Lesson 5 of 5 · 46 min
Capstone: account-research → personalized-outreach demo
Assemble the whole track into one flagship demo: an agent that researches an account, grounds findings in real sources, and drafts personalized outreach a human approves before send — built synthetic-first, scrubbed, tenant-isolated, gated by a smoke test. The full architecture, the numbers and tradeoffs to defend, and a rehearsal of the build-and-present interview that decides the offer.
Capstone
Account-research → personalized-outreach demo
How to demo like a Salesforce Solution EngineerBadassBA (with Jasmine Ashley)Scope it before you draw it
- 01Sources? — which signals count as “research”: CRM facts, a docs corpus, public web/news? (sets retrieval + which tools the agent gets).
- 02Truth bar? — does every claim in the email need a citation, or is some inference OK? (sets the grounding contract + faithfulness gate).
- 03Data? — synthetic, scrubbed-real, or raw-real accounts in the demo? (sets the data track + the scrubbing/isolation you need).
- 04Action? — draft only, or enqueue to a sequence tool and write back to the CRM? (sets the human-in-the-loop gate, the idempotent write, and the blast radius).
- 05Tenancy/stakes? — one org or multi-tenant; is a wrong/spammy email embarrassing or a compliance problem? (sets isolation + approval rigor).
The reference architecture
Account/Company read + a docs corpus + optional web), parsing layout-aware and scrubbing PII on the way in → 2) chunk + embed + index, tagged with a tenant_id and an acl so retrieval is isolated → 3) a research agent runs the Thought-Action-Observation loop, calling a search_account() tool (filtered by ACL at query time) and an enrichment waterfall (provider A→B→C, cheapest-first, cost-per-match) to gather grounded, cited findings → 4) a composer step drafts the email from those cited findings with an enforced “only claim what’s sourced” contract → 5) a human-in-the-loop gate shows the draft + its citations for approval before any send, scrubbing the output too; on approval it enqueues the email to a real sequence tool (Clay Sequencer / HubSpot Sequences / Salesloft) and makes one idempotent CRM write-back (upsert the Contact + log the touch on the Opportunity) → 6) a 20-question smoke test gates the whole thing before the meeting. Three swim-lanes to narrate: the offline ingest path sets quality, the online agent path sets latency, and the gate (approval + smoke test) makes it safe to show.1Account-research -> personalized-outreach: the whole pipeline (lesson per stage)23 INGEST (offline)4 read CRM Account/Company + docs + web, layout-aware ... L25 SCRUB PII on the way in (Presidio) .................... L46 chunk + embed + index, tag {tenant_id, acl} .......... L2 + L4 (isolation)7 RESEARCH (online, per account)8 agent loop: Thought -> search_account() -> Observe .... L39 enrichment WATERFALL (provider A->B->C, cost/match) ... L3 (Clay pattern)10 retrieve ACL-FILTERED at query time .................. L2 + L4 (filter then retrieve)11 findings grounded + CITED (or "not found") ........... L2 (refusal path)12 COMPOSE13 draft email from CITED findings only ................. L2 (grounding contract)14 treat web/docs content as UNTRUSTED (injection) ...... L4 (LLM01)15 GATE (before send AND before the meeting)16 human-in-the-loop approval + scrub OUTPUT ............ L3 + L417 on approval: enqueue to sequence tool (Clay/HubSpot) . L3 (real outbound)18 one IDEMPOTENT CRM write-back (upsert Contact) ....... L3 (no duplicates)19 20-question smoke test (faithful/partial/halluc.) .... L12021 Offline sets quality; online sets latency; the gate makes it safe to demo.1# The online path: a grounded research agent that DRAFTS (never sends) outreach,2# then a gated path that hits the REAL GTM stack only after a human approves.3def research_and_draft(account, user, providers):4 # 3) agent gathers grounded, cited findings: ACL-filtered retrieval (L2+L4)5 # plus an enrichment waterfall for missing contact facts (L3, Clay pattern).6 findings = research_agent.run(account, tools=[7 acl_filtered_search(user.allowed_acls), # filter then retrieve8 enrich_waterfall_tool(providers)]) # provider A->B->C, cost/match9 cited = [f for f in findings if f.source_id] # drop ungrounded claims1011 # 4) compose from CITED findings only; treat retrieved/web text as untrusted (L4)12 draft = compose_email(account, cited, contract=ONLY_CLAIM_WHAT_IS_SOURCED)13 draft = scrub(draft) # output PII pass (L4)1415 # 5) human-in-the-loop: propose, don't send. Approval gate is the feature (L3).16 return {"draft": draft, "citations": [f.source_id for f in cited],17 "contact": account["primary_contact"], "status": "awaiting_approval"}1819def on_approval(approved, crm, sequencer):20 # Runs ONLY after a human clicks approve -- the real outbound + CRM write.21 sequencer.enqueue(approved["contact"]["email"], # Clay/HubSpot/Salesloft seq22 approved["draft"])23 # ONE idempotent write-back: upsert keyed on email, log the touch -> no dupes.24 crm.contacts.batch_upsert(id_property="email", inputs=[{25 "id": approved["contact"]["email"],26 "properties": {**approved["contact"], "last_outreach": "sent"}}])Key idea
The numbers and tradeoffs to defend
