Table of Contents
See how Weflow captures every email, meeting, and contact inside your corporate boundary and syncs it to Salesforce.
Book a demo
Or use our free web app.

What Weflow Cannot Capture, and Why That Is the Right Boundary

See exactly what Weflow captures from email, calendar, and meetings, and how it writes it back to Salesforce.
See it live

Automatic activity capture stops at the edge of your corporate infrastructure. The mail tenant, the calendar, video meetings: all capturable. A rep's personal phone, WhatsApp threads, iMessage, personal email: not capturable, by us or by anyone else selling you capture this quarter.

You already know your CRM data is incomplete. You're not here to be told that. You're here to find out exactly where the next tool will still leave holes, before you sign, because a blind spot you can name is one you can design a channel policy and a rollout around, and a silent one quietly poisons every number downstream.

So here's the map. Weflow is the Revenue AI Orchestration platform for sales, customer success, and RevOps teams, and Activity & Contact Capture is the product doing the capturing. This page covers what it structurally cannot reach, what it deliberately refuses to log, how it reports its own gaps, and the one certification we don't hold.

Where automatic activity capture stops: the corporate infrastructure boundary

Automatic activity capture covers exactly the channels the company controls, and nothing outside them. That line is the capture boundary.

In practice the controlled channels are the corporate mail tenant, the corporate calendar, and video meeting platforms. Weflow Activity & Contact Capture runs server side at the mail tenant level through a central app in Microsoft Entra or Google Workspace, so every email and meeting is logged regardless of which client or device the rep used. No plugin to install, no rep action.

Everything a rep does on a device the company doesn't administer sits outside that line permanently.

Inside the boundary (captured)Outside the boundary (not captured)
Corporate email in Microsoft 365 or Google Workspace, inbound and outboundPersonal email accounts a rep uses on the side
Corporate calendar eventsSMS and iMessage threads with a buyer
Zoom, Microsoft Teams and Google Meet meetings, when the notetaker is admittedWhatsApp and other consumer messaging apps
In-person meetings recorded with Mobile CopilotPhone calls placed from a mobile handset, personal or company-issued
Telephony for Outreach and other dialersMicrosoft Teams chat and LinkedIn messages

Why no capture vendor can honestly claim to capture everything

The boundary is set by consent and device ownership, not by engineering effort. A rep's personal phone is a private space that also carries their private life, so reading it isn't a feature waiting to be built. It's a thing you cannot ask for.

Every capture vendor lives with that exact limit. Most say nothing about it, which is why experienced RevOps leaders have learned to interrogate it themselves and treat "capture everything" as a claim that will turn out to have an asterisk they had to find on their own.

Saying it out loud does cost something. A prospect told us during a rollout:

I found that the transparency part of how much Weflow captures on their email was concerning a few people a little bit.

We'd still rather have that conversation before go-live than have someone discover the shape of it afterwards. Partial capture presented as complete is more dangerous than a gap you documented, because reports built on it look confident and are wrong in exactly the places that matter.

What no capture tool reaches: WhatsApp, iMessage, SMS, personal email

The channels where the strongest deal signal now lives are the ones no capture layer can see. Weflow included.

  • SMS and iMessage: the thread runs on a handset, so there is no corporate system between the two people to read it. Weflow does not capture text messages and it is not on our roadmap.
  • WhatsApp and similar apps: same problem, plus a regional split that makes it worse. WhatsApp dominates buyer conversation in Europe, iMessage in the US, so wherever you sell, some part of your pipeline is running through it.
  • Personal email: outside the mail tenant, outside the admin grant, outside consent.
  • Calls from a mobile handset: the call never touches a system the company administers. Weflow has no VoIP call capture today either; Zoom Phone is on the roadmap and not available yet.
  • LinkedIn messages and Microsoft Teams chat: Weflow records Teams meetings like any other video platform, but Teams chat is not a surface it reads.

The painful part is that getting onto a buyer's phone is itself the signal. A manager inspecting pipeline sees a contact who has gone quiet for two weeks, challenges the rep, and hears that it's all fine, it's all on my phone. Every stale-deal alert and engagement score on your best deals is then quietly wrong.

