PROSPECT_REUSE=trueand lists organizations inGLOBAL_PROSPECT_REUSE_POOL_ORGANIZATION_IDS, a new B2B run may start from unworked company details found by those pooled organizations. The launching organization evaluates them itself and keeps its own row. Every reuse writes the platform audit eventprospect.global_reuse_seeded. - Campaigns, Repository, User management, Organizations, and Audit list 25 rows per page.
- User management, Organizations, and Audit include Back to Settings.
Lead unlock pricing
By default, organizations have no unit prices and operators get unlimited access (full prospect identity, no Square checkout).
Super admins may optionally set prices on Settings → Organizations (create org or edit entitlements):
| Field | Meaning |
|---|---|
| B2B prospect unit price | Charged per selected organization prospect unlock; blank/0 = unlimited |
| B2C contact unit price | Charged per selected person contact unlock; blank/0 = unlimited |
| Lead currency | Currency for Square Payment Links (typically CAD) |
Only when a unit price is greater than zero (and platform billing.enabled is on) does that prospect kind return redacted until purchased. Operators then cherry-pick locked IDs on Prospects, pay via Square, and see full identity for those rows only.
Settings areas
Admins can manage:
| Area | Purpose |
|---|---|
| Email compliance | Legal name, mailing address, and unsubscribe instructions added to every outreach email |
| Do-not-contact list | Company domains, email addresses, and phone numbers that must never be contacted |
| Feature flags | Enable or disable product capabilities (platform-wide; Super Admin only) |
| Provider settings | Base URLs and credentials for research, messaging, calendar, storage, notifications (platform-wide; Super Admin only) |
| Signal catalog | Buying-signal definitions, weights, urgency, pass-to-research toggles (platform-wide; Super Admin only) |
| Research priority blend | Fit / intent / urgency percentages (must sum to 100%; platform-wide; Super Admin only) |
| Social listening | Listen interval, max post age, default communities, default listen keywords (Contacts workflow) |
| Contact request messages | Templates for Call office / Email office when a named person is missing |
| ZoomInfo add-on | Activate or disable ZoomInfo enrichment for the organization |
| Localization | Defaults for English / French operator UI |
| Retention | Data retention configuration |
| Usage | Usage dashboard by category |
| Audit | Searchable history of critical actions |
Feature flags, provider settings, the signal catalog, and the research priority blend apply to every organization on the platform. Organization admins can see them, but only a Super Admin can change them. A change attempt by an organization admin returns 403 Platform settings can only be changed by a Super Admin.
Email compliance
Settings → Email compliance sets the footer that is added to every outreach email, as Canada's anti-spam law (CASL) requires:
- Legal business name (optional; defaults to the organization name)
- Mailing address (required)
- Unsubscribe instructions (optional; defaults to
To stop receiving these emails, reply "unsubscribe".)
Until a mailing address is saved, outreach email is blocked. Sending from the API returns 412 with a message pointing to Settings → Email compliance, and sequence steps stop with the reason email_compliance_missing. Each email also carries a List-Unsubscribe header, so mail clients can show their own unsubscribe button.
Do-not-contact list
Settings → Do-not-contact list blocks recipients for every channel:
- Enter a domain (
competitor.com) to block everyone at that company. - Enter an email address or phone number to block one person.
Paste one entry per line. Lines that aren't recognized are listed back to you and are not saved. People who reply "unsubscribe", or whose email bounces, are added to the list automatically and can't be removed.
API (organization admin):
POST /api/v1/compliance/do-not-contact
{"entries": ["competitor.com", "ceo@partner.ca", "+1 416 555 0100"], "reason": "existing client"}
{"created": [{"id": "…", "identity_type": "domain", "identity_value": "competitor.com", "removable": true}], "existing": [], "invalid": []}
GET /api/v1/compliance/do-not-contact lists active entries. DELETE /api/v1/compliance/do-not-contact/{id} removes a manual entry; unsubscribe and bounce records return 409.
Businesses vs Contacts is not a Settings switch. Operators use the Businesses / Contacts toggle on Research and Prospects; both workflows coexist in the same tenant.
Secrets are masked after save. To rotate a secret, paste the new value and save; the previous value is never shown again. System credentials for research, messaging, and related services live in deployment environment variables — not the Settings UI.
Audit
Open Settings → Audit (or the audit viewer) to review important actions such as:
- Login and session activity
- CRM creates, updates, deletes, restores
- Campaign and research-job actions
- Prospect approval and import
- Message sending and inbox actions
- Exports and file downloads
- Retention runs
- Admin setting changes
Filter by action, resource type, resource id, actor, or date range when investigating. Exports of audit data are tenant-scoped and themselves audited.