1Sizing the outreach demo (numbers to reason in, not memorize)23 per-account cost retrieval (cheap) + agent loop tokens cap steps; short drafts4 latency a few tool round-trips stream draft; show progress5 output vs input output ~3-5x input price keep emails tight6 build cost synthetic-first ~0 until sanctioned real data7 blast radius draft-only + human approval never auto-send in a demo89 The point is to REASON in these and connect each to a tradeoff you chose.The composer prompt: where the personalization lives
1# The composer contract: personalize ONLY from cited findings; no invention.2ONLY_CLAIM_WHAT_IS_SOURCED = (3 "Write a short, specific outreach email to {account}. Use ONLY the findings "4 "below; every specific claim must come from a finding and keep its [id]. "5 "Do NOT invent facts, metrics, or events not present in the findings. "6 "If the findings are thin, write a shorter, more general email rather than "7 "fabricating detail."8)910def compose_email(account, cited_findings, contract):11 body = "\n".join(f'[{f.source_id}] {f.text}' for f in cited_findings)12 prompt = contract.format(account=account) + "\n\nFindings:\n" + body13 draft = llm(prompt)14 # post-check: every [id] the draft cites must be a real finding (L2 rule)15 if not citations_valid(draft, cited_findings):16 return regenerate_or_flag(account, cited_findings)17 return draftKey idea
What breaks on stage — pre-empt it
Common mistake
“Ship it when the emails look good.”
Present it: the demo that wins the room
A winning capstone isn’t the demo that drafts one great email — it’s the one that’s grounded, scrubbed, tenant-isolated, smoke-tested, and gated behind a human, presented by someone who maps every beat to a buyer pain and stays honest under the derail. That’s the technical win.
Interview prep
- 01“Walk us through your demo.” → scope first (sources, truth bar, data, action, tenancy), then ingest(scrub) → agent-research(cited) → compose → human-gate → smoke-test.
- 02“How do you stop it writing things that aren’t true about the account?” → drop claims with no source_id, cite per claim, enforce refusal, faithfulness-gate on real accounts.
- 03“Why an agent and not a single call?” → multi-source research (CRM + docs + web) needs the loop; I cap steps and accept the latency/cost for that, draft-only.
- 04“Won’t this spam our prospects?” → every claim is cited and a human approves before send — the gate is the feature, not a limitation.
- 05“How does this plug into our CRM and sequencer?” → enrich via a waterfall (cheapest-first, cost-per-match), enqueue the approved email to the real sequence tool (Clay/HubSpot/Salesloft), and make one idempotent upsert (key on email) to the Contact + log the touch on the Opportunity — no duplicate records.
- 06“How do you handle our customer data and PII?” → synthetic-first build; scrub input and output; tenant_id + ACL filter at retrieval; treat web/docs as untrusted.
- 07“How do you know it’s ready to show / ready for a POC?” → a 20-question faithful/partial/hallucinated gate, zero ungrounded claims, plus the eval harness handed to the buyer.
- 08“Compress this to 10 minutes for our CRO.” → one flow (name account → cited draft → approve), lead with the hour-to-20-seconds value, drop the plumbing.
- 09“What would you do differently at production scale?” → per-tenant isolation + CMEK, trajectory eval + observability, the 5-stage POV with exit criteria.
Common mistake
The red flag that sinks candidates: a slick demo with no failure story and a guessed answer under pressure.
Checkpoint
An interviewer says: “Build us a demo that researches an account and drafts outreach.” What’s the strongest first move?
Checkpoint
During the demo, the drafted email praises the prospect for “your recent Series C” — but that funding round isn’t in any retrieved source. What does a production-quality build do?
Checkpoint
A buyer asks whether the system can just send the outreach automatically to save reps time. What’s the strongest design stance for the demo?
Checkpoint
You’re demoing for two prospects in one session on a shared environment. While researching Account A, a finding about Account B appears. What should already be in place?
Checkpoint
Your account-research demo works on a few hand-picked accounts. How do you know it’s ready to present to a flagship prospect?
Could you build AND present this account-research → outreach demo end to end — grounded, scrubbed, isolated, gated — and defend every decision through the deep-dive and the derail?
You can now
- Scope a customer demo before building — sources, truth bar, data handling, action scope, tenancy/stakes.
- Assemble account-research → cited-findings → drafted-outreach with a human-in-the-loop send gate, end to end.
- Build it synthetic-first, scrub PII on both sides, isolate tenants at retrieval, and treat retrieved/web content as untrusted.
- Gate it with a 20-question smoke test (zero ungrounded claims) and defend the cost/latency/tradeoff numbers.
- Present with Tell-Show-Tell mapped to buyer pains, name the failure modes unprompted, and handle the derail honestly.
You’ve built the full customer-facing AI demo skill set — grounded, secure, agentic, and presentable. Next: take it into a real take-home and rehearse the loop end to end.
Sources
Free to read · better with Enzo
Learn it with Enzo
Save your progress, answer the checkpoints, and let Enzo quiz you on what you just read.