{"schema_version":"2.0","record_type":"article","canonical_url":"https://marketingwiki.ai/articles/email-agent-funnel-stage-gates","id":"email-agent-funnel-stage-gates","slug":"email-agent-funnel-stage-gates","title":"Put Stage Gates Between Email Marketing Agents","description":"Separate discovery, production, audience, approval, delivery, and measurement so an email agent cannot silently cross authority boundaries.","dek":"Eight evidence-bearing gates turn a collection of capable agents into a reviewable email workflow that fails closed when context or approval is missing.","category":"AI Email Operations","topics":["email agents","Migma MCP","workflow governance","human approval","least privilege"],"publishedAt":"2026-09-03","updatedAt":"2026-09-14","lastVerifiedAt":"2026-09-14","readingMinutes":6,"author":"Marketing Wiki Research Automation","reviewer":null,"featured":false,"sources":[{"title":"Migma: AI Agents for the Email Marketing Funnel","url":"https://migma.ai/blog/ai-agents-for-email-marketing-funnel?utm_source=marketingwiki&utm_medium=referral&utm_campaign=email-agent-funnel-stage-gates"},{"title":"Migma MCP Server Documentation","url":"https://docs.migma.ai/mcp-server?utm_source=marketingwiki&utm_medium=referral&utm_campaign=email-agent-funnel-stage-gates"},{"title":"Migma MCP Security Review","url":"https://docs.migma.ai/security/mcp?utm_source=marketingwiki&utm_medium=referral&utm_campaign=email-agent-funnel-stage-gates"}],"wordCount":1037,"body":"Do not give one email agent authority over the whole funnel. Split discovery, brief creation, production, audience selection, approval, delivery, and measurement into explicit stages; let each agent advance work only when the previous stage produces a named artifact and passes a measurable gate.\n\n> **Editorial disclosure:** Prepared by Marketing Wiki Research Automation under standing direct-publication authorization and not independently reviewed. Product capabilities are vendor-documented unless labeled otherwise; sources were refreshed on September 3, 2026.\n\nMigma published a guide to email agents across the marketing funnel on September 2, 2026. The durable question behind that guide is not which agent tops a list. It is where one agent’s authority ends and the next system’s record begins.\n\nCurrent [Migma MCP documentation](https://docs.migma.ai/mcp-server?utm_source=marketingwiki&utm_medium=referral&utm_campaign=email-agent-funnel-stage-gates) spans research-informed drafting, brand facts, generation, contact import, export, campaign work, and results. Its [MCP security documentation](https://docs.migma.ai/security/mcp?utm_source=marketingwiki&utm_medium=referral&utm_campaign=email-agent-funnel-stage-gates) also shows why stage boundaries matter: `email:send` permits test and live sends, while `campaign:write` can create, schedule, and send campaigns. A conversational surface can therefore cross from reversible preparation into delivery-capable action unless the workflow constrains it.\n\n## Use this stage-gate register\n\n| Stage | Agent may produce | Authoritative input | Pass evidence | Forbidden next action |\n| --- | --- | --- | --- | --- |\n| 1. Discover | Dated lead list | Approved public sources | URLs, event dates, access time, evidence class | Writing unsupported claims |\n| 2. Brief | Audience, goal, claim checklist | Accepted leads and brand policy | Frozen brief ID and exclusions | Generating a sendable campaign |\n| 3. Produce | Draft email or series | Frozen brief and approved brand facts | Email/version ID and source mapping | Selecting live recipients |\n| 4. Validate | Rendering, link, variable, and policy report | Exact draft version | Test timestamp and unresolved warnings | Treating a warning as approval |\n| 5. Select audience | Candidate recipient set | Consent, suppression, segment rules | Rule version, unique count, exclusions | Changing copy or widening scope |\n| 6. Approve | Signed release record | Exact email, audience, sender, time | Named approver and immutable references | Silent mutation after approval |\n| 7. Deliver | One idempotent send request | Approved release record | Provider/campaign ID and accepted count | Retrying ambiguous recipients broadly |\n| 8. Measure | Evidence-bound report | Delivery and outcome events | Metric definitions, windows, missing-data notes | Rewriting history from opens alone |\n\nEach row is a contract. The “forbidden next action” prevents a capable model from collapsing two decisions into one convenient tool call.