Okki Go Permissions, Data Sources, and Intent Data: 3 Questions I Wish I'd Asked Every Vendor

2026-09-11 · Julian Hartwell

Okki Go asks for three permission tiers: LinkedIn profile read access (URL-level, not account-level), email inbox access for reply detection via OAuth (never passwords), and a scoped CRM sync token you can revoke at any time. No browser history, no personal calendar write access, no access to anyone's DMs.

On data sources, Okki Go discloses three: public web signals, a named licensed B2B contact database, and your own team's enrichment input. There's no mystery pool, and no resold CRM contacts. That matters more than the feature list.

And intent data — the part most teams get wrong — is worth paying for when your ACV clears roughly $25K, your sales cycle runs longer than 45 days, and you already have some inbound or product signal to act on. Below those thresholds, intent scores mostly generate meetings that don't close.

That's the short version. Here's why I know, and the details.

First, the receipts — what this cost me to learn

I've been the RevOps lead at a 40-person outbound agency for six years. In that time I've personally signed off on roughly $4,200 of prospect-data subscriptions that we cancelled within the first quarter. Not because the tools were bad demos. Because I didn't ask the questions I should have asked before provisioning seats.

In March 2022, I approved a contact database for a team of five SDRs. The demo was genuinely impressive — coverage looked like 90%+ on our ICP. What I never asked: where the emails came from, and what permissions the tool triggered during LinkedIn connection. Six weeks in, LinkedIn flagged two of our SDR accounts for "automation-like behavior." Email bounce rate sat at 18.4%. The database was scraped-then-resold, and about a third of the phone numbers were more than three years old.

We didn't get banned. We did lose a full quarter of pipeline momentum, plus the credibility cost of explaining to two clients why their SDR accounts were flagged. Not ideal.

It took me two years and about seven vendor evaluations to realize that the questions protecting you from this aren't the ones sales reps want to answer on a demo call. They're the boring ones — permissions, sources, and intended use. So I built a pre-check list. We've caught nine other tools since that looked fine on a demo and failed a question below.

So — what permissions does Okki Go require?

Three tiers, and the distinction between them matters:

  • LinkedIn access. Profile read at the URL level. That means Okki Go can look at a profile you point it at, and enrich from it. It does not mean it logs in as you, scrapes your connections, or drives automated actions on your account. This is the boundary that separates compliant enrichment from account-risky automation scraping.
  • Email inbox access. Standard OAuth scopes for read (to detect replies) and send (for outreach sequences). If any vendor asks for your password instead of an OAuth flow, that's a hard stop. Okki Go revokes the token when you disconnect it.
  • CRM sync. A scoped token — meaning you pick which objects it can read and write. Salesforce and HubSpot both let you cap this at Leads or Contacts without touching Opportunities. Use that cap.

What Okki Go does not ask for: browser history, calendar write access, LinkedIn account credentials, personal social accounts, or DSAR-level sensitive attributes. If a tool asks for any of those, you've just found your answer.

The permission question you should actually ask

It's not "what do you need?" — every vendor will tell you "the minimum." It's this: "What happens on the LinkedIn side if the tool runs at scale across 40 SDR seats?" If they can't describe their rate-limiting, their account-health monitoring, and their fallback behavior in plain English, you're about to find out the hard way.

Okki Go data source transparency — what "transparent" actually means here

Every B2B contact database resells from somewhere. The difference between an honest vendor and a risky one is whether they'll name the somewhere.

Okki Go discloses three source categories:

  1. Public web signals. Company sites, press mentions, conference speaker lists, published executive bios. Standard stuff, verifiable, low legal risk.
  2. Licensed database partners. Named. If a vendor won't name their data partner, treat the emails as unverified and the phone numbers as historical fiction.
  3. Your team's own enrichment. Replies, notes, manual edits — feedback that improves match rates over time. This is the part most vendors bury because it's not sexy, but it's the only source with real signal for your actual ICP.

Here's the contrast that made it click for me: I compared our Q3 2022 stack (two vendors, both refused to name their enrichment suppliers) against Q1 2023 (one vendor that published sources and match methodology). Same ICP definitions, same SDR headcount. Bounce rate dropped from 14.1% to 4.8%. Reply rate on cold outbound moved from 2.3% to 5.1%. Same team.

