**TL;DR**

Suppression state does not belong in the prompt or in the agent's memory. Move the do-not-email list into a durable table that lives outside the agent, and check it right before every send. Then a prompt edit can never wipe it, because the send gate reads from the table, not from whatever the agent happens to remember. Make the gate fail closed: if the table is unreachable, the send does not go out.

```text
agent's do-not-email memory got reset when the prompt was edited  -  it sent a breakup email to a lead who converted last week
```

## Steps

1. Create a suppression table with one row per lead plus a reason (unsubscribed, converted, opted out, bounced hard) and a timestamp. This is the single source of truth, and no prompt edit touches it.
   Expected: editing the agent's instructions changes nothing about who is suppressed; the table is untouched.
2. Write converted and closed leads into that table automatically, the moment the CRM status changes. Don't rely on the agent noticing.
   Expected: a lead that converts today is in the suppression table within minutes, with reason set to converted.
3. Gate every send on a lookup: lead in suppression table means no send, no exceptions, not even the breakup email. The breakup email is still a send.
   Expected: sending a breakup email to a converted lead is impossible; the gate blocks it and logs the block.
4. Fail closed on errors. If the suppression lookup times out or the table is down, the send is held for review instead of going out on the assumption that the lead is fine.
   Expected: pulling the network on the suppression store pauses sends instead of releasing them.
5. Audit the table weekly for rows with no reason or no timestamp, and reconcile against the CRM so the two never drift apart.
   Expected: a weekly diff shows zero leads that are converted in the CRM but missing from the suppression table.

## Use this when

- the agent keeps suppression rules in its instructions or memory and they keep getting lost
- prompt edits, restarts, or context resets wipe the do-not-email state
- converted leads or opted-out leads are getting emailed by later runs

## Not for this skill when

- an unsubscribe link that 404s or doesn't sync back from the mail provider (that's a plumbing/sync problem)
- suppression that exists in one tool but not another, like LinkedIn vs email (that's a channel-suppression problem)
- complaint handling or domain reputation recovery after the damage is done

## Variant phrasings

- do-not-contact list lost after editing the agent instructions, opted-out lead got emailed
- agent forgot the suppression list after a restart and emailed converted leads
- breakup email sent to a customer because the agent's memory of the conversion was gone

## Why it happens

The do-not-email state lived only in the agent's working memory, seeded by the prompt. Editing the prompt changed what the agent was told to remember, and the old suppression entries were silently dropped. Nothing outside the agent knew the lead had converted, so the next run had no way to know it shouldn't send.

## Edge cases

- a lead suppressed for 'converted' who later churns needs a re-entry path; suppression rows should be reviewable, not permanent, with an explicit unsuppress action
- the gate must run on every send path, including manual one-off sends and webhook-triggered sends, or those paths become the leak
- race between the conversion write and the send check can still slip one email through; the write should happen before any campaign that could target the lead
- suppression by email address misses the same person under a second address; key on the CRM contact id where you can

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_L86I7Pv2gicUyVs7_KSe-w
