New piRevenue is sold to sales teams across Africa, Middle East, India & Southeast Asia. Read the manifesto →

Consent Management

Definition

Consent management is the practice of recording who agreed to be contacted, through which channels, on what basis and when, and keeping that record current and enforceable across every system that reaches a buyer.

Every sales team is sitting on a pile of contacts of uncertain origin. Some came from a webinar two years ago. Some from a purchased list. Some from a conference badge scan nobody remembers. When outreach goes out to that pile, the honest answer to "are we allowed to contact these people?" is usually a shrug. Consent management replaces the shrug with a record — who agreed to what, when, and how you can prove it — and in doing so turns a legal anxiety into an operational fact you can build outreach on.

What is consent management?

Consent management is the system of record for permission. For every person your team might contact, it tracks four things: the identity of the person, the basis on which you may contact them (explicit consent, legitimate interest, an existing customer relationship), the scope of that basis (which channels, what kind of messages), and the provenance — when it was established and from what source. It also tracks the other direction: withdrawals, objections and opt-outs, with the same precision.

Crucially, it is a living system, not an archive. Consent changes constantly. People opt in at an event and object a year later. They accept email but not calls. They change jobs and their old permissions die with the old address. Consent management keeps this shifting state current and — the hard part — enforced in every tool that can actually send a message or place a call.

Why consent management matters in sales

The defensive reason is that consent is the load-bearing wall of outreach compliance. GDPR, CASL, LGPD and their cousins all revolve around the same question: on what basis are you contacting this person? A team that cannot answer per-contact cannot demonstrate compliance at all, no matter how good its intentions. And the burden of proof sits with the sender. When a complaint or an audit arrives, "we believe they opted in" loses; a timestamped record from a named source wins.

The commercial reason is sharper than most teams expect. Consent-clean lists perform better. Contacts with a real, recent basis for contact reply more, complain less, and keep your sender reputation intact — the prospects most likely to buy are heavily concentrated among the people who actually agreed to hear from you. Meanwhile enterprise buyers increasingly probe vendors' data practices during procurement; being able to show how consent is captured and honoured is becoming a deal-stage answer, not a back-office one. A clean consent record is also a precondition for safe automation: you cannot let software send at scale on top of permissions you cannot verify.

How consent management works

In practice, a working consent layer has five jobs:

  • Capture. Every entry point — forms, event scans, inbound replies, verbal agreement on calls, imported lists — records consent details at the moment of collection: scope, source, timestamp. A list without provenance gets quarantined, not sequenced.
  • Storage against identity. Consent attaches to the right person even as their records get merged, enriched and deduplicated. This is where consent management leans on CRM hygiene: duplicate records with conflicting consent states are how violations happen by accident.
  • Per-channel, per-jurisdiction resolution. The system answers a precise question — may we email this person in Germany? may we call this number in Ontario? — using the contact's location, channel and current status, not a global yes/no flag.
  • Enforcement at send time. Sequencers, diallers and campaign tools check the consent layer before every touch. Withdrawals propagate instantly, which is where consent management hands off to unsubscribe management.
  • Evidence. Every consent event and every enforcement decision lands in audit trails, so the history is reconstructable years later.

The spreadsheet era vs the systems era

The old way stored consent in fragments: a checkbox in the marketing platform, a "do not call" note in a CRM field, a rep's memory of what a prospect said on a call. Each tool held its own partial truth and none of them agreed. The predictable failures followed: a contact who opted out of the newsletter kept getting sequenced by sales; a purchased list overwrote a suppression on import; nobody could say where half the database came from. The fragments approach fails not because people are careless but because consent is a cross-system state being managed with single-system tools.

The systems era treats consent as one shared source of truth with many enforcement points. One record per person, one current status per channel, checked by everything, updated by everything. That architecture is what makes the difference between consent as paperwork and consent as an operating fact — and it is only achievable when the bookkeeping is automated, because no rep can maintain cross-system state by hand while carrying a quota.

Consent management in practice at piRevenue

Consent bookkeeping is textbook agent work: high-stakes, high-volume, zero creativity, and catastrophic when done sloppily. In the piRevenue model, agents capture consent signals wherever they appear, attach them to the right identity, resolve what is permitted per contact and channel, and enforce the answer before any touch goes out — with every decision logged. When a buyer objects on a call, the rep says one word and the agents handle the rest: suppression, sequence halt, CRM update, audit entry. Under agent governance, consent rules are constraints agents cannot override, not suggestions they usually respect.

What stays human is everything with judgement in it: deciding the company's risk posture on legitimate interest, choosing how to rebuild a relationship after a withdrawal, weighing whether a borderline contact is worth pursuing at all. Agents keep the permission ledger perfect; people decide how to sell within it. That is the human-in-the-loop bargain applied to trust itself — and trust, ultimately, is what consent management protects.

FAQ

Do I need explicit consent before I can email a B2B prospect?

Not always — it depends on the jurisdiction and channel. Under GDPR, B2B email can often rest on legitimate interest rather than explicit consent, while regimes like Canada's CASL demand consent for most commercial messages. The practical answer: your system should record which lawful basis applies to each contact per channel, because "it depends" is exactly why the record has to exist.

What actually needs to be recorded for consent to hold up?

Four things: who consented (or which lawful basis applies), what they agreed to and through which channels, when it happened, and the source — the form, event, call or list it came from. A checkbox in the CRM saying "opted in" with no timestamp or source is an assertion, not evidence, and it will not survive a regulator's or a procurement team's questions.

What happens when a prospect changes jobs — does their consent travel with them?

Generally no. Consent attaches to the person in a context: the address they used, the role they held, what they agreed to at the time. When they move companies, the old work email dies and the basis for contacting them usually needs re-establishing. Job-change moments are great sales triggers, but they are also consent resets — treat the new role as a new relationship.

See how piRevenue puts this into practice — agents do the busywork, your reps own the deal. Take the product tour →