Marketing

Email CRM and Consent in Velveteen

Updated August 4, 2026

The short answer

Email CRM is the administrator-only, workspace-scoped system for managing contact records, brand relationships, consent evidence, lists, tags, segments, source history, message history, and privacy operations. Account sign-in, purchases, and support activity do not create marketing consent by themselves.

Use the canonical CRM at Dashboard, CRM for every website and store audience. The same contact can relate to several artist or label brands, while each consent projection remains brand- and topic-specific.

Manage a contact

  1. 1

    Create or find the record

    Search by email or name, or create an administrator record with an optional brand relationship. A manually created relationship starts non-affirmative and pending.
  2. 2

    Review the complete context

    The detail view separates core fields, custom fields, brand and topic consent, evidence, source events, lists, tags, messages, suppressions, and the typed timeline.
  3. 3

    Edit and organize

    Update bounded profile fields, add an internal note, and attach or remove brand-scoped lists and tags. Membership never grants consent.
  4. 4

    Use legal-impact controls carefully

    Merge, roster moves, consent corrections, exports, and erasure require a reason; destructive actions also require a preview or explicit confirmation.

Consent is separate from audience membership

A subscribed projection requires affirmative, contact-confirmed evidence for the matching brand and topic. An admin can unsubscribe, suppress, or reclassify questionable evidence as pending, but cannot manufacture a subscription by typing a note or selecting a list.

Lists and segments are audience organization tools. Every marketing send re-checks the current consent, suppression, identity, and provider gates at dispatch time.

Heads up

Do not treat a fan account, purchase, membership, waitlist request, or imported address as affirmative marketing consent unless the source flow records the required disclosure and action evidence.

Privacy and workspace boundaries

Every contact belongs to exactly one email workspace, while brand relationships, source facts, topics, and timeline events remain explicitly scoped. Cross-workspace IDs are rejected before data is returned or changed.

Exports are formula-safe and audit records retain bounded counts or masked identifiers. Erasure redacts the contact, operational copies, import and webhook payloads, suppression records, and message-linked personal data according to the privacy runbook.

Tip

Use the durable contact URL when handing an investigation between administrators; it opens the same canonical detail surface used by CRM search.

Domains, delivery, and reputation

Email identities are administrator-managed and separate from Velveteen platform mail. The managed default domain and each custom domain have their own identity records, while provider verification, domain-scoped credentials, account webhooks, and production readiness are recorded as separate gates.

Transactional messages and marketing campaigns use separate streams. A suppression or reputation incident can pause the affected marketing scope without pausing unrelated transactional delivery; shared provider-team rate, quota, suppression, and reputation coupling remains visible to administrators.

Warmup uses accepted volume and available bounce, complaint, and rejection facts. Missing recipient-level Gmail complaint coverage is shown as unknown, and Postmaster Tools is supplemental aggregate evidence rather than a replacement for provider events.

Heads up

A verified domain does not by itself authorize sending. Real provider delivery remains off until the tenant key, webhook, controlled smoke receipt, and paid production gates are accepted.

Campaigns, automations, and imports

One-off campaigns are draft-first: define the brand, template, sender, topic, audience snapshot, exclusions, schedule, and approval before dispatch. Automations pin each run to an immutable version and re-check purpose, consent, suppression, and provider controls at send time.

CSV imports begin as a dry run and staged review. Invalid or unverified consent is not silently subscribed, and an approved staging record does not itself trigger provider delivery or bypass the import gate.

Tip

Use the preview and report surfaces to inspect audience counts and skip reasons before any future real send is authorized.

Templates and reviewed publication

  1. 1

    Choose a brand

    Open Dashboard, Email, Templates and select the brand whose tenant-owned content you are editing. Workspace and brand boundaries are enforced by every route.
  2. 2

    Install or create a draft

    Install a Babbage starter or create a new draft. Marketing templates remain tied to a brand topic; transactional templates must use a registered purpose and event contract before publication.
  3. 3

    Preview and save

    Edit subject, declared variables, constrained blocks, and links. Preview uses the same escaped renderer as sends and supports desktop/mobile plus light/dark inspection. Each save creates an immutable version.
  4. 4

    Review and publish

    Publishing requires a bounded admin review reason. Raw HTML, unsafe links, unknown variables, missing marketing unsubscribe links, and unrelated promotional transactional blocks are rejected before publication.
  5. 5

    Run a sink test

    A non-production sink test is available only to administrators, only for an explicitly allowlisted recipient, and only when the test-mode gates pass. The dashboard stores a digest rather than displaying the recipient address.

Heads up

A verified sending domain does not authorize provider delivery. Template work can be built and sink-tested while tenant credentials, webhooks, live sends, database apply, and deployment remain separate approval gates.

Retention and erasure

Retention workers operate in bounded, workspace-scoped batches and report counts without addresses or raw payloads. Exact message payloads, event/link descendants, imports, webhook and sink bodies, automation context, consent evidence, timeline metadata, rollups, attributions, suppressions, and completed privacy-operation references have explicit redaction or deletion paths.

Contact erasure starts with a dry-run preview, requires a reason, checkpoints relationship/history/redaction stages, and can resume by operation ID after a failure. Retention and object-store execution remain disabled until the approved PII, storage, and operational decisions are recorded.

Heads up

Do not treat a successful preview as completion. Wait for the operation to reach completed and retain its masked checkpoint receipt.

Frequently asked questions

Does signing in or buying something subscribe a fan?+

No. Account, purchase, membership, and support facts are separate from marketing consent.

Can an admin subscribe a contact manually?+

No. The admin correction workflow can unsubscribe, suppress, or mark evidence pending. Only a contact-confirmed preference action can create affirmative consent.

Do lists and segments grant consent?+

No. They organize audiences. The send gate always checks live brand/topic consent and suppressions.

Where should website CRM users go?+

Use Dashboard, CRM. Website and email contact entry points redirect there so there is one canonical management surface.

Who can use the CRM?+

The current pilot is limited to Velveteen administrators. Fan-facing capture forms are public and abuse-protected, but their configuration and data remain admin-only.

Does verifying a domain enable sending?+

No. Domain verification, a tenant sending key, an account webhook, a controlled smoke receipt, and the paid production gate are separate readiness facts.

Can a marketing suppression stop transactional mail?+

A correctly scoped marketing pause does not stop unrelated transactional identities. Shared provider-team coupling is shown explicitly so administrators can see the remaining blast radius.

What does an import approval do?+

It records reviewed staging state. It does not manufacture consent, write CRM rows without the import executor gate, or send provider email.

Can I publish arbitrary HTML in a template?+

No. The editor uses a bounded block contract with escaped text, HTTPS or root-relative links, declared variables, a required marketing unsubscribe link, and immutable reviewed versions.

Can a transactional template contain a release promotion?+

No. Registered transactional purposes reject unrelated promotional catalog, social, and column blocks. Use a consented marketing topic for promotional content.

Can I undo an erasure?+

No. Erasure is a destructive privacy operation. Preview it carefully, provide a reason, and use the operation ID to resume a failed checkpoint rather than attempting to restore personal data.

Related articles