Agency and consultant access handoff
When to use this guide: Use this guide when an agency, consultant, or GTM operator is connecting OutboundSync on behalf of a client — or when the client needs lasting access after the engagement ends.
Outbound, Salesforce, Clay, and other GTM agencies run into the same questions on setup calls: which email logs in, why other clients’ webhooks appear under one login, who can edit receivers after handoff, and what breaks if the consultant leaves the client CRM. This guide covers the shared access model, then the CRM-specific differences that matter for handoff.
For adding coworkers inside a single company workspace (not a multi-client agency engagement), start with How teammates get OutboundSync account access.
Who this is for
Section titled “Who this is for”- Outbound and GTM agencies operating client SEP + CRM stacks
- Salesforce partners and HubSpot agencies connecting OutboundSync for a client portal
- Clay operators and freelance consultants who set up sync, then leave the account with the client
The audience is the agency or consultant. The CRM destination is still HubSpot, Salesforce, Close, Attio, or another supported CRM — Clay and similar tools are workflow context, not OutboundSync CRM destinations.
How OutboundSync access works
Section titled “How OutboundSync access works”OutboundSync uses passwordless email login at app.outboundsync.com. There is no separate workspace invite flow for agencies.
- Sign in with any email. On first login, OutboundSync creates an account for that address — see Create your OutboundSync account.
- Connect the client CRM. That connection scopes the CRM-backed workspace that owns webhook receivers and synced activity.
- Create webhook receivers and paste the URLs into the client’s sales engagement platform.
The login email does not need to match the CRM user. What matters for the initial connect is that whoever completes OAuth has enough CRM admin rights to approve OutboundSync’s scopes.
Three roles that are easy to confuse
Section titled “Three roles that are easy to confuse”| Role | What it controls |
|---|---|
| OutboundSync login | Who can sign in at app.outboundsync.com and (after support permissioning) see or manage that CRM’s receivers, logs, and Connected Accounts |
| CRM OAuth authorizer | Which CRM identity approved the OutboundSync connection — HubSpot Super Admin / Salesforce System Administrator (or equivalent) at connect time |
| Webhook owner | Per-receiver setting (for example HubSpot Select Owner) for who owns newly created contacts or activities in the CRM — not the same as OutboundSync UI access |
Multi-client agencies under one email
Section titled “Multi-client agencies under one email”One OutboundSync login can hold multiple CRM connections. If you already support other clients, you may see their webhook receivers when you sign in. That is expected — each Connected Account is a separate CRM portal/org, not a shared “agency workspace” that mixes client data into one configuration.
The client does not automatically inherit that login. If the client needs to operate the same HubSpot- or Salesforce-backed receivers after the consultant finishes the engagement, the client must sign in once with their own email, then support must permission them onto the connected account. Until then, the client sees their own empty (or separate) OutboundSync profile.
Who can edit webhooks
Section titled “Who can edit webhooks”OutboundSync does not offer self-serve user invites. After CRM connect:
- Users permissioned onto the same CRM-backed OutboundSync account can view and manage that portal’s webhook receivers.
- A teammate or client who only signed up with a new email sees a separate profile until support permissioning is complete.
Contact support and ask to permission users onto the connected account. Include the primary account email that completed CRM OAuth, each email that should gain access, and whether they need admin-level access to webhooks and Connected Accounts. Details: How teammates get OutboundSync account access.
Recommended setup pattern
Section titled “Recommended setup pattern”- Prefer a durable client-owned OutboundSync login when the client will operate the integration long-term. Agency staff can still be permissioned onto that account for day-to-day work.
- Complete CRM OAuth with a client admin who has the right scopes (HubSpot Super Admin or Salesforce System Administrator / dedicated integration user). Agencies with temporary CRM admin access can complete OAuth themselves when the client is not on the call — see the CRM sections below for what must remain true after handoff.
- Create webhook receivers, configure the SEP, and store API keys as needed.
- Before the engagement ends, have client admins sign in once and contact support to permission them onto the account.
CRM-specific handoff notes
Section titled “CRM-specific handoff notes”HubSpot
Section titled “HubSpot”- Super Admin (or sufficient scopes) is required for the initial OAuth approve.
- After connect, the integration runs at the HubSpot account level. The authorizing HubSpot user can lose Super Admin or leave the portal and sync continues.
- To stop OutboundSync, uninstall the OutboundSync app from HubSpot — do not rely on removing the authorizing user.
See Disconnect CRM after connecting to OutboundSync? and Re-authorize your HubSpot account. Full setup: HubSpot setup guide.
Salesforce
Section titled “Salesforce”- The connection is tied to the Salesforce user who authorized OutboundSync. That user (or a dedicated integration user) must remain active, or sync stops.
- When an agency connects with an agency Salesforce user, removing that user later breaks the integration for the client. Prefer a client-owned or dedicated Salesforce integration user for OAuth when the agency will leave.
- On Salesforce, Created By on API-written records reflects the OAuth user — not every OutboundSync teammate who can open the UI. See Identifying OutboundSync activity in Salesforce.
See Disconnect CRM after connecting to OutboundSync? and Re-authorize your Salesforce account. Full setup: Salesforce setup guide.
Close, Attio, and other CRMs
Section titled “Close, Attio, and other CRMs”OutboundSync login, multi-client Connected Accounts, and support permissioning work the same way. Use the CRM’s own setup guide for OAuth and admin requirements:
Handoff checklist
Section titled “Handoff checklist”Before the agency or consultant steps away:
- Confirm the client’s CRM connection is healthy under Connected Accounts.
- Have each client admin sign in once at app.outboundsync.com.
- Contact support to permission those emails onto the connected account.
- Document webhook receiver URLs and which SEP workspaces/events use them.
- On Salesforce, confirm OAuth is owned by a client or dedicated integration user that will stay active — not only an agency user that will be deactivated.
- On HubSpot, confirm the OutboundSync app remains installed; the original authorizing Super Admin does not need to stay on the portal for sync to continue.