CRM Governance shows whether campaign launch controls, audience readiness, recovery preparation, and retention health need operator attention. A Recovery playbook is a stored relationship between an optional segment and automation rule. Creating or activating that record does not execute the rule, rebuild a segment, send a campaign, or prove recovery.
Require high-risk campaign sign-off
Open Admin → CRM → Governance. Under Policy controls, select Require sign-off when high-risk campaigns must receive explicit approval before they are trusted for launch. Select Make optional only when the tenant's approved policy permits launch without that additional gate.
The Sign-off policy tile confirms the stored posture. Pending high-risk queue counts high-risk draft, scheduled, or active campaigns without sign-off. Changing the tenant policy does not sign off existing campaigns. Open the campaign and complete Sign off (high risk) for the intended record.
Investigate the risk queues
Review Audience exceptions for draft, scheduled, or active campaigns with an audience size of zero. Rebuild the executable segment, confirm Current members, and use Resync audience from the campaign before trusting delivery readiness.
Under Retention governance watchlist, read each item's healthy, watch, or risk severity, summary, and Next action. The watchlist requires human review even when the sign-off policy looks healthy. Use Refresh after correcting the underlying campaign, segment, consent, or retention condition.
Create a Recovery playbook
Open Admin → CRM → Recovery playbooks. Under Create playbook, enter Name, choose an optional Segment, choose an optional Automation rule, and set Active as intended. Select Create playbook.
Choose None when the playbook is being saved before a segment or rule is ready. That creates a planning record, not an executable recovery path. For operational readiness, use an executable segment with current membership and a reviewed automation rule.
Edit, deactivate, or delete a playbook
Use the edit action in Playbooks to change the name, segment, rule, or Active state, then select Save changes. Cancel edit discards unsaved form changes. Inactive playbooks appear in the governance count so operators can see recovery plans that exist but are not ready.
The delete action permanently removes the playbook record after confirmation. It does not delete the referenced segment or automation rule. Before deleting, confirm that the record is not part of an operational runbook or audit trail.
Verify recovery rather than assuming it
To verify an actual recovery, separately confirm that the segment was rebuilt, eligible members exist, consent is valid, the automation or campaign lifecycle was intentionally started, provider dispatch completed, and recipient outcomes were recorded. The playbook's active badge indicates configuration readiness only; it is not execution or delivery evidence.