# Build brief — a focused alternative to SalesTouch

> **Verdict:** Not faithfully · **Buildability:** 26/100 · **Category:** Automation
> **Source:** https://www.canitbevibecoded.com/salestouch
> Independent editorial assessment from Can It Be Vibe Coded? Not affiliated with, endorsed by, or derived from SalesTouch. Verify current pricing and capabilities before acting.

## Context

**SalesTouch** — LinkedIn MCP for AI agents to research prospects and run outreach workflows. It currently costs $49/mo.

The local CRM and AI drafting layer are straightforward, but SalesTouch's core value is reliable access to LinkedIn's private network: authenticated sessions, live data extraction, residential IP routing, human-paced queues, limits, cooldowns, reconnection, and ongoing adaptation to platform changes. A one-shot clone either stops at manual copy and paste or becomes brittle automation that can put the LinkedIn account at risk.

This brief describes a focused, single-operator replacement for the part of SalesTouch that is genuinely reproducible. It is deliberately narrower than the product it replaces, and it says so in writing. Build the useful core; do not pretend to have rebuilt the rest.

## What you are building

Import or paste prospects, score them from user-supplied context, draft personalized outreach with an LLM, and track manual follow-ups in a local pipeline.

- Automate a small number of known workflows with logs, retries, and manual recovery.
- A responsive interface with real empty, loading, success, and error states.

## Requirements

### Functional

- LinkedIn account.
- Manual profile and conversation input.

### Data and integrations

- OpenAI API key.

Each of these needs a real account, credential, or quota. Set them up before writing feature code.

### Non-functional

- Accessibility: semantic markup, labelled controls, visible focus, and reduced-motion support.
- Security: server-side secrets, validated input, and no credentials in the client bundle.
- Reliability: retries with backoff on external calls, and a clear failure state when a provider is down.
- Portability: the operator can export their data and leave without losing it.

## Implementation brief

Build me a local LinkedIn outreach cockpit inspired by SalesTouch. Requirements:

- Node 22 + Express + better-sqlite3; one localhost web app with no accounts.
- Import prospects from CSV with name, company, role, LinkedIn URL, source,
  notes, and last-contact date; validate and deduplicate by LinkedIn URL.
- Let me paste profile, company, post, and conversation text into each record.
  Never crawl LinkedIn or read browser cookies.
- Store my offer and ICP rules in config.json. Use the OpenAI API to return a
  fit score, evidence, a personalized angle, a connection note under 300
  characters, a first DM, and one follow-up. Put OPENAI_API_KEY in .env.
- A kanban pipeline: new, researched, ready, contacted, replied, won, lost.
- A Today queue showing due follow-ups and a configurable manual daily limit.
- Each action opens the LinkedIn profile in a new tab and has copy buttons for
  the approved text. It must never click, send, invite, comment, or publish.
- Let me paste a new reply, show the complete conversation history, and draft
  a suggested response for approval.
- Log every status change and copied draft in SQLite; export prospects and
  activity as CSV. Never pretend a copied message was sent.
- Keep all data local. No cloud database, telemetry, background workers, or
  multi-user features.
- Explicitly out of scope: LinkedIn login or cookies, scraping, Sales Navigator
  automation, residential proxies, auto-sending, engagement, publishing,
  multi-account orchestration, and claims that this is account-safe automation.
- README: setup, CSV format, backup path, and an honest explanation that the
  tool replaces planning and drafting only, not SalesTouch's LinkedIn execution.

## Delivery standard

- Inspect the repository first, then write a short implementation plan before writing code.
- Deliver the smallest complete end-to-end workflow first; every primary control must work against persisted data.
- Use real validation and storage; never substitute fake dashboards, decorative controls, hard-coded success states, or mock integrations.
- Include responsive layouts plus genuine empty, loading, success, validation, and failure states.
- Keep secrets server-side in environment variables, provide .env.example, and never commit credentials or user data.
- Add structured logs around every external call and return actionable errors without leaking sensitive details.
- Write unit tests for the core logic and one automated test of the main user journey.
- Finish with a README covering setup, architecture, data location, backups, tests, deployment, and known limitations.

## Acceptance criteria

- [ ] A clean install starts the app using only the README and .env.example.
- [ ] The primary journey works from first visit through saved result, reload, edit, export, and deletion where applicable.
- [ ] Invalid input, missing configuration, provider failure, and an empty database each have a usable state.
- [ ] The interface works at 390px and 1440px, is keyboard navigable, and shows visible focus on every control.
- [ ] Tests, type checking, linting, and a production build all pass with no ignored failures.
- [ ] No part of the interface implies a live integration, security guarantee, or scale capability that was not actually built and verified.

## Non-goals

Do not build these, and do not claim to have replaced them:

- Live LinkedIn and Sales Navigator searches and audience extraction.
- Authenticated messages, invitations, engagement, and publishing.
- Residential IP routing and resilient LinkedIn sessions.
- Human-paced queues, limits, cooldowns, and account safety controls.
- Connectors, OAuth flows, and vendor API changes require constant upkeep.
- Reliability at the vendor's scale is an operations problem, not a prompt.

## What you still own after launch

- Secure credentials, rotate secrets, and handle provider rate limits.
- Run migrations, backups, restores, and dependency updates.
- Test the critical journey after every model, API, or hosting change.
- Monitor failures and fix the edge cases a first prompt will miss.
- Maintain every third-party integration as APIs and OAuth rules change.

## Risk

**Operational risk.** The code is achievable; dependable data, integrations, and ongoing operations are the real cost.

Editorial confidence in this assessment: high. No independent one-shot implementation is linked yet.

---

Generated by [Can It Be Vibe Coded?](https://www.canitbevibecoded.com) · Full report: https://www.canitbevibecoded.com/salestouch