The thing I haven't been able to sort out is the text messaging or iMessage. In a lot of businesses that I've been a part of, one of the best indicators of success is if you're on a text message basis with your buyer, especially in enterprise, I think that becomes really important. But I don't think that you can easily integrate that or measure it. It's like the one remaining black box that you just have to have some janky checkbox like, are you texting with them? Yes or no?
Mallory Lee, VP Revenue Operations, PhoneBurner

The janky checkbox is still the honest answer. If your enterprise deals genuinely live in messaging, treat that as a manual field your managers ask about in review, and don't expect any vendor to close it for you.

What Weflow will not log: the Salesforce record-match rule

Weflow logs nothing that doesn't resolve to an existing Salesforce contact, lead, or account domain. That's the default, and it does most of the privacy work before any rule is written.

Which answers the fear behind the question everyone actually asks: no, a rep's dentist, their mortgage broker, and their weekend group thread were never candidates for the CRM. There is no record for them to attach to, so nothing is created.

That reframes what an exclusion list is for. You need exclusions for correspondence that does match a Salesforce record and must still stay out: the law firm, the board member, the consumer segment sitting inside a B2B instance.

How Weflow keeps confidential and personal email out of Salesforce

This is the part reps raise first, and they raise it in specifics:

Exclusion in Weflow runs in three layers: rules an admin sets centrally, controls in the rep's hands, and scope decided before a single mailbox is read. All three are configuration you can show a security reviewer, not a promise from a datasheet.

Layered exclusions: domains, objects, keywords, and conditional rules

The reasons for excluding differ, so the layers do too.

LayerWhat it blocksWhen you need it
Internal and external domain exclusionAll mail and events involving a listed domain or addressYour law firm, your auditor, your own internal traffic, resource calendars
Salesforce object exclusionLogging to an entire object, for example Lead or CaseTeams that never work leads, or an object you don't want an activity trail on
Keyword exclusionAny email whose body contains a listed termConfidential subject matter your team can flag by wording
Conditional custom rulesActivity evaluated against fields on the Salesforce recordA consumer segment in a mixed B2C and B2B instance, or a named account that must never be logged

One trap worth knowing before you build your list. Domain exclusion blocks records that don't already exist in Salesforce. A board member who is already sitting there as a contact will keep being logged no matter how many times you add their domain, and the control you actually need is a custom rule evaluated against the record.

Admins get caught by this because the two controls look interchangeable in the UI. They aren't.

Weflow Activity Capture setup modal on the Exclude Addresses step with internal and external domain exclusion fields.

Three capture modes and per-thread suppression for reps

Capture runs in one of three modes, set per team. Most customers run hybrid.

ModeWhat happensWho it fits
Fully automatedServer-side capture with no rep-facing layer at allIndividual contributors, high volume, no appetite for a plugin
HybridServer-side capture plus the mail add-in, which shows what is about to be logged and whereMost teams, and anyone who needs a rep to re-map or suppress
Fully manualNothing is logged unless a person chooses to log itLeadership, whose mail is the most sensitive and the least useful to capture wholesale

In hybrid, the rep sees the Salesforce record a message is about to land on, can change it, and can tick a control that switches logging off for that thread. You can also hand out the add-in with that control removed, so a team sees the mapping and cannot suppress it.

Now the honest limit. Nothing in Weflow detects that a message is sensitive. The rep-side control only works where the rep notices in the moment, which means a customer or a contact who must never be captured is an admin exclusion, not a judgement call you delegate to a seller having a bad Tuesday.

Scoping capture to a security group before anyone is enrolled

No mailbox is read until a user is enrolled in a capture configuration. Installing the managed package, connecting the integration user, and adding the workspace app all grant access without capturing anything.

That matters for two reasons: your scope is a configuration you set before go-live, and the technical setup can finish while legal review is still open. Admins are right to assume the default install is greedier than they want:

The controls you have before anyone is switched on:

  • Enrolment: capture reads a mailbox only once that user is enrolled, so an unenrolled inbox is untouched rather than filtered later.
  • Group scoping: connect a nominated security group instead of the whole tenant, so the mailboxes in scope are the ones you named.
  • Read-only mode: a single switch under Salesforce Permissions blocks every record creation and field update flowing from Weflow into Salesforce, while capture and conversation intelligence keep running.

Weflow Salesforce Permissions settings showing record creation, read-only mode and per-object editable field controls

How Weflow reports coverage gaps instead of hiding them

Inside the boundary, capture still misses things, and Weflow reports those misses as an operational metric instead of letting a setup look complete while being quietly wrong. That reporting is the part we'd argue matters more than any coverage percentage in a deck.

