Lesson 8 of 8 · 50 min
Capstone: multi-client outbound pipeline design
Timed system-design capstone: multi-tenant outbound control plane across ICP, enrichment, sequences, deliverability, reply ops, and attribution — with isolation, SLOs, failure modes, and an explicit hire rubric.
Assemble the factory for multiple tenants
Key idea
Clarifying questions (say them)
- 01Volumes — contacts/week per client? meetings targets?
- 02CRM — each client brings HubSpot/SFDC or you host?
- 03Regions — data residency and legal basis for cold email?
- 04Channels — email only or multi-channel?
- 05Staffing — who handles positives, 24/7 or business hours?
- 06Success metrics — meetings, pipeline $, or retained client NPS?
- 07Constraints — budget caps for enrichment; existing domains?
Reference architecture
1MULTI-CLIENT OUTBOUND CONTROL PLANE23 [Tenant policy store] icp_version, waterfall, sequence graphs,4 domain fleets, SLA clocks, suppress lists5 [Identity + scoring] per-tenant features; no shared person cache6 across tenants without contract7 [Enrichment workers] shared code, per-tenant API keys + credit meters8 [Sequence engine] graph executor; stop on reply; rate limits9 [Send fleet mgr] per-tenant domains/mailboxes; health scores10 [Reply ops] classify → route to client owner map → CRM11 [Event bus] enroll/sent/bounce/reply/meeting (tenant_id)12 [Warehouse views] per-tenant dashboards + agency rollup (meta)1314 Hard rule: tenant_id on every row, key, and log line.Per-client policy differences
1TENANT DIFFERENCES (examples)23 Client A fintech US:4 ICP strict; phone optional; catch-all discouraged; reply SLA 10m5 Client B EU SaaS:6 lawful basis review; softer volumes; richer suppress; geo routing EU7 Client C PLG:8 product-intent features; suppress active users; lifecycle co-exist910 Same engine, different policy documents + feature flags per tenant.Common mistake
“One global ICP and one sequence template keeps the agency efficient.”
Worked spine — Client A happy path
- 01Vendor outage — skip provider, degrade coverage, alert, do not block forever.
- 02Bounce spike — throttle fleet, freeze enrolls, hygiene loop, client comms.
- 03CRM down — queue write-backs; do not stop acknowledging replies internally.
- 04Cross-tenant misconfig — page sev-1; key/namespace audit; customer notice process.
- 05Credit exhaustion — pause enrich for tenant; surface budget owner.
Capstone rubric
1CAPSTONE HIRE RUBRIC (score 1–4 each)23 1. Control plane clarity (states, events, tenant_id)4 2. ICP + scoring versioning and suppressions5 3. Enrichment waterfall economics + validation6 4. Sequence graph stops, capacity, HITL7 5. Deliverability architecture + incident response8 6. Reply ops SLA + CRM write-back idempotency9 7. Attribution honesty + experiment hooks10 8. Multi-tenant isolation + least privilege11 9. Metrics / SLOs / kill criteria12 10. Communication under timebox (waypoints)1314 Strong hire: ≥3 on most, no 1s on isolation or stop-on-reply.15 No-hire patterns: tool tour only; shared caches across clients;16 no bounce budget; Slack-as-SoR; single ROI decimal to board.Key idea
Interview narration script (condensed)
Drill: whiteboarding checklist
1BEFORE YOU END THE MOCK — CHECK23 [ ] Tenancy boundary drawn4 [ ] State machine or stages listed5 [ ] MVE fields + waterfall accept rule6 [ ] Stop-on-reply and booking stop7 [ ] Domain isolation from primary corp mail8 [ ] Bounce/complaint budgets + throttle9 [ ] Reply SLA + atomic owner10 [ ] Event list for attribution11 [ ] One experiment design12 [ ] Two failure modes + mitigations13 [ ] Explicit non-goals (what you won’t build yet)Common mistake
“Capstones are about choosing Clay vs Outreach correctly.”
Self-score exercise
Failure injection table (practice saying these)
1FAILURE → DETECT → CONTAIN → RECOVER23 Cross-tenant key misconfig4 detect: audit log / canary contact5 contain: freeze affected workers; rotate keys6 recover: re-encrypt if needed; client notice runbook78 Bounce storm client A9 detect: rolling hard_bounce% alert10 contain: throttle A only; keep B/C sending11 recover: hygiene + ramp; RCA to client1213 CRM write-back lag14 detect: reply without task > SLA15 contain: secondary notify queue16 recover: replay idempotent events1718 Enrichment budget blowout19 detect: spend anomaly20 contain: circuit break tenant enrich21 recover: sample dry-run; fix list filters- 01Q: How do you onboard a fourth client in a week? Tenant config templates, domain warmup checklist, CRM OAuth, ICP workshop → versioned score, seed list validation, dry-run sequence with internal seeds, then ramp. Timebox human work; automate the rest.
- 02Q: Shared enrichment credits or per-client? Per-client meters for cost attribution and noisy-neighbor control; shared volume discounts negotiated underneath without shared data caches.
- 03Q: What do you defer on day one? Exotic multi-touch MTA UI, fully automated phone, custom ML ranking — keep rules scoring, solid waterfall, stops, and reply SLA first. Depth before breadth.
- 01Pass bar — tenancy + stops + bounce SLO + reply write-back named without notes.
- 02Strong — failure injections, experiment hooks, cost meters, explicit non-goals.
- 03No-hire — tool tour, shared PII cache, no kill criteria, Slack-as-SoR.
Key idea
articleClay — GTM engineering resourcesClaydocsGoogle email sender guidelines (fleet baseline)GoogledocsSalesforce multi-tenant integration patterns (conceptual)SalesforcedocsHubSpot private apps / integration authHubSpotThe capstone is not a tool demo. It is proof you can own reputation, data boundaries, and revenue ops as one system.
Checkpoint
Agency design shares one Redis cache of emails across all clients for “efficiency.” Verdict?
Checkpoint
In the capstone mock, where should you spend the first five minutes?
Checkpoint
Client C PLG active users start receiving cold sequences. Which control failed?
Checkpoint
You must pick one kill criterion for the whole multi-client platform’s automated throttle. Best default?
Checkpoint
Strong closing line in a GTM eng design interview?
Ready to run a 45-minute multi-client outbound system design mock against the capstone rubric?
Takeaways
- Capstone = tenancy + full outbound spine + SLOs + honest metrics.
- Shared workers, isolated data/keys; stop rules and bounce budgets non-negotiable.
- Rubric beats tool lists; practice timed narration with failure injections.
- Track complete: revisit weak lessons; pair with gtm-stack-automation for CRM depth.
Track complete. Schedule a mock on the multi-client prompt and re-score the ten-dimension rubric.
Sources
Free to read · better with Enzo
Learn it with Enzo
Save your progress, answer the checkpoints, and let Enzo quiz you on what you just read.