-
The short version
-
Argument one: permission scopes are a product spec, not a legal checkbox
-
Argument two: data source transparency tells you more about deliverability than any benchmark
-
Argument three: intent data is a timing tool, not a targeting tool
-
The objection I get every time: "but everyone scrapes LinkedIn"
-
Four questions I ask before a prospecting tool gets a yes
-
Where I've landed
The short version
I'll lead with the part that gets me uninvited from vendor calls: if a prospecting tool can't tell you, in plain language, what permission scopes it needs and where its contact data comes from, that isn't a documentation gap. It's a deal-breaker.
Not "a yellow flag." Not "something to circle back on." A deal-breaker.
I'm a quality and brand compliance manager at a B2B software company. Part of my job is reviewing vendor deliverables and security questionnaires before anything touches a customer-facing team—roughly 200 items a year across procurement, marketing, and now sales tooling. I rejected about 18% of first deliveries in 2025, and a surprising share of those rejections came down to one thing: nobody could tell me where something came from.
It took me about two years—or rather, closer to three once you count the year I spent just reading privacy policies—to understand that vendor transparency isn't a legal formality. It's a proxy for how the product is actually built.
Argument one: permission scopes are a product spec, not a legal checkbox
When a vendor asks for OAuth access, most buying committees glance at the checkbox list and move on. That's a mistake. The scope list tells you more about the architecture than the demo does.
Ask yourself what the tool actually needs versus what it requested:
- A tool that reads your CRM contacts needs read access to that object. Fine.
- A tool that sends email on a rep's behalf needs send permission on that mailbox. Also fine, if the rep knows.
- A tool that asks for full mailbox read/write across every seat, plus calendar, plus the ability to modify contacts—and then explains it as "for better sync"—is telling you something. It didn't design around least privilege. It designed around convenience, and you're the one carrying the risk.
Then there's LinkedIn. If a tool asks a rep to hand over a session cookie or log in through an unmanaged browser session, that's a materially different risk profile from a tool using LinkedIn's official partner APIs. And yes, the official APIs expose far less. That's the trade.
Worth knowing: LinkedIn's User Agreement prohibits scraping and automated data collection (Source: LinkedIn User Agreement, linkedin.com/legal/user-agreement, accessed April 2026). You can argue about whether that rule is reasonable. You can't argue that the rep's account isn't the asset being put on the table—and that account is usually tied to their name, their network, and five years of relationship history.
I've watched a sales team lose a senior AE's account access for nine days during a quarter-end push. Nine days. The tool was reinstated. The trust wasn't.
Argument two: data source transparency tells you more about deliverability than any benchmark
The question everyone asks a B2B contact database vendor is "how many contacts do you have?" The question they should ask is "where did the last 10,000 come from, when were they last verified, and what happens when verification fails?"
Contact data decays. People change jobs, companies get acquired, domains get parked, role-based aliases get retired. A list that was 95% valid in January isn't 95% valid in October. So "verified" isn't a state—it's a timestamp, and it only means something if the vendor will tell you the timestamp.
Two things I check:
First, churn disclosure. If the vendor can't tell you their annual bounce or invalidation rate, they either don't measure it or don't want to say it. Both are answers.
Second, enrichment order. Waterfall enrichment—running a record through provider A, then B, then C until you get a match—performs completely differently depending on the sequence. Put the strongest source for a given data type first and you get better coverage from the same three vendors. Same inputs, different output. If a vendor can't explain their ordering logic, they probably don't have one.
This matters legally too. Under GDPR, relying on legitimate interest (Article 6(1)(f)) for prospecting requires a balancing test, and Article 21 gives individuals the right to object at any time—which means you need to know whose data you're holding and where it came from (Source: EUR-Lex, Regulation 2016/679, accessed April 2026). Under CAN-SPAM, the FTC requires accurate header information and a working opt-out honored within 10 business days (Source: FTC Business Guidance, business.ftc.gov, accessed April 2026). And Google's bulk sender guidelines, effective February 2024, ask bulk senders to keep Gmail spam complaint rates under 0.3% and support one-click unsubscribe (Source: Google Workspace Email Sender Guidelines, support.google.com, accessed April 2026).
You can't hit any of that from a black box. Regulatory information is for general guidance only—verify current requirements at the official sources above.
Argument three: intent data is a timing tool, not a targeting tool
Here's the counterintuitive one.
Most teams buy intent data to decide who to go after. It's much better at telling you when.
Third-party intent is usually built from a co-op of publisher content consumption—someone at a company read a handful of articles about a category over a few weeks. That's directional, not deterministic. It doesn't mean they're buying. It means they're reading. Treating a topic surge as a purchase signal is how you end up with a pipeline full of researchers and no deals.
First-party intent—your own site visits, docs page views, pricing page sessions, product usage—is cheaper, cleaner, and almost always stronger. Most teams underuse it because it lives in five systems nobody joined up.
So when should a B2B sales team actually use intent data? My rule of thumb: after your ICP is defined and your list is clean. Not before. Intent amplifies whatever targeting you already have. If your targeting is fuzzy, intent just helps you be confidently wrong at higher volume.
The practical use is sequencing. Same account, two different weeks, two very different openers. That's a timing play. That's what the data is good for.
It's tempting to think intent data replaces the ICP work. It doesn't. It sharpens the timing on accounts you already had a reason to want.
The objection I get every time: "but everyone scrapes LinkedIn"
Fair. Plenty of tools do it. Plenty of teams run it.
Everyone also drives over the speed limit. The question isn't whether other people do it—it's whether you've priced the downside. Nine days of lost account access. A rep's professional network flagged. A vendor relationship you now have to disclose on the next enterprise security review, because someone will ask how you sourced that contact list.
The other pushback I hear is that transparency slows things down. It does. Maybe by a week or two during evaluation.
The alternative cost shows up a quarter later, when you're explaining to legal why a rep's mailbox is connected to a service nobody vetted. I've been in that meeting. It runs long.
Four questions I ask before a prospecting tool gets a yes
- What permission scopes do you request, per seat, and why does each one exist?
- Where does contact data originate, and can you show me a sample record's full provenance?
- What's your invalidation rate over the last 12 months, and how do you measure it?
- If a rep's account gets restricted, what's your remediation path?
Vendors who answer these well tend to be the same vendors who answer everything else well. That's not a coincidence. It's a signal about how the company thinks.
We hold our own stack to that bar. That's part of why we run agent-native prospecting with human-in-the-loop outreach rather than fully automated sending—not because automation is the problem, but because someone has to own the judgment call about who gets contacted and why. Agent-native prospecting handles the research and enrichment; a person still decides whether to hit send.
Where I've landed
Permission scopes and data source transparency aren't procurement formalities. They're the earliest available signal of whether a vendor will be a good partner or a problem you inherit.
You don't need a perfect answer from every vendor. You need an honest one. A tool that says "here's exactly what we access, here's exactly where the data comes from, and here's what we don't do" is worth more than one that promises everything and explains nothing.
Bottom line: the demo shows you the ceiling. The permission list and the provenance answer show you the floor. Buy for the floor.