Start with the honest numbers. Recording coverage typically runs between 60 and 80 percent of eligible meetings, and measured across all of a customer's meetings the recording ratio usually lands between 50 and 70 percent. Some of that apparent gap was never a real meeting: calendar systems attach a video link to every event, including internal and in-person ones nobody intended to record.

What the reporting names:

  • Per-meeting skip reasons. Someone opted out, or the notetaker wasn't admitted, or another recorded reason. These are attributed separately, so a lobby problem doesn't get read as a product failure.
  • Opt-outs as a legitimate outcome. A rep or a customer declining to be recorded is a logged, respected reason, not an anomaly to chase down.
  • The lobby case. The notetaker joins as a participant and has to be admitted, so a meeting the customer booked and never joined cannot be recorded by anyone. It leaves the lobby after about ten minutes, and a rep can send it back in mid-call from the Weflow calendar.
  • Silent users. A user whose sending address doesn't match the address on their CRM user record falls out of capture with no error at all. Common after an acquisition, or where someone sends from a marketing subdomain. A health view names the users producing nothing so you find them without going person by person.
  • Data quality blocking matches. Contacts with no email, accounts with no domain, duplicates: the things that quietly stop activity resolving to a record.

The same health view flags whether Einstein Activity Capture is still running, which matters because two capture layers writing the same emails and meetings produce duplicate and conflicting activity. Replacing Einstein Activity Capture is a cutover with a date, not a parallel trial.

Weflow Analytics Activity Capture Health tab listing data quality issues and Salesforce settings checks including Einstein Activity Capture

Which certifications Weflow holds, and where FedRAMP stands

Here is the list you can paste into the vendor review, with nothing implied that isn't held.

Certification or controlStatus
SOC 2 Type IICertified, held since 2021
GDPRCompliant. German company, Frankfurt infrastructure for European customers
HIPAACompliant. BAA available, US storage option
CCPACompliant
Zero Data Retention for AI processingIn place. Customer data is never used to train models
EncryptionTLS 1.2 or above in transit, AES-256 at rest
Penetration testingRegular third-party tests
Data residencySelectable EU, US or APAC region, following the customer's Salesforce region by default
ISO 27001Not held. In progress, target December 2026
FedRAMPNot certified

On residency, Weflow spins up your instance in the region where your Salesforce org sits, which means you're answering the question with a location your own security team already approved. It can be overridden to keep data in the EU or UK. Video recordings are the exception: Weflow holds those and streams them back, because Salesforce is a poor place to store large files.

One more detail that shortens reviews: the only way to sign in to Weflow is through your Salesforce authentication, so there's no second identity to provision, no separate password, and deactivating a user in Salesforce removes their Weflow access immediately.

What the capture boundary means for your rollout

A named boundary is actionable. It becomes a channel policy and a fit decision, which is exactly what an unnamed one can never be.

Design a channel policy before switching capture on

  • Decide which channels deal communication is supposed to run through, and say it out loud to the team. Capture ends at corporate infrastructure, so a team allowed to work customers from personal channels will carry holes no tool can close.
  • Make the texting blind spot an explicit field your managers inspect, rather than letting "it's all on my phone" function as an answer in a deal review.
  • Set the mode per team before enrolment: leadership on fully manual, individual contributors on automated or hybrid.
  • Write the exclusions first, including the custom rules for contacts that already exist in Salesforce, then enrol.
  • Scope the connection to a security group and confirm which mailboxes are in it before anyone is switched on.
  • Plan the Einstein Activity Capture cutover as a date with an owner, since you can't run both against the same org, and run your parity check on the boring part: did it capture one for one.

When Weflow is not the right fit

If the real work of your deals happens in WhatsApp or over text, Weflow does not solve that and neither does anything else on your shortlist. Buy capture for the channels you control, and handle the messaging channel with process.

If FedRAMP is a hard requirement, Weflow is not a fit today. We hold SOC 2 Type II, GDPR, HIPAA and CCPA, and that is not a substitute for a certification a US government contractor is mandated to have.

And Weflow works exclusively with Salesforce. If your CRM is HubSpot or Dynamics, stop here.

FAQ: Weflow capture limits, privacy, and compliance

Does Weflow capture inbound emails or only outbound?

