Financial Operations

Lead Capture & Routing

Signed first-party and provider gateways, native ad-form and dedicated inbound email ingestion, safe end-to-end tests, and exact routing into one real-time inbox.

01

Six ways in, one inbox

Google Ads native webhooks (per-client URL + key, paste into the lead form's webhook integration). Meta lead form CRM integration (live verify endpoint; after Meta approves leads_retrieval, each account must reconnect for the expanded scope before ingestion is verified). Dedicated inbound email securely captures each client's CRM conversation for marketplaces and websites, with deterministic ADF/provider parsing and optional privacy-approved structured AI fallback. The CRM inbox address is shown once when created or rotated, then cannot be retrieved later. A generic webhook endpoint for Zapier, Make, n8n, partner CRMs, embedded forms, and mobile apps. CSV import for Meta Lead Center exports with column auto-mapping. Manual entry for walk-ins and phone calls. Every source enters the same canonical routing and CRM pipeline; inbound email does not reply to customers.

02

A universal signed gateway — CRM optional

Websites and form providers can send a versioned lead.submitted.v1 receipt directly to XeroFlow using replay-protected HMAC signatures and copy-once rotating secrets. XeroFlow stores and routes confirmed leads in capture-only mode, so an external CRM is an optional downstream destination rather than a prerequisite.

03

Contained end-to-end testing

Start a 15-minute, origin-bound test from the setup guide and follow append-only evidence from tracker load through browser correlation to the trusted receipt. Synthetic leads are hidden from default reporting and cannot notify staff, route to live destinations, promote into CRM, or publish normal conversion events.

04

Exact enquiry-to-conversion mapping

Stock, finance, test-drive, contact, and model/variant enquiries can map to separate provider conversion actions. Typed destinations use exact matching; an unknown type pauses for configuration instead of sending one enquiry to every action.

05

Real-time, not polled

Native webhooks deliver leads within seconds, not Zapier's 1-15 minute polling window. Speed-to-lead matters — contacting a lead within 5 minutes is 21x more likely to convert. Each ingestion path enqueues routing immediately, and the SSE stream pushes new rows to any open inbox tab without a refresh.

06

Multi-tenant by design

One agency dashboard manages every client's lead routing. Each client gets their own webhook URL + secret key, their own form rules, and their own portal view — no Zap duplication, no per-task fees, no separate logins to maintain.

07

Automotive leads delivered to AutoGate

Add AutoGate as an outgoing destination on an individual form rule—not as a blanket client-wide push. Configure the dealer seller identifier and lead context in XeroFlow, then filter delivery by campaign ID or name, ad ID or name, Facebook Page, vehicle make, model, retailer item ID, or stock number. Prospect, campaign, stock, and vehicle fields are mapped with a stable unique identifier across retries to prevent duplicates; shared AutoGate credentials remain protected in Cloudflare.

08

Client portal inbox built-in

Add a "portal" destination to any rule and the client sees their leads inside the same XeroFlow portal where they already track invoices and projects. Branded, real-time, no extra login — and the client's "Mark contacted" actions sync back to the agency side automatically.

09

Routing logic that's actually useful

Per-destination filters: "AutoGate only for the EV campaign", "AutoGate only when make is Hyundai", "SMS only if budget > $5,000", or "Slack only if utm_source = facebook". Optional delays run from immediate to 24 hours. HMAC-signed outbound webhooks and stable AutoGate identifiers let receivers safely dedupe retries.

10

Senses test data and treats it differently

Google's test data and XeroFlow signed test runs are stored as synthetic evidence but excluded from normal side effects. Toggle "Show test leads" when an authorised operator needs to inspect one; staff notifications, routing, CRM promotion, and conversion fan-out remain suppressed.

11

Marketer-friendly setup

In-product setup guide with platform-specific instructions, a destination-config wizard with one-click presets ("Slack: Lead alert", "Email: Sales notification"), a side panel that lists the actual fields each form has sent so template tokens can be copied without typing them, and a form picker that lists Google Ads lead forms across all connected accounts directly from the API.

Ready to see it in action?

Get Started