Activated Cloud
← App Store

Prospect List Building

Activated Cloud✓ Officialactivated/prospect-list-building

No ratings yet4 installsv1.0.0Updated Oct 6, 2026● Unknown

Free · MIT

About

Builds a researched, scored list of target accounts and the right contacts inside them from public sources and the owner's CRM, with a reason to contact, a source and a lawful basis on every row, deduplicated against customers, open deals and opt-outs. Never buys or scrapes lists. Use when the team needs who to contact next. Not for deep research on one account (use account-research) or writing the messages (use cold-outreach-sequence).

Sales

Documentation

From SKILL.md · v1.0.0 · what the agent reads when it loads this skill3 files: SKILL.md, references/compliance-gate.md, references/list-schema.md

Prospect List Building

You build the list that outreach runs on: accounts that fit the ideal customer profile, two to four people per account who play a real part in buying, and for every row the evidence that makes contacting them reasonable now. The standard: every row could be defended to the owner, to the prospect and to a data protection regulator. Fewer, better rows beat a long list.

When to use

  • "Find me 50 companies like our best customers."
  • "Who should Nell email this week?"
  • "Build a list of logistics firms in the UK that just raised money."
  • "Find the right person to talk to at these 20 accounts."
  • Topping up a list that has run dry, or re-scoring an old one.

What you need

  • The ICP: criteria, disqualifiers, triggers, personas and fit score.
    • Check memory first.
    • If none exists, use clarify to get at least the target industry, size band, geography and buyer titles, and label the list "built without an agreed ICP".
  • The CRM as a connected app (HubSpot, Salesforce, Pipedrive, Attio) or a CSV export, to dedupe against customers, open deals and past contacts.
  • The suppression list: everyone who has opted out, asked not to be contacted or bounced. If there is none, ask the owner where opt-outs are recorded before you add a single contact.
  • Target count, the countries you are allowed to contact, and the channels planned (email, LinkedIn, phone). Countries decide the law.
  • The agent's own browser for public research. A paid prospect database is optional: use it only if the owner already pays for it and has connected it.

Method

  1. Run the compliance gate first. For each target country, confirm what the law allows for the planned channels before collecting anyone's details. Use references/compliance-gate.md, check anything uncertain with web_search against the regulator's own guidance, and cite it. Headlines to respect:
    • Never buy, rent or swap lists. You cannot show where the data came from or that people were told.
    • EU and UK GDPR apply to named business contacts ([email protected] is personal data). Record the lawful basis, usually legitimate interests with a short written balancing note, and the source of every personal data field.
    • Where you collect data from somewhere other than the person, GDPR Article 14 requires telling them, at the latest at the first communication. Outreach templates must include a short privacy line and an opt-out.
    • Some countries require prior consent even for business email (for example Germany). UK PECR treats sole traders and some partnerships like consumers. Canada's CASL needs consent, which can be implied only in narrow cases.
    • Flag rows the law does not let you email, and route them to other channels or drop them.
  2. Account list first, people second. Search for accounts that match the ICP using public sources:
    • industry association member lists and conference exhibitor or speaker pages;
    • public company registers (Companies House, SEC EDGAR and their equivalents);
    • press releases and funding news;
    • marketplace, integration or partner directories, and review sites;
    • job boards (a company hiring for the role you serve is a signal);
    • the owner's own inbound history and past enquiries. Respect each site's terms; do not scrape anything behind a login.
  3. Dedupe accounts against the CRM.
    • Match on normalised domain (strip www., lowercase) first, then normalised name (drop Inc, Ltd, GmbH, LLC and punctuation).
    • Remove current customers, accounts with an open opportunity, and accounts owned by a colleague unless the owner says otherwise.
    • Keep a removal tab with the reason for each.
  4. Score every account with the ICP fit score and a separate intent score from fresh evidence.
    • Each intent signal needs a URL and a date.
    • Discard signals older than 90 days unless the trigger has a longer window.
    • Drop accounts below the tier cut-off the owner set (default: tier B and above).
  5. Find the people. For each account above the cut-off, find 2 to 4 contacts across the buying committee: the likely champion, the economic buyer and one user or evaluator.
    • Sources: the company's own website, press releases, conference talks, published articles, and the person's public LinkedIn profile viewed manually in the browser.
    • Do not run automation, bulk exports or scrapers on LinkedIn; its User Agreement forbids them.
    • Confirm the person is still in the role (a recent post, a current team page). Mark anyone unconfirmed.
  6. Email addresses: published beats inferred.
    • Prefer addresses the person or company publishes.
    • If you infer one from the company's visible pattern (first.last@), mark it inferred and flag that it must be verified before sending.
    • Never send volume to inferred addresses; bounces above 2 percent damage the owner's sending reputation.
  7. Write the reason to contact. One line per contact linking a fresh signal to a likely pain, for example: "Hiring 3 warehouse planners in Leeds (careers page, 12 Sep) suggests they are scaling fulfilment manually." This line is the raw material for personalisation. A row with no reason is not ready.
  8. Screen against suppression (opt-outs, bounces, do-not-contact, competitors, the owner's personal exclusions) as the last step before handing over, and again before import.
  9. Quality check. Re-open 10 percent of rows at random (at least 5).
    • Confirm the person still holds the role, the signal is real, and the source link works.
    • If more than 1 in 10 fails, fix the batch, not just the sample.
  10. Hand over and import only with approval.
  • Show the summary on a show_card: counts by tier, by country, rows dropped and why.
  • Import to the CRM only after the owner agrees, with lead source set, status new and the lawful basis field filled.
  • Save the list location and date to memory.

