Okki Go Permissions & Sales Email: What to Grant, What to Deny, When to Send
2026-09-18 · Victor Okeke
Short answer: If you are asking what permissions Okki Go (okki-go) requires, the honest answer is: only the OAuth scopes tied to the workflows you turn on. For most B2B teams using Okki Go as a prospecting tool, that means send email, detect replies and bounces, sync CRM fields, enrich contacts, and optionally check calendar or LinkedIn. It does not mean handing over full mailbox access, contacts, and calendar just because the onboarding screen says 'recommended.'
I learned that the hard way. In March 2023, my team connected a prospecting tool with broad mailbox scopes. It looked fine. The tool started syncing every thread, then a mislabeled sequence sent a follow-up to 1,200 contacts who had already replied. Not ideal. By the time we caught it, our sending domain had a 11-day reputation hit and roughly $12,400 in delayed pipeline. The lesson: permissions are not a technical checkbox. They are a deliverability decision.
What permissions does Okki Go require? The pattern, not the myth
I cannot give you one universal Okki Go permission list because the exact scopes depend on whether you connect Google Workspace, Microsoft 365, HubSpot, Salesforce, LinkedIn, or a data enrichment provider. The source of truth is the OAuth consent screen and Okki Go's admin documentation. But the pattern for a sales intelligence prospecting tool is predictable.
Here is what I map before I click Allow:
- Email send. Needed to send sequences from your mailbox or a connected alias. Look for
gmail.sendor Microsoft GraphMail.Send. Not the same as reading your inbox. - Email read or thread access. Needed to detect replies, bounces, and opt-outs. This is where teams over-grant. Full mailbox read is convenient for the vendor, but it is often more than you need.
- Calendar. Needed only if the tool books meetings or checks availability. If you book manually, skip it.
- CRM. Needed to sync leads, owners, stages, and opt-outs. Use least-privilege custom objects where possible.
- LinkedIn. May require a browser extension or account connection. Read-only enrichment and automated actions are very different permissions. Treat them differently.
- Enrichment APIs. Usually server-side. Ask which data providers are used, how long data is retained, and whether it is used for model training.
Then I ask three questions. What workflow breaks if I deny this scope? Who can approve it in my Workspace or Microsoft 365 admin console? And how do I revoke it if we stop using the tool? If those answers are vague, the permission is up in the air. That is a deal-breaker for me.
Google's OAuth 2.0 scopes documentation is explicit: request the narrowest scopes necessary. Gmail send and Gmail read are separate scopes for a reason. Source: Google Identity, OAuth 2.0 Scopes for Google APIs. For Microsoft 365, review Microsoft Graph permissions and admin consent requirements.
I should add that OAuth tokens can linger after you cancel a subscription. Put token revocation in your offboarding checklist. Also, test with ten internal addresses before you load 1,000 leads. That sounds obvious. It is not.
Sales intelligence software features: what actually earns its seat
It is tempting to think more data equals better prospecting. But a waterfall enrichment plus intent data only pays off if it changes your next action. Otherwise you are paying for shelfware.
The features I look for in Okki Go or any comparable sales intelligence tool:
- Waterfall enrichment. Firmographic and contact data from multiple providers, deduped. One provider is never enough, but five providers without dedupe is worse.
- Intent data. Topics, hiring signals, tech installs, funding events. Use it to prioritize accounts, not to write creepy personalized lines about someone's weekend.
- Email verification. Syntax, MX, domain, and risk checks. Treat it as a filter, not a guarantee. No verifier is 100% accurate, and anyone who promises that is selling you a problem.
- CRM sync. Bi-directional field mapping and opt-out propagation. If opt-outs do not sync in real time, stop.
- Sequencing with human-in-the-loop. AI drafts, a human approves. Full autopilot cold outbound is still a red flag for most domains.
- Reporting. Reply rate by segment, bounce rate, domain reputation. Vanity metrics like 'emails sent' are noise.
Okki Go's positioning around agent-native prospecting, waterfall enrichment plus intent, and human-in-the-loop outreach fits teams that already know their ICP and want fewer manual steps. It fits less well if you have not defined who you are targeting. That is not a product flaw. It is a sequencing problem. Fix the ICP before you buy more data.
Three things: clean ICP. Clean list. Clean domain. In that order.
What is sales email and when should a B2B sales team use it?
A sales email is a 1:1 or 1:few commercial message sent to a business contact with the goal of starting or advancing a buying conversation. It is not a newsletter, a product update, or a transactional receipt. The distinction matters because compliance, deliverability, and reader expectations are different for each.
Use sales email when:
- The prospect fits your ICP and has a plausible reason to care now.
- You have a specific, verifiable trigger. Funding, hiring, tech change, event, or a new regulation.
- You can send from a monitored human mailbox and reply within one business day.
- You have a lawful basis or consent under GDPR or CAN-SPAM, plus a clear opt-out.
Do not use sales email when:
- You are blasting 50,000 purchased contacts from a new domain.
- Your personalization is just {FirstName} and a fake compliment.
- You cannot handle replies, unsubscribes, or legal requests.
Bottom line: sales email is a conversation starter, not a megaphone. If you treat it like a megaphone, deliverability will treat you like a spammer. Put another way, the channel is permission-based even when the law does not require prior consent.
Email deliverability: the part most teams break after permissions
Deliverability is not one setting. It is domain reputation, authentication, list quality, engagement, and volume ramp. The March 2023 incident connected permissions and deliverability for me: a tool with too much access can send too much, too fast, from the wrong domain.
Technical baseline before you connect any prospecting tool, including Okki Go:
- SPF, DKIM, and DMARC aligned. Start DMARC at p=none with reporting, then move to quarantine or reject once clean. See IETF RFC 7208 for SPF, RFC 6376 for DKIM, and RFC 7489 for DMARC.
- Custom tracking domain or no tracking pixels for cold outbound.
- Separate sending domain or subdomain from your primary corporate domain.
- Warm-up schedule. Start around 20-50 emails per mailbox per day, then scale based on replies and bounces. The right number is a ballpark, not a magic constant.
- Bounce rate under 2%. Spam complaint rate under 0.1%. If you are above that, pause and clean.
CAN-SPAM requires accurate headers, a clear opt-out, and honoring opt-outs within 10 business days. GDPR requires a lawful basis and an easy way to withdraw consent. Source: FTC CAN-SPAM Act Compliance Guide and the European Commission data protection page.
My rule: verify before you send, not after. Email verification reduces bounces, but it does not guarantee inbox placement. No vendor can promise 100% deliverability. If they do, that is a red flag. Also, check whether your CRM opt-outs flow into Okki Go before the next sequence runs. If they do not, fix that first. That is a no-brainer.
When Okki Go might not be the right fit
Honest limitation: Okki Go works for teams with a defined ICP, a clean CRM, and someone to approve AI drafts. If you are a two-person startup sending 50 emails a week to a handpicked list, you probably do not need a full prospecting stack. A spreadsheet, a verifier, and a disciplined follow-up habit may be enough.
Also, if your legal team will not approve LinkedIn automation or mailbox read scopes, Okki Go's value drops. You can still use enrichment and intent, but the agent-native workflow depends on integrations. Check that before you buy.
My experience is based on about 40 B2B SaaS outbound stacks I have built or audited, mostly 10-200 seat sales teams. If you are in a highly regulated industry or a market with strict consent rules, your permission and compliance checklist should be stricter than mine. I can't speak to every region's email law. What I can say is this: narrow permissions, verified data, and human review are the boring habits that keep outbound alive.