The MVP is one product shipped in two releases. Release A (desk) sits on top of the sequencers agencies already pay for. Release B (sender) replaces the sequencer underneath, reusing every desk module. The rule for both: build what an agency resells to its clients (approvals, reports, meeting proof, isolation) and what the leaders structurally will not (country rules, never-compete, honest billing). Buy or integrate the rest. See The wedge for why, and Build costs and team for the 3–4 engineer, 4–6 month envelope this has to fit.
Must: Release A, the desk (target: partners live by 11 Dec 2026)
| Feature | Evidence it matters |
|---|---|
| Connectors to Smartlead, Instantly, EmailBison reply events | Webhooks documented for Smartlead, Instantly and EmailBison; reading via their APIs avoids CASA (OAuth verification and the end of basic auth) |
| Reply classification: interested, not now, referral, wrong person, OOO with return date, objection, unsubscribe | Published reply rates span 0.45% to 3.43% mostly because of auto-replies (Reply benchmarks); costs about $0.0009 a reply on Haiku (Build costs and team) |
| Hard opt-out path: any opt-out phrasing suppresses the person across every campaign and client within minutes, with an audit record | Verkada's $2.95M partly for unsubscribes; €3,000 per email after an Abmahnung (Germany) |
| Global objection list, hashed, scoped workspace / agency / platform, with an "Abmahnung received" flag | Art. 21(3) objection is unconditional (GDPR and ePrivacy) |
| Approval queue per client, SLA timers on "interested", every AI draft logged with approver | AI-SDR churners want approval back (Fully autonomous AI SDR); Instantly charges 5 credits per AI reply |
| Client-viewer role that sees only its own data | Instantly clients "will be able to see all campaigns in the workspace, there's no way to restrict" (White-label and agency portals) |
| Branded weekly client report on replies and meetings, not opens | Instantly's second-largest G2 complaint is reporting, 190 mentions (Campaign analytics) |
| Meeting ledger: booked → held → opportunity, calendar link per client | Agencies bill on meetings and prove them in spreadsheets (Lead-gen agencies) |
| EU hosting, DPA, EU-only subprocessor list | No pricing page reviewed advertises an EU data region (Workspaces, roles and SSO) |
| Billing: one-click cancel, proration, an email for every charge | Billing after cancellation is Instantly's top 1-star theme, 10+ on one page (Customer voice) |
Whether a third party can post a reply back into a Smartlead, Instantly or EmailBison thread through their APIs is not documented in this hub. If it cannot, Release A drafts and approves in the desk and the operator sends from the sequencer. This is test K3 in Kill criteria.
Must: Release B, the sender (target: first partner client migrated by Apr 2027)
| Feature | Evidence it matters |
|---|---|
Connectors: IMAP/SMTP with app passwords, Microsoft Graph OAuth; one Mailbox interface | Google app passwords still work; Basic SMTP AUTH goes default-off end of Dec 2026 (Sending architecture) |
| Scheduler: per-mailbox token bucket, randomised gaps, recipient time zones, sharded by mailbox | Inbox rotation, Sending limits and throttling |
Idempotent sends: persist Message-ID first, check Sent before retry | Double-sends are the screenshot bug (Sending architecture) |
| Ingestion with reconciliation poll; RFC 3464 bounce parsing; RFC 3834 auto-reply detection | Push notifications are documented as lossy (Sending architecture) |
| Mailbox health engine: rolling bounce rate over emails sent, first check at ~50 sends, adaptive caps, rotate out and ramp back | Smartlead divides bounces by total leads in the campaign; Instantly checks after 200 emails (Mailbox health engine, Bounce protection) |
| Isolation by client: separate mailbox pools and complaint budgets | Shared-pool bleed is EmailBison's whole pitch (EmailBison) |
| Country rule engine v1: recipient country × generic/named address → allow / warn / block; versioned ruleset with source and confidence per row; unclear rows default strict | ~13 of 31 countries need consent for B2B (EU/EEA country matrix); no volume sequencer gates by country (EU-native compliant outbound) |
| Art. 14 notice injected into step one in the recipient's language; provenance per contact | KASPR's €240,000 fine, partly for English-only notices (Data sourcing law) |
| Campaigns, steps, variants, spintax, reply-intent branching | Table stakes in the feature matrix (Conditional sequences and subsequences, Spintax and message variants) |
| Importers from Smartlead and Instantly: campaigns, leads, suppression, mailbox credentials | Switching is a CSV export today; make it an afternoon (Trust as positioning) |
| Verification via a licensed provider on import; catch-all contacts routed to their own pool | Give it away (Built-in email verification); catch-all lane is open (Data at cost) |
| Custom tracking domains; open tracking off by default | Custom tracking domains, Content and tracking |
| API with OAuth scopes, idempotency keys, signed webhooks with replay | API, webhooks and MCP, Sending engine as an API |
Should (months 6–12)
- Inbox purchase through a partner API (InboxKit or Zapmail), domains registered in the customer's legal name, published cost-plus (Transparent infrastructure, Infrastructure strategy: build or partner).
- Rebilling: pass inboxes and usage to each client with the agency's markup (Agency operating system).
- CRM push to HubSpot and Pipedrive per client; Salesforce later (CRM sync).
- LinkedIn replies merged into the thread via HeyReach's API, not our own automation (HeyReach, Multichannel: LinkedIn, calls, SMS and video).
- Slack approvals and a mobile approval view.
- MCP server with the same scopes and caps (API, webhooks and MCP).
- Placement from live sends, with optional seed tests through EmailGuard or MailReach (Inbox placement testing).
