Pull to refresh
# Member outreach and lead coverage — team operating guide
Updated September 12, 2026. App: LandConnect Pro. Backend: srv1251391 / n8n and canonical Supabase project yiepwcjwssaspbbtnxzr.
## What the service does
The new Member Outreach service selects a fixed audience from a lead list or geographic area, assigns each lead to one canonical member account, and communicates on that member’s behalf only while their explicit permission is enabled. A Florida-only profile cannot receive Georgia leads through this service. Campaign criteria must also match; they cannot widen the member’s permitted geography or property requirements.
The configured TextMagic/Twilio BYOC sender is preserved. Messages identify the member’s team at PRG LandTech. Automated replies do not claim that the member personally typed them, invent personal experiences, or deny automation when asked. They reference the conversation, ask at most one useful question, and hand price discussions, uncertainty and human requests to a person.
## Optional future service setup (no current campaign requested)
1. Open Member Outreach in the latest app build, or the existing lead-list campaign dialog. The page path is `/MemberOutreach`.
2. Select a member. The account must map to exactly one canonical Supabase user. Only administrators, owners and programmers can save member restrictions or outreach permission. Ordinary members cannot change their restrictions; their authorized campaign access remains limited to themselves.
3. Enter the approved display name, states and any narrower county, ZIP, property-type, acreage or asking-price criteria. All criteria are optional. Blank geography preserves normal unrestricted routing. A county restriction requires exactly one state. Restrictions are independent of messaging permission. Missing values never pass a required acreage or price range.
4. Enable “Allow automated outreach and replies on this member’s behalf” and save. This is an explicit permission, disabled by default. A campaign does not imply permission.
5. Enter a campaign name and a lifetime recipient limit from 1 to 100. Paste canonical Supabase lead UUIDs for a list, or leave the list blank to select from existing inventory by area. Newly acquired lists must first use the existing importer; this feature does not purchase or fetch a new external list.
6. Create a draft, then preview. Review matches and exclusion reasons. Preview assigns nobody and sends nothing. Matches are the bounded selected audience, not an estimate of the whole market.
7. Start the campaign. Assignment is performed transactionally, existing ownership is preserved, and a duplicate phone cannot enter a second member campaign. Starting authorizes scheduled operation against the fixed audience. Exclusions and current ownership are rechecked.
No real member has been enabled and no member campaign has been launched as part of implementation/testing. No current member needs this service. First-member selection and campaign launch are deferred, not feature-completion prerequisites.
## Autonomous operation
The n8n member worker runs every five minutes, processing at most five messages per execution. It checks member permission, current canonical ownership, campaign state, recipient replies, human-response mode, opt-outs, verified mobile eligibility, verified consent, recipient timezone and contact windows before sending. Existing consent-aware policy uses weekday 10 a.m.–6 p.m. recipient-local contact checks; the global SMS quiet-hour check also applies.
An initial message is followed by at most three unanswered follow-ups, with delays of 3, 4 and 7 days after the previous confirmed delivery. Acceptance alone does not advance the sequence. A reply stops automated nurture. The last follow-up ends the sequence. Do not restart a completed sequence merely to contact the same person again.
Disabling a member pauses their campaigns and prevents further automated replies. Pausing a campaign stops scheduled outreach. Human-response mode takes priority. A message already submitted to the provider cannot be recalled. An existing conflicting assignment is never stolen; resolve ownership in the normal lead record and review any held campaign before resuming.
## Status meanings and recovery
- Attempted: a submission reservation/attempt exists. A pre-send cancellation may be recorded with zero provider attempts.
- Accepted: an individual provider message reference was returned. Accepted counts can include messages later delivered or failed; do not add those overlapping totals together.
- Delivered: an authoritative provider receipt confirmed delivery.
- Failed: the provider explicitly rejected or failed the submission/delivery.
- Unknown: a timeout, missing individual reference, or uncertain provider result. HTTP 200 and a session ID do not prove acceptance.
- Held/paused: review is required. A hold is tracked work, not a silently abandoned lead.
For unknown submissions or accepted messages whose database recording failed, check the provider history and stored queue reference first. Never blindly retry, delete an attempt, reset the total, or clear a hold to force a new send. The worker stops and the campaign pauses on uncertain outcomes. Repeated execution cannot reserve the same campaign lead/step again. Delivery events cannot move a delivered message backwards.
If consent, mobile verification, ownership or contact-window data is missing, correct the source record with real evidence. Do not fabricate consent or replace a missing value with an optimistic assumption. Resuming does not bypass these checks.
## Lead coverage and replies
The coverage monitor runs every 15 minutes. The old hourly nurture monitor also performs a harmless coverage scan. Both share a lock and deduplicated alerts. Coverage is available on Member Outreach; select a category to open up to 200 underlying lead records. It distinguishes suppressed/closed, uncontacted review, nurture held/scheduled/due, queued/uncertain messages, human-response mode and unanswered replies.
At verification, coverage included 50 unassigned reply threads and 14 assigned threads awaiting a response. The monitor created 64 durable review alerts. Assign an actual owner to unassigned threads, then review the conversation. Do not send a generic automated response just to clear an alert. Alerts follow changed owners and resolve when the underlying condition clears.
There are approximately 15,260 older nurture enrollments held for missing verified consent evidence (15,259 appear in the current coverage category because another lead is classified by a higher-priority state). These were not mass-released. The older queue-advancing nurture implementation now delegates enrollment to the existing consent-aware engine. Inbound replies also cancel pending legacy nurture/reengagement messages.