Agent Runs
Agent Runs makes AI work visible:
- Provider call status and timestamps
- Campaign / prospect linkage
- Citations when available
- Cost signals when available
- Failure reasons for failed rows
Use Agent Runs in demos and support to show that research is explainable, not a black box.
Social listening
For the Contacts workflow, org admins can tune research cadence under Settings → Social listening:
- Listen interval (how often active campaigns look for new public intent)
- Max post age (how old a post may be and still count)
- Default communities / sources to prefill the research interview
- Default listen keywords to prefill interview and fall back when a campaign leaves keywords blank
Campaign values override workspace defaults. Clearing a campaign field means “use workspace default” at listen time. The listen interval applies to scheduled campaigns only; a campaign an operator switched to manual cadence stays manual when relaunched.
A super admin connects the platform Google Ads account under Settings → Google ads. Creating an organization calls CRM partner provision, which creates that organization's workspace, Hub account, domain, and default Connect campaign. It also ensures the Ad leads page. Organization admins see both addresses and the provision status under Settings → Connect campaign. Connect campaign URL is the page that still sends the confirmation text. Ad campaign URL is the notify-only page ad clicks open. They do not type either URL and they do not connect the Google Ads account. Create ad campaign and Refresh ad campaign ask Engagement Hub for the Ad leads page and replace only the Ad campaign URL. The same controls are on the organization CRM workspace section. An accepted prospect is copied into that workspace once the organization is allowed to see the contact. Prospects stay in Client Growth Hub until then. The Ad leads form itself does not write CRM.
Reddit listening uses a shared platform account managed by a super admin. After the Zernio API key changes, connect the account again. Client Growth Hub drops a saved profile the new key cannot access and starts the connection on a profile that key can use. Organization admins connect their own Facebook, Instagram, and LinkedIn under Settings → Your social accounts. After Meta login, Facebook asks for the Page, then the Meta ad account the organization pays for. The Page id is saved from that Page. The Business id is saved when the ad account list includes it. The admin confirms that lead-gen terms are accepted. Connect ads permissions runs the Facebook ads login. Client Growth Hub then reads health for the Page account and the Meta ads account, and stores only the scopes Zernio returns. The account stays not ready until those items are present. Instagram and LinkedIn are used when an approved post should go out on that organization's account. Live ad spend stays off until it is explicitly enabled. Operators still review drafts in Social before anything is published. A Contacts campaign's Ads section is described in B2C Social Listening.
Demo entitlements (platform super admin)
Platform super admins manage tenants under Settings → Organizations. Provision workspace is shown only when that organization is not linked yet. If the CRM workspace or domain already exists, the action stores the workspace link and API key. Otherwise it creates the workspace. For a pilot or demo org you can set:
- Research launches allowed (blank = unlimited)
- Email / Hub messaging / Calls toggles for outbound prospect contact
Limited workspaces see an access notice on the dashboard with remaining research runs and any channel restrictions. When research launches are finite, each research is also capped at a small prospect limit and discovery pool so demo users cannot raise sizes in the interview. Unlimited tenants do not show the notice. The Getting started tutorial’s fixture jobs do not count against research quota.
Integrations (configuration overview)
Configure providers in Settings (or deployment env for system-level credentials). Product-level roles:
| Integration | Used for |
|---|---|
| Research / LLM (Perplexity) | Discovery, qualification, on-demand enrichment |
| ZoomInfo (optional add-on) | Contact enrichment with field accept/reject |
| Aventora Engagement Hub | SMS, call, WhatsApp, and related engagement |
| SMTP | Email send and delivery events |
| Calendar | Booking links and scheduling |
| Social networks | Research public intent and approved interactions for Contacts |
| Object storage | Files and document attachments |
| Notifications | Operator alerts (for example Teams) |
Client Growth Hub uses adapters so provider payloads do not leak into core workflows. Exact environment variable names and secrets belong in your deployment package — not in public docs.
Security and tenancy (workspace view)
- Organization-scoped CRM, campaigns, prospects, messages, files, and analytics
- Role-based access for admin vs operator work
- Human approval before CRM import and before active template use
- Audit trail for critical actions
- Masked provider secrets in the UI
- Encryption for sensitive connected-account tokens when configured
Platform commitments: Security Overview.
Localization
Operator UI supports English and French. Users can set locale preferences where the product exposes them; admins set workspace defaults under Settings.
