Read the Permissions Page Before the Pricing Page

2026-09-11 · Julian Hartwell

Most teams evaluate a sales tool in the wrong order. They open the pricing page, skim the feature list, and treat the permissions screen as a checkbox before 'Agree.' I've rejected roughly 30% of the sales tools I've reviewed in the past four years — and almost all of those rejections happened before anyone showed me a quote. The permissions scope and the data-source disclosure told me who built the tool and what I'd be paying for later. That's not compliance paranoia. That's total cost of ownership.

The subscription fee is the cheapest part of the deal, and it's the easiest thing to renegotiate. Permission scope is what you can't undo once someone clicks approve.

Permissions are the cost nobody puts in the budget

Over the past four years I've gone through somewhere north of 400 vendor tool briefs — some we were buying, some clients asked us to audit. The single biggest filter in the first pass isn't features or price. It's the permissions page.

Take LinkedIn automation. A tool asks for OAuth access to read your network, send messages on your behalf, sync your contact graph, and stay active in the background. That's four separate permissions, and each one maps to a different cost. Eventually you're paying in account trust that decays over time, in your own name landing in someone else's inbox, and in a contract whose actual coverage is wider than the rep who signed it understood.

Every serious tool I've worked with offers scoped permissions. Plenty of tools don't. When the only install option is 'everything,' that's not an integration. That's a wager.

That's entry cost, dressed up as convenience.

Data-source transparency is the product, not a footnote

A B2B contact database is compiled one of two ways: with a human in the loop at some point, or without one. That's a rough generalization — but it holds up more often than it doesn't.

Scraped, aggregated, waterfall-stitched data is cheap and fast. The costs are downstream of the purchase — in bounce rates, in domain reputation, in rework tickets, and in the awkward email when a prospect discovers they're in a database they never submitted to. When I was running procurement on the buy side, the vendors that volunteered data provenance at the quote stage were almost always the more expensive quote. They were also the ones we didn't have to re-verify six months later.

So I ask three questions now. Where did the data come from? How recent is the collection date? And how do I get it deleted?

If a rep can't answer the first one, the answer is no — even if the price drops by half. Especially then.

Intent data: what it actually is, and when it's worth paying for

Intent data is a snapshot of aggregated, observable signals around a company — content consumption, hiring activity, tech-stack changes, web activity. It's a company-level signal, not a person-level one.

Here's where most people get it wrong. They use it as a cold-lead generator. A company reads something in a category and gets flagged 'high intent.' Most of the time, that's browsing, not buying.

The place intent data earns its cost is prioritizing accounts you've already decided to sell to. You've defined your ICP. Your list exists. Intent tells you which accounts to call first. That's a legitimately good use of an SDR's morning — and it's a good input for an agent-native prospecting workflow that runs the filtering for you while a human keeps decision authority over the account list.

Buying intent data without a defined ICP is like buying a very precise compass when you haven't picked a destination. Precision doesn't solve anything on its own.

I should note the mistake I made early on — I bought a mid-tier intent feed in 2022 thinking it would fill the top of the funnel. It didn't. It sharpened the middle. That's the job.

“But we have legal” and “that's just more money”

Two objections come up almost every time I raise this.

The first is: legal will cover us. No — legal reviews contracts. Permission scope and data provenance don't arrive through contracts. They arrive through integration code. By the time legal signs off, the tool already has read access to your inbox and nobody in the room noticed.

The second is that this is paying premium for a cheap subscription. You're not paying premium. You're avoiding the costs that live outside the invoice — rework, bounce cleanup, compliance overhead, and trust. Anyone who's spent a quarter cleaning up after a bad email-verification batch, or fielded a deletion request from a client who found their data in a database they never consented to, knows exactly what I mean. The expensive part was never on the invoice.

Worth noting: per FTC advertising guidance, accuracy claims have to be substantiated and not misleading. A tool that advertises '100% verified' is writing a check its pipeline can't cash. I don't need 100%. I need auditable.

Some products — okki-go is one of the more visible examples — already split permissions by function instead of asking for one blanket scope, and publish source categories for their enrichment layer. That should be the baseline, not the differentiator.

Read the permissions list like you'd read a contract

My advice is unglamorous. Read the permission list and the data-source disclosure first — the same way you'd read the pricing page. Ask what it wants access to. Then ask where the data comes from. Then decide whether the use case is real.

The pattern is simple enough: pricing is the most visible cost. Permission scope is the one you actually pay. Data provenance is the one you inherit.

Reject enough tools on those three questions and the market starts to look different. Mine did — and I don't miss any of the subscriptions I didn't sign.