Safety rules

Medical3 has built-in rules that protect buyers, recipients and clients. This page lists them, shows which actions cannot be undone, and explains what clients can and cannot see.

Do-not-contact buyers#

A buyer can be flagged Do not contact in the Buyer asset library. The flag saves at once and is internal only: clients never see it.

A flagged buyer cannot be added to a new opportunity and cannot be introduced to a client. The Introduce buyer action is disabled for them. See Pipeline.

Opt-outs from replies#

Campaign emails carry no unsubscribe link. Recipients opt out by replying and asking to be removed.

  • Medical3 reads replies in the connected workspace mailbox about every 5 minutes.
  • A reply that asks to unsubscribe is recognised in English, French, German, Spanish, Chinese and Japanese.
  • The contact is then marked Opted out — excluded from campaigns automatically.
  • Contacts marked Opted out — excluded from campaigns or Bounced — excluded from campaigns are left out of new campaigns, and they are skipped again at send time.

An opt-out is permanent: Medical3 never emails that address again. The opted-out contact's email address is locked, and restoring an archived contact does not clear an opt-out. For questions about a specific contact, ask your Medical3 administrator.

A reply-based opt-out applies to that workspace contact and stops it in every campaign, including active ones. Do not contact is a separate per-buyer flag in the pipeline and does not affect campaign contacts.

Note: Replies to a different address than the connected mailbox are not detected automatically. Keep conversations in the connected mailbox.

Campaign safeguards#

Several checks stand between a draft and an email going out:

  • A saved draft never sends anything.
  • Launch campaign stays disabled until the message preview has loaded, and then asks you to confirm the sender and recipient count.
  • Send test to sender mailbox emails only the sender's own mailbox, never a recipient.
  • Each campaign has a daily maximum, from 1 to 500, so sending is spread over time.
  • Whether a contact is eligible is checked again when each email is about to go.
  • Pause campaign and Cancel campaign stop messages that have not been sent.

Important: A message already being sent cannot be recalled. Pausing or cancelling stops the rest, not the ones already gone.

Actions that cannot be undone#

These actions take effect at once and cannot be reversed from the console.

ActionWhereEffect
Introduce buyerOpportunity drawerRecords the introduction; the client sees the identity once disclosure is enabled.
PublishClient's Weekly tabThe client sees that week's briefing immediately.
IssueClient's Money tabThe amount and invoice number are fixed, and the client sees the invoice.
VoidClient's Money tabThe invoice is voided and disappears from the client's invoice history.
Cancel campaignCampaign pageUnsent messages are never sent.
Send a new setup link and Send password reset linkAdmin UsersThe person is signed out everywhere, their current password stops working and earlier links are cancelled.

Confirmations#

Medical3 asks you to confirm before anything risky happens. Stage changes in the opportunity drawer, Introduce buyer and Weekly Publish use a two-click arm: the first click turns the button into a confirmation, and the second click performs the action. Only dragging a card on the board (Confirm stage advance) and campaign launch or cancel open a confirmation box.

People, access and invoice changes also need two clicks. In the Admin section the first click arms the button, which turns amber and shows what will happen. The second click performs it. Esc or a click elsewhere disarms it. On invoices, Trigger, Issue and Void arm the same way, but Void turns red and Esc does not disarm invoice buttons. Read the sentence before you confirm; see Admin.

Internal-only and client-visible evidence#

Each piece of evidence on an opportunity has a visibility:

VisibilityWho sees it
Internal onlyStaff only.
Visible to clientStaff and that client.

Default to Internal only. Choose Visible to client only when you are happy for the client to read the label and see the date. The Do not contact flag is always internal.

Customer masking#

Buyer names stay hidden from clients until the buyer is introduced. While disclosure is restricted for a client's engagement, names stay hidden even after an introduction; the introduction is recorded and takes effect when disclosure opens. Until then, their dashboard shows Unlocks after introduction. The View customer view preview applies the same masking, so you can check exactly what a client sees before you publish or introduce anything. Buyer tags are an exception: they are written for clients and are visible to them.