Changelog
| Date | Change |
| --- |
| 2026-10-08 | Settings → Connect campaign shows Connect campaign URL and Ad campaign URL. Ad clicks use the Ad leads page. Create ad campaign and Refresh ad campaign replace only that address. |
| 2026-10-06 | Settings → Google ads shows the saved customer after Google returns. One returned customer is saved. Several customers stay as choices until one is selected. |
| 2026-10-05 | Re-provision workspace reads the existing Connect campaign URL and stores it. It does not create another workspace, Hub account, or domain. |
| 2026-10-05 | Re-provision workspace appears when the organization already has a CRM subdomain. It asks CRM to create the Hub account and domain again for that workspace. The organization keeps the Hub result, including a failure reason. |
| 2026-10-04 | Provision workspace links an existing CRM domain, including one already named for the organization, and keeps the failure reason on the organization. A green note appears only when the Connect URL is stored. |
| 2026-10-04 | Settings → Organizations has Provision workspace for one organization when it is not linked. An existing CRM workspace is linked and its API key is stored. |
| 2026-10-04 | Creating an organization provisions its CRM workspace, Hub account, and Connect campaign. Google ads use that Connect URL. Organization admins see it under Settings → Connect campaign. An accepted, unlocked prospect is copied into that workspace. |
| 2026-10-03 | After Connect ads permissions, Save and recheck readiness reads scopes from the Page account and the Meta ads account. |
| 2026-10-03 | Connect ads permissions starts the Facebook ads login. Client Growth Hub stores the scopes returned by account health. |
| 2026-10-03 | The Facebook Page id and Meta Business id on Settings → Your social accounts are shown and cannot be edited. |
| 2026-10-03 | Settings → Your social accounts stores the Facebook Page id from the Page you select, and the Business id when the ad account list includes it. |
| 2026-10-03 | Settings → Your social accounts asks for the Facebook Page after Meta login, then the Meta ad account can be saved. |
| 2026-10-03 | Connecting a social account after a Zernio API key change replaces a saved profile the new key cannot access, then starts the connection again. |
| 2026-10-03 | Organization admins manage delivery from Ads. That page lists the organization's Meta and Google ads and can create one without a research campaign. Canceled and finished ads cannot be set live. |
| 2026-10-03 | Settings → Google ads is Super Admin only. It stores one Google Ads connection and the https Engagement Hub URL used as the landing page for campaign Google search ads. |
| 2026-10-03 | Saving the Meta ad account writes the organization, Meta, and ad-account allowlist. Live spend still requires the API and worker ads flags to be set together. Those flags stay off until set. |
| 2026-10-03 | Settings → Your social accounts also collects the Facebook Page id, Meta Business id, and lead-gen terms, then stores the ads scopes Zernio returns and shows the remaining readiness gaps. |
| 2026-10-03 | Settings → Your social accounts lets an organization admin connect Facebook (and choose a Meta ad account), Instagram, and LinkedIn. Reddit stays a shared super-admin connection. |
| 2026-09-30 | Added Settings → Email compliance (CASL footer; outreach email blocked until a mailing address is set) and Settings → Do-not-contact list (domains, emails, phones; unsubscribes are added automatically). Platform-wide settings are now read-only for organization admins; only a Super Admin can change them. |
| 2026-09-29 | Social listening interval applies to scheduled campaigns only; manual cadence stays manual on relaunch. |
| 2026-09-29 | Assigning or sharing prospects gives the organization its own copy with company details only; it never sees the original, its evaluation, contacts, or outreach. Cross-organization identical research is visible only to super admins through GET /api/v1/platform/campaigns/{campaign_id}/research-overlaps. Global prospect reuse is off unless GLOBAL_PROSPECT_REUSE and a pool of organizations are set, and every reuse is audited. |
| 2026-09-28 | Sharing a campaign can also assign the prospects that campaign has already found, except any the target organization has already accepted. The choice applies only to that share. |
| 2026-09-28 | Super admin Delete on Campaigns permanently removes that campaign and its runs. Discovered prospects and their assignments stay. |
| 2026-09-23 | Prospect assignment is on the Repository record. Campaigns, users, organizations, and audit use 25-row pages. |
| 2026-09-23 | Sharing a campaign with its owner is blocked in the Campaigns screen, and the error text from the API is shown. Duplicate organization names include the slug. |
| 2026-09-23 | Settings subsections include Back to Settings. Campaign prospect assignment explains that the record stays global and each organization keeps its own accept or reject. |
| 2026-09-23 | Super admin Campaigns can move, clone, share, or unshare a definition, and assign a global prospect to another organization. |
| 2026-09-23 | User management Edit updates name, role, language, status, and password. Email and organization stay fixed. |
| 2026-08-12 | Social listening: default listen keywords; blank campaign fields fall back to workspace defaults. |
| 2026-07-28 | Clarified default unlimited access when org unit prices are unset; billing only when prices are positive. |
| 2026-07-28 | Documented org-level B2B/B2C unit prices and Square lead unlock billing. |
| 2026-07-28 | Replaced Settings product-mode with Businesses/Contacts toggle; documented social listening cadence and capabilities (without internal provider connection details), demo entitlements, ZoomInfo add-on. |
| 2026-07-21 | Initial public admin, settings, and integrations guide. |