- DACH destinations: seeds and routing for GMX/WEB.DE, T-Online and IONOS, if the MX scan shows they matter (ESP matching).
- Microsoft SMTP AUTH checker as a free tool (Microsoft-first outbound).
- Legal-form flag for UK sole traders from Companies House data (UK: PECR and DUAA 2025).
Later (year two and beyond)
Google OAuth with restricted scopes after CASA (OAuth verification and the end of basic auth). SSO/SCIM, audit export, SOC 2 and two-way Salesforce sync for Governed volume for sales teams. A signal-triggered campaign mode (Signal-triggered sequencer). EU-hosted isolated IP pools on KumoMTA, priced like EmailBison (Infrastructure strategy: build or partner). EU-provenance data sources such as Dropcontact (Data at cost). A productised sending API (Sending engine as an API).
Never
| Do not build | Why |
|---|---|
| A warmup network | Instantly claims 4.2M+ accounts; a new pool is small and homogeneous, and the practice is under attack (Does warmup work?). Ship a real-send ramp; integrate warmup optionally |
| A lead database | KASPR deleted its database; in the EU you become controller (Built-in lead database) |
| Autonomous sending without approval as a default | Moves you from conduit to initiator (Platform liability: what the sequencer itself risks) |
| Native LinkedIn automation | Violates LinkedIn's terms; integrate instead (Multichannel steps) |
| Per-client or per-mailbox fees, per-AI-reply credits | The grievances you are selling against (Pricing strategy) |
| Inboxes in invented identities, grey "panels" | 18 U.S.C. §1037; panels were the 2025 wave's targets (Provider crackdowns) |
| A per-account email API underneath | Nylas at $2.00 per account breaks unlimited-inbox pricing; build connectors or license EmailEngine (Build costs and team) |
| Managed outbound services | The never-compete promise (Lead-gen agencies) |
Data model sketch
agency id, legal_entity, aup_status, plan, eu_region
client_workspace id, agency_id, brand, default_countries, pool_id, approvers[]
user_role user_id, scope(agency|workspace|campaign|mailbox), role(owner|operator|client_viewer|client_approver)
domain id, workspace_id, owner_legal_name, supplier, spf/dkim/dmarc, suspensions[]
mailbox id, domain_id, provider, auth_type, health_state, cap_today, pool_id
campaign/step/variant
contact id, email, country, address_type(generic|named), legal_form, role
provenance contact_id, source, collected_at, basis, notice_sent_at
rule_set version, country, address_type, verdict(allow|warn|block), source_url, confidence
send_decision message_id, rule_set_version, verdict, override_by
thread id, lead_identity, channels(email|linkedin), external_ref(sequencer, id)
reply id, thread_id, class, confidence, received_at
draft id, reply_id, author(human|ai), approved_by, approved_at, sent_message_id
meeting id, thread_id, booked_at, held_at, disputed, billable
objection email_hash, scope(workspace|agency|global), reason, abmahnung_flag
audit_event actor(user|api_key|agent), action, object, at
Two design rules. external_ref lets the same thread live in a Smartlead campaign today and in your own engine tomorrow, which is what makes Release A reusable. Scopes and audit_event.actor exist from day one because retrofitting tenancy is exactly Instantly's white-label problem and Governed volume for sales teams will need them.
Parity checklist for agencies (as of Oct 2026)
| Capability | Instantly | Smartlead | EmailBison | Us, Apr 2027 | Us, Oct 2027 |
|---|---|---|---|---|---|
| Unlimited mailboxes | Yes | Yes | Yes | Yes | Yes |
| Client workspaces | Unlimited on Hyper Growth+ | $29/workspace | Unlimited, $599 | Unlimited, all plans | Same |
| Client-scoped viewer | No | White-label add-on | Reseller role | Yes | Yes |
| Reply AI | 5 credits/reply | SmartAgents (workflows) | None documented | Unlimited drafts, approval | + Slack, mobile |
| Meeting proof / per-client report | Limited | Per-client analytics | Not documented | Yes | Yes |
| Bounce protection scope | Campaign | Campaign | Not documented | Mailbox | Mailbox + domain |
| Warmup | Pool, 4.2M+ claimed | Tiered pools | Private pool | Real-send ramp only | Optional partner |
| Dedicated IPs | Light Speed ($358) | $39/server | Included | No | No (year 2) |
| Placement tests | On plans | $49–599 | Via EmailGuard | Live-send inference | + partner seeds |
| Lead database | 450M+ | SmartProspect | None | No | Pay-on-valid partner |
| API / MCP | 300+ endpoints / 31 tools | Pro+ / 116+ tools | REST / none | API + webhooks | + MCP |
| Country rules, Art. 14, EU hosting | No | No | No | Yes | Yes |
| Google OAuth | Yes | Yes | n/a | App passwords | After CASA |
Sources: Instantly, Smartlead, EmailBison, API, webhooks and MCP, Mailbox health engine.
What this means for an entrant
- Ship Release A in eight weeks with three connectors and the opt-out path working perfectly. A missed opt-out is a legal event, not a bug (The first 90 days).
- Accept the deliberate gaps (no warmup pool, no database, no dedicated IPs in year one) and say so on the pricing page (Pricing strategy).
- Make
rule_setpublic. A versioned, sourced country table is content marketing competitors would have to rebuild (Go-to-market plan). - Treat the mailbox, not the campaign, as the unit of protection. That is the retention engine (Mailbox health engine).
- Keep
external_refand scopes in the schema from the first commit. They are what let one codebase serve the overlay, the sender and year-two SDR teams.