Skip to content
All work

Case study 06 / 11

Sales and CRM

In production

AgentlyLeads: An AI-Native CRM You Run from ChatGPT and Claude

AgentlyLeads is a CRM that sales teams run directly from ChatGPT or Claude. As an AI engineer on the CS2 Technologies team, I worked on the AI connection, the AI features, the security that keeps each customer's data separate, and the path to production. Its core promise: the AI prepares the work, and a person approves anything that reaches a customer.

  1. AI

    AI prepares a draft

  2. Person

    A person reviews and approves

  3. System

    A separate step sends it

  4. Output

    Every send is recorded

Nothing is sent, deleted or charged without a person's approval.

The problem

Sales teams live in two places: their CRM and their AI assistant. The CRM holds the data and the assistant does the thinking, but they don't talk to each other. People copy and paste back and forth, and CRM vendors charge extra per seat for a chatbot added on the side. The team at CS2 also found the big, established CRMs complex to navigate for the way they actually sell.

The goal: a CRM you can run entirely from the AI tools you already use, that keeps a person in control of anything customer-facing, and doesn't charge extra for AI.

My role

I'm an AI engineer on the CS2 Technologies engineering team, and AgentlyLeads was a team effort. My work covered the AI features, the backend, the overall design, and the path from local development to production.

What we built

  • Your AI assistant becomes the CRM. Through a secure connection built on the Model Context Protocol (MCP), people can search contacts, log calls, draft emails, update deals and run pipeline reports just by asking ChatGPT or Claude in plain language.
  • The Agent Brief. AI reads a contact's full history and returns a short summary, an engagement score, a suggested next step and a draft reply. Scattered history becomes a decision in seconds.
  • Everything a sales team needs: contacts, companies, deals, tasks, quotes, contracts, support cases, campaigns with paced sending, booking links, a shared team inbox, and two-way sync with other CRMs, all behind review and approval.
  • Fair AI pricing. Customers can bring their own AI key, which is encrypted, and AI usage is metered per workspace. The AI connection is unlimited on every plan because customers use their own AI subscription.

How it works: AI prepares, people approve

Anything that reaches a customer follows the same safe path:

  1. System
    Step 1, System:

    The request is checked for a valid login before anything runs.

    Nothing else runs on an unverified request.

  2. System
    Step 2, System:

    The system confirms which company's workspace it belongs to before touching any data.

    Every read and write is scoped to one company, so one customer's data never reaches another.

  3. Agent
    Step 3, Agent:

    The AI creates a draft. Sending needs a person's approval.

    The AI can search, create records and write drafts. Sending is simply not one of its tools.

  4. Human
    Step 4, Human:

    A person reviews, edits and approves it in the app.

    Without this step, nothing can reach a customer.

  5. System
    Step 5, System:

    Only then does a separate step send it.

    Sending is its own call, and it only accepts drafts a person has approved.

  6. System
    Step 6, System:

    Unsubscribes and daily sending limits are checked at the moment of sending.

    Someone could unsubscribe after the draft was written, so this is checked at the last possible moment.

  7. Logged
    Step 7, Logged:

    Every send is recorded.

    There is always a record of what went out and when.

Example run · one outreach email

  1. Press play to watch one email go from draft to send.

Illustrative replay of the send flow. The names and values are examples, not real customer data.

Key decisions

  • Customer data kept apart by design. Every workspace is identified from the user's secure session, never from anything the browser sends, and every link between records is checked before it's saved.
  • Separate security for separate audiences: customers, platform administrators and AI assistant connections each have their own login system.
  • Protecting sender reputation. New accounts warm up gradually, and all sending pauses automatically if bounces or complaints get too high, until a person resumes it.
  • Reliable details: booking times that stay correct across time zones and daylight saving, payments that can't be double-processed, and open and click counts that aren't inflated.

From local development to production

The whole app runs on a laptop with one small database. Every proposed change is automatically tested before it's accepted, and approved changes deploy to AWS automatically: the new version is built, the database is updated safely from inside the private network, and the live service is updated to the new version. No passwords are stored in the pipeline, and the production database has no public access at all.

The results

AgentlyLeads is live in production. CS2 Technologies runs the sales pipelines for its own products on it, and outside customers use it too. Teams search, log, draft and report from ChatGPT or Claude, while every customer-facing action still passes through a person.

Under the hoodShow technical details
  • AI: an MCP server secured with OAuth 2.1 (dynamic client registration, PKCE and consent), and one interface over OpenAI and Anthropic with every response checked against a strict schema.
  • Security: workspace ID taken from the session and passed into every data function, with a shared guard that validates related records before writes.
  • Engineering: tests run in parallel on cloned databases, cutting the suite from about five minutes to under two; the private production database was seeded with a one-off task inside the network.
  • Cloud: Docker, AWS ECS Fargate, RDS, ECR, SSM for secrets, GitHub Actions with OIDC, and Sentry for error tracking.