create_campaign
Create a marketing campaign (email, SMS, or WhatsApp) in DRAFT. For email channelConfig, use subject + htmlBody + optional plainTextBody. recipientSource="list" is accepted as an alias for "individual".
This record as markdown: /tools/io-favcrm-favcrm/create-campaign.md
What create_campaign does on FavCRM
AI agents use create_campaign to create or update resources in FavCRM, usually the action step of a workflow, after the agent has gathered context. Every call changes real data in your FavCRM environment.
| Parameter | Type | Required | Description |
|---|---|---|---|
name | string | Yes | Campaign name (internal) |
status | string | — | Default DRAFT |
channel | string | Yes | email | sms | whatsapp | push |
segmentId | object | — | Required if recipientSource="segment" |
scheduledAt | object | — | ISO datetime for scheduled send (status must be SCHEDULED) |
recipientIds | array | — | Required if recipientSource="individual", "list", or "csv"; values are account IDs |
channelConfig | object | — | Channel-specific config: subject + htmlBody for email, body for sms/whatsapp, templateId, etc. Legacy email html is normalized to htmlBody. |
recipientSource | string | — | Where to source recipients from. "list" is normalized to "individual". |
Parameters from the server's own tool schema.
Why create_campaign is rated Medium
This tool creates new marketing campaign records but does not execute, delete, or send them (they remain in DRAFT state). It is a Write operation because it creates and modifies data reversibly. Severity is medium because a misused campaign could be created with malicious content targeting customer lists, but the draft status provides a safety boundary—it does not automatically send or execute.
From the tool's definition Tool description states 'Create a marketing campaign (email, SMS, or WhatsApp) in DRAFT', indicating it creates new data records. The mention of draft status shows the action is reversible (campaigns can be edited or deleted before sending).
Attacks that exploit this kind of access
The rule that runs create_campaign safely
PolicyLayer is an MCP gateway: it sits between your AI agents and FavCRM, and checks every tool call against a rule you set before the call runs. Nothing changes on the server itself. For create_campaign, this is the rule to start with:
create_campaign stays usable, but capped: an agent stuck in a loop can't make hundreds of changes a minute. Everything else on the server is denied unless you say otherwise.
The button opens the PolicyLayer dashboard: create your workspace, connect FavCRM, apply this rule, and every create_campaign call is checked against it from then on.
Questions about create_campaign
Create a marketing campaign (email, SMS, or WhatsApp) in DRAFT. For email channelConfig, use subject + htmlBody + optional plainTextBody. recipientSource="list" is accepted as an alias for "individual". It is categorised as a Write tool in the FavCRM MCP Server, which means it can create or modify data. Consider rate limits to prevent runaway writes.
create_campaign accepts 8 parameters: name, status, channel, segmentId, scheduledAt, recipientIds, channelConfig, recipientSource. Required: name, channel. The full parameter table on this page comes from the server's own tool schema.
Register the FavCRM MCP server in PolicyLayer and add a rule for create_campaign: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches FavCRM. Nothing to install.
create_campaign is a Write tool with medium risk. Write tools should be rate-limited to prevent accidental bulk modifications.
Yes. Add a rate_limit block to the create_campaign rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.
Set action: deny in the PolicyLayer policy for create_campaign. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.
create_campaign is provided by the FavCRM MCP server (https://api.favcrm.io/mcp). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.
More on FavCRM, and thousands of servers like it.
This server
Across the catalogue