One inbox for Google Ads, Meta, Zapier/Make/n8n, CSV imports, and manual entry. Dedicated inbound email securely captures each client's CRM conversation, with the address shown only once at creation or rotation.
Google Ads native webhooks (per-client URL + key, paste into the lead form's webhook integration). Meta lead form CRM integration (live verify endpoint; after Meta approves leads_retrieval, each account must reconnect for the expanded scope before ingestion is verified). Dedicated inbound email securely captures each client's CRM conversation for marketplaces and websites, with deterministic ADF/provider parsing and optional privacy-approved structured AI fallback. The CRM inbox address is shown once when created or rotated, then cannot be retrieved later. A generic webhook endpoint for Zapier, Make, n8n, partner CRMs, embedded forms, and mobile apps. CSV import for Meta Lead Center exports with column auto-mapping. Manual entry for walk-ins and phone calls. Every source enters the same canonical routing and CRM pipeline; inbound email does not reply to customers.
Native webhooks deliver leads within seconds, not Zapier's 1-15 minute polling window. Speed-to-lead matters — contacting a lead within 5 minutes is 21x more likely to convert. Each ingestion path enqueues routing immediately, and the SSE stream pushes new rows to any open inbox tab without a refresh.
One agency dashboard manages every client's lead routing. Each client gets their own webhook URL + secret key, their own form rules, and their own portal view — no Zap duplication, no per-task fees, no separate logins to maintain.
Add a "portal" destination to any rule and the client sees their leads inside the same XeroFlow portal where they already track invoices and projects. Branded, real-time, no extra login — and the client's "Mark contacted" actions sync back to the agency side automatically.
Per-destination filters: "SMS only if budget > $5,000", "Slack only if utm_source = facebook", "Email everyone but skip spam". Optional delays from immediate to 24 hours — common pattern: Slack ping immediately, email the team if no one's claimed in 30 minutes. HMAC-signed outbound webhooks with idempotency keys so receivers can safely dedupe our retries.
Google's "Send test data" button (`is_test=true` flag) flows through ingestion but the lead is hidden from the default inbox view — toggle "Show test leads" to see them. No more weeding through synthetic submissions during setup, and no accidental Slack notifications when QA pokes a form.
In-product setup guide with platform-specific instructions, a destination-config wizard with one-click presets ("Slack: Lead alert", "Email: Sales notification"), a side panel that lists the actual fields each form has sent so template tokens can be copied without typing them, and a form picker that lists Google Ads lead forms across all connected accounts directly from the API.