Shaduf.Research preview
Open-Source Marketing Agents & Harnesses/Cross-layer handoff and approval boundaries

Documentation synthesis · 28 Sep 2026

Where a marketing draft becomes an authorized action.

Keep the draft, human decision, flow run and sender record separate. No reviewed source shows a shared approval or consent chain across Marketing Agent OS, Activepieces CE and Mautic. The combined path below is a paper architecture, not a recommendation or a tested integration.

Choose the smallest sufficient layer

JobPossible starting pointStill owned by you
One content draftManual, versioned document. No product needed.Review record, backup and deletion.
Reusable instructions in a controlled hostSelected Marketing Agent OS skills.Host permissions, connector scopes, versioned output and reviewer. A skill is not an approval engine or sender.
Repeatable local transform and run detailActivepieces CE, with a technical operator.Infrastructure, keys, retry effects, monitoring and recovery. CE is not a consent ledger.
Contact/campaign operationsMautic Community, only if broader campaign state is needed.Consent provenance, transport, cron/queue, provider outcome, backup and restore.

A simple newsletter or welcome sequence does not automatically justify Mautic. That is a scope inference, not a review of Listmonk or Keila; neither is in the vetted shortlist.

Handoff and responsibility

Four-step proposed handoff: organization-owned versioned draft; separate named human decision with exact draft hash and expiry; optional Activepieces CE execution; sender or CRM owner with production credentials and current consent checks. Dashed connectors mark unverified integration.
Solid draft-to-decision path is a proposed organization process. Dashed product handoffs have not been built or verified.
BoundaryRecord and ownerStop condition
Brief → draftOrganization-controlled file/repository holds brief version, output and diff. Author controls local edits; host operator limits tools and network.No production credential or live connector in the drafting host.
Draft → decisionNamed content owner records accept/reject, exact payload hash, channel/target scope, timestamp and expiry in a separate controlled record.Missing, stale or mismatched decision means no action. This is a human process unless separately enforced.
Decision → possible external actionSender/CRM operator owns production credential and rechecks present consent/suppression, target rights, payload and action ID. The sending system records request and provider outcome.No assumed native transfer of approval, consent or idempotency from draft or CE log.
Outcome → recoveryIncident operator reconciles target-side IDs before retry; backup/data owners manage restore, retention and deletion.An unknown provider outcome is not a safe resend.

What the product evidence does—and does not—show

  • Marketing Agent OS: the audited selected-skill projection is an instruction library inside a separate host. Its Apache-2.0 wrapper declaration does not cover every retained upstream asset; host enforcement, installer effects and exact derivations were not tested. Architecture · Security · dossier.
  • Activepieces CE: the 0.92.0 anchor is a release record, while relevant docs are unversioned and main-branch licenses were not tag-compared. Flow Approvals are Enterprise/Cloud with plan limits; RBAC and audit logs are marked paid. CE does not establish enforced two-person approval. An interrupted step may run again. Its current Limits page says 30-day default self-host run-data retention and 50 MB log cap, while Truncated Logs says 25 MB. Deployed retention is unverified. Compose requires preserving AP_ENCRYPTION_KEY with the database; recovery docs also discuss S3 and Redis-loss windows.
  • Mautic Community: 7.2.1 tagged metadata declares GPL-3.0 for that package, not every plugin or provider. Cron and queue processing must be operated. Roles, DNC/preferences and reports do not prove lawful consent, dual approval, provider delivery or tested restore. Dossier.

A combined route is a contract to design, not a recommendation

A hypothetical route could pass an approved payload from an organization record to CE and later to a separately operated Mautic or sender. No audit verified its API mapping, approval transfer, consent check or recovery. Before building it, name owners and specify brief_id, draft_hash, approval_id, target/recipient source, consent snapshot, payload_hash, action_id, target request ID and outcome. Reject expired approvals, changed payloads, stale suppression and duplicate IDs. Prove what happens if the CE worker stops, Mautic cron stops, the provider accepts but a local write fails, or logs expire. Without that implementation and evidence, do not connect the layers.

A run log shows only what that platform recorded. A human review shows who approved a recorded artifact. Neither proves target-side idempotency, rollback, recipient consent, current suppression or provider delivery. CE retry model · Mautic reports.

Minimum safe next step

  1. Use only a fictional brief and a versioned three-item calendar draft. A named content owner records a decision against the exact version.
  2. If evaluating a skill, inspect its commit/notices and host permissions in a disposable project. If evaluating CE, propose a private manual-triggered local transform without Connections or external nodes. If evaluating Mautic, propose a non-public fictional form/contact without live transport or cron. None of those evaluations occurred in this research.
  3. Keep the combined route on paper. Have the content approver, consent owner, sender/CRM operator and incident/backup owner review its failure contract.
  4. Teardown scratch files, local data, disposable credentials and stores; record remaining backup copies. No real contacts, production credentials, public webhook, outbound send/post, CRM mutation, paid media or unattended schedule.

Before any real action, verify the exact release/edition/component license and scope, current consent and suppression, target permissions, sender identity, target-side dedupe and outcome evidence, monitored workers/cron, on-call owner, retention, deletion and tested restore. This list is an evidence requirement, not a claim that any candidate meets it.

Open question

Which operated system owns the authoritative approval record and can reject a changed payload, target or consent state? The checked sources do not answer it. Stay with a human-reviewed internal draft until an action boundary is separately designed and tested.

Research library · Safe first test · Evidence and limits

Search published pools, pages, reports, and evidence.