Inbound SMS is durably stored before acknowledgement. A dedicated authenticated `smsOwnerNotification` function resolves the actual canonical owner and creates a durable in-app notification. Missing/conflicting owners remain pending for review/retry. The repaired path creates in-app notices; live customer-to-owner delivery is still unverified. Email delivery is not claimed. No Slack STAFF messages are used.
## Conversation quality
The AI uses the current persisted stage, recent canonical conversation history and approved member identity. High-randomness instructions and fabricated personal biographies were removed. Replies are not chopped mid-sentence at 160 characters. Empty, overlong, repeated, unsupported or unsafe replies are held for human review. The system cannot negotiate our price, accept a deal, promise a contract or invent work already completed. A request for a person creates a durable handoff and pauses AI handling.
State transitions, recipient filtering, reservations and event processing are deterministic. Generated wording is not guaranteed to be byte-for-byte identical between model calls, even with temperature zero.
## Validation completed
- Transactional database fixtures: Florida/full-state-name normalization, Georgia exclusion, required acreage/range checks, disabled permission, canonical assignment, preview without writes, repeated-start prevention, and permission revocation. Fixtures were rolled back.
- Delivery fixtures: accepted does not advance; delivered advances exactly once; duplicate/stale receipts do not regress; failure pauses; replies stop member and legacy nurture. No provider messages were sent by these tests.
- Backend regression tests: signed-in access, cross-member denial, explicit enablement, profile validation, draft/preview/start separation, canonical notification ownership, conflicting/unassigned owners, event deduplication, opt-outs and unknown receipts.
- Worker tests: no eligible recipient, revoked permission, valid acceptance, session-ID uncertainty, timeout without retry, and database failure pause.
- Live checks: the dedicated notification endpoint rejects missing authentication, validates its contract, and queries the canonical lead store; the n8n member worker executed successfully outside the contact window with zero outcomes. Coverage also passed under the actual service-role permissions.
- App build passed. New live customer replies, real member-campaign provider acceptance/delivery, and a signed-in production-browser walkthrough remain unverified. Synthetic tests are not live inbound proof. Production frontend publication must be verified separately from source/build completion.
## Original Quick Send order
W-20260911-006 remains separate, with its original approved template and cumulative 100-recipient total limit. Its prepared audience is excluded from new member campaigns while still reserved for that order. At verification: attempted 0, accepted 0, delivered 0, failed 0, unknown 0, remaining 100. Its scheduled window begins September 12 at 3 p.m. New York / 19:00 UTC and now stops at 18:00 New York / 22:00 UTC. No billing settings or entitlement balances were changed by this implementation.
## Technical ownership and rollback
New n8n worker: `EMHNz5Xarvon0Qt3`. Existing original-order worker: `O2lA8uK94PHP6OcV`. Main inbound/manual workflow, TextMagic callback/notification retry, and the two coverage monitors were updated selectively.
The authoritative member tables are `prg_member_outreach_profiles`, `prg_member_campaigns`, `prg_member_campaign_leads`, `prg_member_campaign_attempts`, and `prg_member_outreach_audit`. They are service-role-only with RLS. Canonical ownership is written to `leads.assigned_to_user_id` and `leads.assigned_to`, both using the mapped Supabase user UUID. Base44 IDs remain the notification identity. No obsolete human_takeover fields were added.
VPS source, tests and backups: `/root/n8n-nurture-20260912`; earlier SMS repair backup: `/root/n8n-repair-20260912`. Private snapshots contain credentials and must not be shared. This guide contains no credentials.
Before reverting, pause member campaigns and deactivate the member worker. Restore targeted workflow snapshots only; preserve all attempts, receipts and audience ledgers after any real sending. Restore pre-change SQL definitions selectively from `functions-before.sql`; do not drop or reset ledgers to permit retries. The Base44 pre-feature checkpoint is `6aa4d27112b1e1327057c973`, git `f2ff0bdb08fea07cecd7480c85d096a7244bc7fe`. Prefer individual-file restoration over a full checkpoint to preserve unrelated work. Keep the separate original-order worker and its cumulative limits intact.
## Acquisition Control daily campaign controls
The existing Campaigns tab now contains approved message and Daily Send Limit controls. An administrator saves exact copy (only {area} is substituted) and a limit from 1 to 100 per Eastern calendar day. Blank or unapproved copy cannot start. A started campaign's message is immutable. The canonical Supabase control/daily/attempt ledgers retain a fixed audience, cursor, day and reserved count across pause, resume and browser reload. Reservations, including uncertain submissions, consume the daily allowance. Acceptance is not delivery. Paused uncertain submissions require provider reconciliation. Exclusions and temporary precheck holds remain visible in the persisted control record.
Keep the page open while sending; start/resume continues saved progress. No automatic acquisition schedule was added. The authenticated on-demand n8n endpoint is /webhook/prg-acquisition-dispatch, workflow g8cBBcxNhtX5vVhH. No real acquisition campaign was configured. Browser publication and a signed-in walkthrough remain unverified.
Daily-cap SQL tests and two simultaneous database calls passed: exactly one reservation and daily-count increment; the competing call held for reconciliation. No provider call was made by the concurrency fixture, and all fixture records were removed. Updated member authorization, optional-geography, normal-routing and dispatch tests passed.