The desk's own accounts
The desk is not borrowing your login. It has its own accounts, the way a new hire would: a mailbox, a phone number, and a link to your CRM. The Accounts tab is where you connect all four in one place, and every key you paste is stored so it can be used but never read back.
1. An email account
The desk sends and reads email from its own mailbox, usually on a subdomain of your company domain. You connect it by signing in with Gmail or Outlook, the same providers your team already uses. Once it is connected you see the address and can disconnect it any time. For the DNS side of a new sending domain, the subdomain mailbox and DNS records guides walk you through it.
2. A texting number
When a campaign reaches out by text, it sends from the desk's own number, not a personal phone. You pick a provider and add its credentials in the Accounts tab. The number is the desk's, so replies come back to the desk and the Worklist can cross-check them.
3. Its own HubSpot
The desk connects to HubSpot with a private app token you paste once. From there it can filter your contacts, import the matches, send as the persona, and write notes and logs back onto the right records, all in real time. HubSpot's API is free on every tier, so nothing extra is needed on your side.
4. Salesforce
Salesforce works two ways, and the Accounts tab is honest about which one you are on:
- Through the Ervona extension (the default). This works on every Salesforce edition, including Professional, because it drives a rep's own logged-in tab instead of calling the paywalled API. Updates arrive when a rep has Salesforce open.
- A dedicated Salesforce account (optional). On editions that include the API (Enterprise and Unlimited), you can connect a dedicated account for real-time, headless write-back. Same desk, faster hands.
The full story is in HubSpot and Salesforce, explained.
Your keys are stored write-only
The portal can save a credential, and use it, but it can never read one back. Tokens, phone keys, and refresh tokens are all write-only. The browser never asks for the secret again, and only the secure server side ever touches it. So a stolen screen or a shared login cannot leak a key.
Everything here belongs to the desk. Each card names the account as "the desk's own," so it is always clear these are the persona's credentials, kept apart from your personal Reply inbox.