Verification research
The 7-Step Checklist I Use Before Letting Any Sales Tool Touch Our LinkedIn Account (And Why It Took Me 3 Years to Build It)
2026-09-11 · Julian Hartwell
-
Who this checklist is for (and what it solves)
-
Step 1: Map every permission the tool requests—and match it to a real need
-
Step 2: Force the vendor to name their data sources in writing
-
Step 3: Test email verification accuracy with your own domains
-
Step 4: Run a 30-day intent data reality check
-
Step 5: Check how the tool handles LinkedIn's terms of service
-
Step 6: Verify the tool's human-in-the-loop controls
-
Step 7: Calculate total cost including the failure case
-
Common mistakes I still see (and one I made last month)
Who this checklist is for (and what it solves)
I've been running outbound operations for B2B sales teams for nine years. Since 2017, I've personally approved tools that cost us north of $40,000 in wasted spend, caused two LinkedIn account restrictions, and once triggered a GDPR complaint from a prospect in Germany. Should mention: that complaint was resolved without a fine, but it took six weeks of legal back-and-forth.
This checklist is for RevOps managers, SDR leads, and agency owners who are evaluating tools like okki-go, or any platform that touches LinkedIn automation, scrapes contact data, or layers intent signals on top of prospecting workflows. It's not theoretical. Every step comes from a specific failure I've either caused or cleaned up.
The checklist has 7 steps. Don't skip any of them—I've tried, and it always costs more later.
Step 1: Map every permission the tool requests—and match it to a real need
Most teams install a Chrome extension, click "Allow," and move on. That's how we ended up with a tool in 2022 that had read access to our entire Google Workspace. Nobody on my team could explain why it needed that.
Here's what I do now. I open the permission request and literally write down each scope on a whiteboard. Then I ask: "What specific feature breaks if we deny this?" If nobody can answer within 30 seconds, we deny it and see what happens.
For LinkedIn automation specifically, watch for these:
- Profile read access — usually needed, but check if it's read-only or includes messaging.
- Connection list access — this is where scraping risk lives. Some tools download your entire network on install.
- Email send scope — if the tool also touches your inbox, that's a separate approval in our process.
The question everyone asks is "is this tool safe?" The question they should ask is "what's the blast radius if this tool's database gets breached?"
Step 2: Force the vendor to name their data sources in writing
This is the step most people skip. I used to skip it too—until Q1 2024, when we discovered that a "B2B contact database" we'd been paying $800/month for was largely compiled from scraped LinkedIn data. That's not inherently illegal in all jurisdictions, but it created a compliance problem for our EU campaigns.
Now I require a written data provenance statement. Not a marketing page. An email from their legal or compliance team listing:
- Primary data sources (e.g., "public web scraping," "licensed data brokers," "user-contributed," "opt-in panels")
- Refresh frequency (daily, weekly, quarterly—take this with a grain of salt; verify with a test query)
- GDPR/CCPA compliance posture, with a named DPO if they claim EU coverage
- Whether email verification is real-time or cached
If a vendor won't put this in writing, that's your answer. Walk away.
Step 3: Test email verification accuracy with your own domains
Here's the uncomfortable truth: most "email verification" tools are 85-95% accurate on a good day. The vendors claiming 99%+ are usually counting "valid syntax" as "valid inbox," which is meaningless.
I keep a test file of 200 email addresses: 50 known-good, 50 known-bad (hard bounces), 50 catch-all domains, and 50 role-based addresses. I run every new tool against this file before we load a single real prospect.
Never expected the pattern that emerged. Turns out the premium tool we trialed in October 2024 scored worse on catch-all domains than a $29/month alternative. The expensive one was flagging catch-alls as "valid" to inflate its numbers.
Step 4: Run a 30-day intent data reality check
Intent data is the most misunderstood category in B2B sales tech. Teams buy it expecting a list of prospects ready to buy. What they usually get is a list of companies that visited a website about a topic related to your product.
Those are not the same thing.
My process: for any intent data provider, I ask for a 30-day pilot with a control group. We split our target account list in half. Half gets intent-based prioritization, half gets our normal prioritization. Then we measure reply rates and meeting bookings.
In our November 2023 test, the intent-prioritized group had a 12% higher reply rate but the same meeting booking rate. Put another way: we got more conversations that didn't go anywhere. That's useful to know before you commit to an annual contract.
Step 5: Check how the tool handles LinkedIn's terms of service
I'm not a lawyer, and this isn't legal advice. But I've had two LinkedIn accounts restricted, and both times it was because a tool was automating actions faster than a human plausibly could.
What I check now:
- Does the tool have a built-in daily action limit? (If it lets you set 200 connection requests/day, that's a red flag.)
- Does it randomize timing between actions?
- Does it mimic human browsing patterns (profile views before messages, etc.)?
- What's the vendor's response when LinkedIn changes its detection? (Ask for a changelog.)
Dodged a bullet when we tested a tool that promised "unlimited" LinkedIn actions. We ran it on a test account for three days. Account restricted by day four.
Step 6: Verify the tool's human-in-the-loop controls
Fully automated outreach doesn't work for most B2B sales teams. The reply rates tank, and the messages read like they were written by a robot because they were. What works—at least in my experience—is human-in-the-loop: the tool does the research and drafting, a human reviews and sends.
When evaluating any tool, I ask: "Show me the review step." Can a human edit every message before it sends? Can they skip, rewrite, or personalize? Is there a queue view, or does it just fire-and-forget?
If the demo shows a "set it and forget it" workflow, that's not a tool for serious outbound. That's a spam cannon with a nice UI.
Step 7: Calculate total cost including the failure case
Most teams compare monthly subscription prices. That's the wrong math.
Total cost includes:
- Subscription fee
- Onboarding/setup fees
- Time spent cleaning bad data (I estimate 3-5 hours per 1,000 records)
- Cost of a restricted LinkedIn account (lost pipeline, recovery time)
- Cost of a compliance complaint (legal review, potential fines)
When I ran these numbers in December 2024 for a tool we were considering, the "$99/month" option actually cost more than the "$499/month" option once we factored in data cleaning and a 2-week productivity hit from a restricted account.
Common mistakes I still see (and one I made last month)
Mistake 1: Trusting the vendor's case study. Every tool has a story about a team that 10x'd their pipeline. Ask for a reference you can call, not a logo on a slide.
Mistake 2: Skipping the data provenance step because "everyone scrapes." Everyone speeds, too. That doesn't make the ticket cheaper.
Mistake 3: Not testing with your actual ICP. A tool that works great for SaaS founders might fail completely for manufacturing VPs. The data coverage varies wildly by industry and geography.
My most recent mistake: In March 2025, I approved a tool based on a demo that looked perfect. I didn't run the test file from Step 3 because the vendor said their verification was "AI-powered." That AI flagged 40% of our known-bad emails as valid. We sent to them, got a 6% bounce rate, and our domain reputation took a hit that took three weeks to recover.
I should add that the vendor refunded us. But the domain damage was already done.
Small doesn't mean unimportant—it means potential. Same goes for checklist steps. The ones that feel like overkill are usually the ones that save you.
"The value of a checklist isn't the steps you remember. It's the steps you'd forget without it."
