AI NativeMarketing Operations Engineer

Point your own AI agent at the marketing stack

One MCP server exposing campaigns, CRM, content, ads, influencers, SEO, events and analytics as typed tools

Point your own AI agent at the marketing stack

The most useful automation a marketing team writes is rarely a workflow node. It is "pull every campaign that ended last month, summarise the channel mix, and open a doc" — the kind of thing that wants a general agent with real access, not a fixed integration.

HeadshotMarketing exposes exactly that. Its MCP server is a thin shell over the shared platform library: it authenticates with the same OIDC client the product uses, points at the production workspace and global gateways, and mounts a marketing domain module alongside the platform modules for auth, files, tags, notifications, workspaces, organizations, billing, integrations, scheduler, support, and store. The marketing module covers the whole surface the app covers — campaigns and templates, contacts, leads, deals and pipelines, content items and assets, the AI tool registry and its executions, social accounts and posts, paid ad campaigns, creatives and audiences, influencers and their campaigns and relationships, events, SEO keywords and audits, landing pages, automation workflows, and analytics — as roughly 172 individually described tools grouped per entity.

Two prompts ship with it as worked recipes — launching a campaign end to end, and running the sales pipeline — plus read-only resources for the schema, the dashboard, campaigns, and SEO, so an agent can orient itself before it starts calling tools. Because everything routes through the workspace gateway, the agent inherits the caller's role: there is no second authorization path, and a tool cannot see or change anything its user could not.

That is also where the honest caveat lives. Twenty-six of those tools are delete-class, and today none of them require an explicit confirmation argument — an agent that misreads an instruction can delete a campaign, a contact, or a content item in one call. That is a governance gap in the agent surface, not a feature, and gating destructive operations behind a confirmation token is committed platform work. Until it lands, the MCP server is best pointed at read and create paths, with delete reserved for humans in the UI.

This is an illustrative pre-launch scenario, not a customer story.

Ready to make this your story?