Sizing the list

Work back from the meetings the owner wants, using the owner's own past rates where they exist (label any assumption):

  • contacts needed = meetings wanted / (delivered rate x positive reply rate x meeting-booked rate);
  • accounts needed = contacts needed / contacts per account.

Example with assumed rates: 10 meetings; 97 percent delivered, 8 percent positive replies, 60 percent of those book. Contacts = 10 / (0.97 x 0.08 x 0.60) = about 215. At 3 contacts per account, about 72 accounts. If the ICP only yields 40 good accounts, say so; do not lower the bar to hit the number.

Output

  • A CSV or sheet with the columns in references/list-schema.md, one row per contact, sorted by tier then intent.
  • A short summary: what you searched, how many accounts you reviewed, kept and dropped (with reasons), tier counts, any countries or rows held back for legal reasons, and the next best sources if more rows are needed.
  • No outreach. Messages are written in cold-outreach-sequence and sent only with the owner's go-ahead.

Checks before you finish

  • Every row has: source URL, date collected, reason to contact with a dated signal, lawful basis, country, email status (published, inferred or none).
  • No row matches the suppression list, a current customer or an open deal.
  • No data came from a bought list, a scraped login-only page or an automation tool.
  • Rows in countries where email needs prior consent are flagged for another channel or removed.
  • The 10 percent spot check passed, and you have said what you checked.

Pitfalls

  • Volume over fit. Two hundred loosely matched rows produce spam complaints, not meetings. Hit the target count only with rows that pass the tier cut-off; report a shortfall honestly.
  • Single-threading. One contact per account dies when that person ignores you or leaves. Find two to four roles.
  • Stale signals. "Raised a seed round" from three years ago is history, not a trigger.
  • Personal data you do not need. Collect business contact details and role only. No home addresses, personal phone numbers, personal social accounts or sensitive data.
  • Assuming B2B is exempt. It is not exempt from CAN-SPAM, GDPR or most national rules. Check every country.
  • Hiding uncertainty. If you could not confirm a role or an address, say so in the row.

See also: ideal-customer-profile, account-research, cold-outreach-sequence.

Versions

v1.0.0currentOct 6, 2026

Listed from the source repository.

Reviews

No reviews yet. Be the first.

Write a review