The largest agency risk is not volume. It is using one client’s audience, sender, or API key in another client’s campaign. Each client needs separate workspace access, credentials, contacts, suppressions, and billing boundaries. Bartago can bring campaigns, devices, email senders, APIs, and automation into one operational surface, but the agency must still define roles, maker-checker approval, naming conventions, and incident ownership. Production recipients should not move through an unaudited shared spreadsheet.
Make tenant boundaries operational
A workspace is more than navigation
Keep client users, senders, lists, templates, keys, and suppressions separate. Require explicit approval for a cross-client export or import. Revoke access and keys during staff offboarding.
Use a maker-checker launch flow
Separate the builder and approver
Approve an audience sample, rendered copy, schedule, credit estimate, selected device or provider, and compliance note. A last-minute edit should invalidate approval and return the campaign for review.
- Client naming prefix
- Role matrix
- Seed recipient
- Approval record
- Emergency pause owner
Separate outcome and cost reporting
Give the client a transparent handoff
Report platform credits, SIM or carrier charges, and email-provider charges separately. Define accepted, delivered, click, and conversion, and minimize raw recipient data in exported reports.
Practical checklist
- Workspace isolation
- Least privilege
- Approval
- Seed test
- Cost breakdown
- Incident owner
Key takeaway
Agency efficiency comes from repeatable, isolated, auditable operations—not shared access.
Final thoughts
Dry-run one client campaign to test the permission matrix, approval invalidation, billing split, and emergency pause. Copy a template when useful; never share credentials or suppression data.
Verify consent, provider or carrier policy, and current applicable requirements before launching a campaign.
Start with 100 free automation credits →Common questions
Can one API key serve every client?
No. A client or workspace-scoped key reduces blast radius and audit ambiguity.
Can an agency report SMTP as delivered?
Only with an authenticated provider delivery event. Do not label generic acceptance as delivered.
Sources and editorial note
Last editorial review: August 1, 2026. Product behavior may change with releases; check current documentation.
