A sales automation that runs as itself, not as an administrator

The lead process rebuild depends on automation writing to records under its own name rather than under a person's. That needed a separate identity with a narrow role, and a test of whether the platform will let such an identity do the work. It will do most of it. The automation now signs in as […]

In this series · Part 26 of 27

1Dynamics 365 CRM: API integration + change-control repo2Dynamics 365 CRM: Last Contact Engagement tracking on Accounts3Turning a sales-intelligence export into a clean CRM data model4Dynamics 365 CRM: contacts inherit their company’s website, and emails timestamp by send time5Your SEO health now lives as a dashboard inside the CRM6Contact form duplicate detection now reads the request, not just the address7Marketing list members now show engagement and account fit8Campaign responses now create leads behind a confirmation step9Three CRM automations passed their tests without running the code that had just changed10A signature defect that three mailboxes agreed was not there11Why a corrected email signature kept sending the old one12A read-only CRM endpoint for scoring outside the desktop13Choosing what runs the AI layer in the CRM sales process14Asking whether a partner is involved, instead of inferring it15An email step in the sales process can now be excused, not only sent16The rehearsal that guards every process change had been failing silently17A one to one email from a lead left the engagement record blank18Two local dependencies, and only one was obvious19Filing a generated document to the record automatically20One meeting that served two process steps, recorded as two21A setting that stored correctly, read back correctly, and was never in force22Generating a product catalogue from one canonical file23Three date fields that existed on every row, and had never once been written24Unused, unreferenced, and still not safe to delete25A measure that could not record early26A sales automation that runs as itself, not as an administrator27A stage change that was refused, and reported as a success

On this page

Free Revenue Lifecycle Assessment

Connect with Marissa Wright to receive a free Revenue Lifecycle Assessment Report on your own business.

Book a consult →

The lead process rebuild depends on automation writing to records under its own name rather than under a person's. That needed a separate identity with a narrow role, and a test of whether the platform will let such an identity do the work. It will do most of it.

  • The automation now signs in as itself, with a role built for the job rather than as an administrator. It can read leads and it can create, read, update and assign tasks and emails. Proving the role really is narrow meant asking it to read something outside that role and having the platform refuse, which is stronger evidence than reading the role back, because the refusal comes from the system rather than from the person who built it. One thing worth knowing for anyone doing the same: a new role reads back holding more than it was granted, because the platform seeds every role with a set of its own, so the only honest way to state what a role allows is to read the role and not the grant.
  • Whether the connection really was the automation rather than the person could not be established from any configuration screen. The name, the owner and the status all look identical either way. The only evidence available anywhere is a record showing who last changed it, so the test was to have the automation write to a disposable record and read the name back off it. It came back as the automation.
  • The automation can run the reconciliation on a schedule but cannot start it the moment a record changes. Two flows identical in every respect except which identity they used settled that: the one on a person's connection fired immediately, the one on the automation's never fired at all. The plan now reconciles every fifteen minutes rather than within seconds, which keeps the record of who changed what that the separate identity exists to provide.