What I mean is that transparent sourcing isn't just an ethics thing — it's a deliverability thing. Scraped-then-resold emails are the reason your domain reputation whispers "spam risk" every time you hit send. Verifiable sources are the reason it doesn't.

LinkedIn automation scraping — where the line actually sits

"Automation scraping" gets thrown around a lot. Here's the practical split:

  • Compliant enrichment: you provide a LinkedIn URL, the tool retrieves publicly-visible profile data, and matches it against a licensed database. No login-as-you. No automated connection requests from your account. No DM automation.
  • Risky automation: the tool logs into your LinkedIn account, drives connection requests, sends messages, or scrapes your feed and connections at machine speed. This is what actually gets accounts flagged.

The question isn't "do you use LinkedIn data." It's "whose session is making the request, and at what rate?" Okki Go's answer is that enrichment runs server-side on public URLs. Your LinkedIn session never leaves your device.

If a vendor says "LinkedIn doesn't really mind" — that's not a compliance answer. That's a hope.

What a B2B contact database should actually earn its seat on

Coverage percentages in a demo are marketing. What matters in production:

  • Email verification freshness. A 95% verified rate means nothing if the verification happened 14 months ago. Ask for verification date windows.
  • Match rate on your ICP specifically. Ask them to run a sample of 500 of your real target accounts. Not theirs.
  • Enrichment waterfall depth. A single-source database tops out around 55–65% match on hard-to-reach titles. A waterfall (multiple sources layered) can hit 75–85%. Ask how many sources feed each field.
  • Timezone and phone validity. For outbound call teams, stale mobile numbers are the silent killer. Freshness here isn't a nice-to-have.

Note that I said "waterfall." Okki Go uses one — that's one of the reasons we switched. But you should ask any vendor this question regardless.

Intent data — what it is, and when a B2B sales team should actually use it

Intent data is signal about which accounts are showing buying research — content downloads, review-site visits, hiring patterns, tech-stack changes, forum discussions. It surfaces which accounts to prioritize, not which contacts to pitch.

Where most teams go wrong: they buy intent data, point it at a dormant list, and expect meetings. Then they wonder why closed-won didn't move.

Here's the honest filter I use now, after about three years of getting this wrong before getting it right:

Use intent data when:

  • ACV is above roughly $25K. Below that, the cost of acting on the signal usually exceeds the deal size benefit.
  • Sales cycle is longer than 45 days. Short-cycle deals close too fast for intent signal to matter. Long-cycle deals need it to prioritize correctly.
  • You already have some inbound or product signal. Intent works best as a layer over existing qualification, not as a replacement for it.
  • Your SDR team has bandwidth to act within 72 hours. A hot intent signal that sits for two weeks is just a cold lead with a worse excuse.

Skip it when:

  • Your ICP isn't clearly defined. Intent on a fuzzy ICP is expensive noise.
  • You're running transactional or SMB volume plays.
  • Your reps are already at capacity on inbound. Adding intent without capacity doesn't add pipeline.

Seeing our pre-intent quarter (Q1 2023) side-by-side with our first intent quarter (Q3 2023) made this concrete: same headcount, same ICP, but SDR time shifted from 60% prospecting new logos to 35% prospecting and 25% acting on prioritized intent. Qualified meetings per rep only moved from 8 to 11. The bigger change was the quality — SQL-to-opportunity conversion went from 22% to 34%. Intent was prioritizing the right accounts, not just more accounts.

Where this advice stops applying

I'm not an attorney, so I can't speak to GDPR, CCPA, or DSAR specifics in your jurisdiction. What I can tell you from a RevOps seat: the vendors who name their data sources are also the ones who tend to have a real compliance team. That correlation has held up across every evaluation I've run since 2022.

I can also only speak to our context — mid-market B2B, US and EU buyers, ACV between $25K and $180K, SDR team of 5 to 12. If you're running enterprise direct sales or a high-volume SMB motion, the calculus is different. Intent thresholds move; permission requirements stay roughly the same.

One more boundary: the pre-check list I use is not a substitute for your own legal review. It's a first filter — one that saves you from the third demo call you'd otherwise waste on a tool that was never going to clear your security review anyway. The boring questions are the cheap ones. The expensive ones come after the seat is provisioned.