\n\n## Bind permissions to stages, not job titles\n\nAn “email agent” is too vague for access review. Create separate credentials or connections for roles such as research reader, brand-fact writer, draft producer, validator, audience operator, and sender. Start with read or draft permissions. Add delivery capability only to the component that consumes a completed release record.\n\nFor Migma, inspect the exact scopes shown during browser authorization. A connection that can generate does not automatically need `email:send`. A workflow that prepares a campaign may still not need permission to schedule it. Revoke unused OAuth-created keys from the platform’s developer settings rather than assuming disconnecting a chat window removes authority.\n\nThe [API/CLI/MCP permission matrix](/articles/ai-email-agents-api-cli-mcp-comparison) compares access surfaces. This guide adds a different control: even a correctly scoped interface must prove the stage transition before it acts.\n\n## Define the handoff envelope\n\nEvery stage should emit the same small envelope:\n\n```json\n{\n  \"workflowId\": \"launch-2026-09\",\n  \"stage\": \"validate\",\n  \"artifactId\": \"email-version-17\",\n  \"inputHash\": \"sha256:...\",\n  \"decision\": \"blocked\",\n  \"checks\": [\"links:pass\", \"outlook:fail\"],\n  \"actor\": \"preflight-agent\",\n  \"occurredAt\": \"2026-09-03T07:15:00Z\"\n}\n```\n\nThe hash or immutable version reference prevents a later edit from inheriting an earlier pass. The decision vocabulary should be small: `blocked`, `ready_for_review`, `approved`, `rejected`, `sent`, or `closed`. Do not let “done” cover all six meanings.\n\n## Fail closed when context is missing\n\nAgents often receive partial context. Define stage-specific stop rules:\n\n- Discovery stops when a change date or primary source cannot be established.\n- Production stops when the brief contains an unverified price, offer, legal term, or customer claim.\n- Validation stops when the exact final version is unavailable.\n- Audience selection stops when consent or suppression state is stale or ambiguous.\n- Delivery stops when the approval record, sender, timezone, or unique recipient count differs.\n- Measurement stops when the attribution window or denominator is unknown.\n\nA stop is a successful control outcome, not an agent failure.\n\n## Keep Migma’s role explicit\n\nMigma can be the production and review system in this register: store brand context, generate an editable email, return an email ID and canvas link, run Preflight, export a reviewed artifact, or create a campaign. It can also be the delivery system when the team intentionally grants the relevant scopes.\n\nIf Mailchimp, Klaviyo, HubSpot, or another ESP owns the runtime, the Migma stage ends at a documented draft or template handoff. The downstream platform then owns variables, current audience eligibility, sender settings, schedule, and final delivery. The [system-of-record guide](/articles/migma-vs-klaviyo-vs-mailchimp-ai-email-workflows) provides the matching ownership model.\n\nDo not infer that a list of possible agent capabilities means every capability is connected, enabled, or appropriate in one account. Plan, region, admin policy, client support, and granted scopes can change what is available.\n\n## Test the gates with adversarial fixtures\n\nRun the workflow in a non-production brand with synthetic contacts. Test at least:\n\n1. an undated source presented as urgent;\n2. a draft edited after Preflight passes;\n3. a missing personalization value;\n4. an unsubscribed address inside an otherwise valid segment;\n5. an approval for 100 recipients followed by a 140-recipient selection;\n6. a timeout after send acceptance;\n7. a conversion report with no defined window;\n8. a revoked key that the client still caches.\n\nFor each fixture, record which gate stops the run and what evidence the operator sees. A safe workflow should not depend on the model “remembering to be careful.”\n\n## Evidence limits\n\nMarketing Wiki did not connect an agent or execute Migma tools. The September 2 article establishes a dated product-led discussion of agents across funnel stages; it does not prove third-party capabilities, adoption, or comparative performance. The stage-gate register is an inferred governance design built from documented permissions and email production boundaries."}