Both. Weflow captures server side at the mail tenant level through Microsoft Entra or Google Workspace, so inbound replies are logged the same as outbound sends, regardless of the client or device the rep used. This is worth checking with every vendor on your list, because add-in-based capture only sees mail that passes through the add-in, and that usually means outgoing only. The reply is the half of the record that proves a deal is alive.

Can an activity already logged to Salesforce be corrected?

Yes. An activity mapped to the wrong record can be unlinked and re-logged to the right one. Weflow maps to open opportunities in a fixed order, preferring a contact over a lead and a single open opportunity where the person holds a contact role, and falling back to the account when nothing resolves cleanly. The rep-facing add-in exists so the mapping gets fixed at the moment of capture rather than in a cleanup project later.

Does Weflow capture Slack messages or Microsoft Teams chat?

Microsoft Teams chat is not captured. Teams meetings are recorded and analyzed like Zoom or Google Meet. For Slack, Weflow reads only channels somebody has deliberately connected to a specific Salesforce record, by a command in Slack or from Weflow. Unconnected channels are not read at all, which is the same governance rule email capture follows: data enters only where it resolves to a record.

Is Weflow FedRAMP certified?

No. Weflow is not FedRAMP certified. Weflow holds SOC 2 Type II, and is GDPR, HIPAA and CCPA compliant, with Zero Data Retention for AI processing and ISO 27001 targeted for December 2026. If your organization requires FedRAMP, Weflow is not a fit.

Do I need the full Weflow platform for activity capture?

No. Weflow Activity & Contact Capture is sold standalone at $19 per user per month, billed annually, with a 10-user minimum. Pricing is published, not gated behind a call.

One thing to watch: call recording lives in Weflow Conversation Intelligence ($39 per user per month), not in Activity & Contact Capture. If you want emails, meetings, contacts and meeting recordings, the Revenue AI Foundation bundle pairs both products at $49 per user per month.

Walk through the product yourself, no call required. The exclusion layers, the capture modes, and the coverage health view described here are all things you can inspect rather than take our word for.

By
Weflow

Weflow is a modular Revenue AI platform for RevOps leaders and revenue teams, powering pipeline, forecasting, and deal inspection for 200+ B2B companies. The team behind Weflow also hosts the RevOps Lab podcast and runs RevOps Chat, the Slack community for 1,000+ RevOps practitioners.

More articles by
Weflow

Related articles

What Talk Ratio and Question Rate Actually Tell You (and What They Don't)

Learn what talk ratio and question rate show, miss, and when to use AI coaching scorecards.

What Weflow Cannot Capture, and Why That Is the Right Boundary

Learn what Weflow cannot capture, from personal phones to email, and why that privacy boundary matters

Why 100% Conversation Recording Coverage is The Wrong Target For Conversation Intelligence Tools

Learn the real recording coverage benchmark for Conversation Intelligence and why 100% is the wrong target

MEDDIC auto-fill: let AI write the scorecard from the call

Learn how AI auto-fills MEDDIC scorecards from call transcripts, with rep review before Salesforce updates.

Gong AI Data Extractor vs Weflow AI Field Updates: Overwrite Rules, Caps, and Custom Objects

Learn how Gong AI Data Extractor vs Weflow handle overwrite rules, caps, and Salesforce custom objects

What Gong and Clari Recording Exclusion Lists Actually Stop (and What They Don't)

Learn what Gong and Clari recording exclusion lists block, what bypasses them, and how to test.

How Weflow Tags Meeting Types Automatically, and What That Lets You Trigger

Learn how Weflow auto-tags meeting types to trigger scorecards, summaries, and Salesforce updates

How to Build a Call Library for Onboarding Without Anyone Curating It

Learn how to build an onboarding call library that updates itself from Conversation Intelligence.

How Weflow Login and Access Control Work When There Is No Weflow Password

Learn how Weflow login, access control, and provisioning work through Salesforce without a Weflow password.

Why Weflow Doesn't Do AI Role-Play, and What Actually Reinforces Sales Training

Learn when AI role-play helps, why Weflow skips it, and how Conversation Intelligence reinforces training.

Meeting Notes vs Conversation Intelligence: The Transcript Is the Cheap Part

Learn why meeting notes vs conversation intelligence comes down to Salesforce field writes, not transcripts.

How to Show Weflow Call Recordings and Transcripts on Salesforce Account and Opportunity Records

Learn how to show Weflow call recordings and transcripts on Salesforce Account and Opportunity pages