Intent & Signals
C

Common Room

Buyer intelligence platform that collects signals from across a company's own systems and the public web, resolves them to a single person, and activates them through agents. Signals are drawn from more than fifty channels spanning product usage, customer records, website activity, social engagement, community platforms and open source contribution, which is a wider and more developer oriented net than the advertising derived intent common in this category.

The resolution engine, marketed as Person360, is the distinguishing asset: it merges the same individual appearing as a code repository handle, a community member, a product user and a website visitor into one enriched profile, running waterfall enrichment across dozens of providers without per lookup charges. An agent layer performs research, drafts personalised messaging, maintains customer record hygiene and executes pipeline plays. A command line interface and a model context protocol server expose the whole thing as scriptable infrastructure rather than a dashboard.

Zoom announced a definitive agreement to acquire the company on 2 July 2026 and the transaction closed that month, with the founding chief executive and team joining the acquirer. The product continues to sell on its own site under its own name with its own pricing, documentation and free entry path, so it is graded on that surface rather than as an absorbed product.

Founded 2020 in Seattle. Two unrelated businesses trade under similar names and neither is this vendor.

Last VerifiedAugust 30, 2026
Compare Common Room with other vendors
Founded
2020
Headquarters
Seattle, Washington, United States
Categories
intent-and-signals, data-and-enrichment, ai-sdr-agents
Assessment

Capability Axes

Capability grades

17 of 17 axes rated · 6 graded A or B

AI Capability
AI CentralityAI CentralityWhether AI is the product or a feature veneer. The removal test: peel the AI label off, and does anything sellable remain?
BB on AI CentralityAI carries a core workflow, with real product surface that is not AI. The vendor is specific about which parts are model driven.
Vendor Published

Identity resolution is the product and it cannot be done without models. The platform's value proposition is that the same person appears as a code repository handle, a community forum member, a social commenter, a product user and an anonymous website visitor, and that these are one buyer. Deciding that is probabilistic matching across systems with no shared key, which is what the resolution engine does, and it runs waterfall enrichment across dozens of providers on top.

Remove that layer and what remains is fifty channels of unresolved activity, which is the problem the customer already had rather than a smaller version of the product. The acquirer described the company as AI native in its own announcement.

Held below the top band because the origin is narrower than the current positioning: the company began in 2020 as a community intelligence tool aggregating engagement across developer platforms, and the agent layer performing research, message drafting and record maintenance is a recent addition on top of that graph rather than the thing that was built first. Ask what match rate the resolution engine achieves and how it degrades on individuals with no public footprint.

Autonomy and Oversight ModelAutonomy and Oversight ModelWhat the system does without a human. Draft for review, auto send, or fully agentic, and what contains a bad run.
CC on Autonomy and Oversight ModelAutonomy is claimed or implied with the oversight model asserted rather than documented. Buyers cannot tell from public sources what runs unsupervised.
Vendor Published

Autonomous enrolment into outreach is described by the vendor in its own words, and no boundary around it is published. A published playbook describes website pricing page activity flowing into the platform, the resolution engine filtering to economic buyers, and qualifying individuals being added to outreach sequences personalised to their behaviour, stated explicitly as happening without human intervention.

That is a system deciding on its own that a specific named person should begin receiving sales messages. An agent layer separately maintains customer records and executes pipeline plays. What is absent is everything that would bound it: no published statement on what an operator can constrain, whether enrolment can require approval, what volume ceiling applies, or what stops a workflow mid run.

One structural mitigation exists and is worth recording, in that the platform enrols into a connected sequencer rather than sending itself, so the customer's own sending controls apply downstream. Ask whether automated sequence enrolment can be set to require human approval, and what caps apply per workflow.

AI Disclosure and Model TransparencyAI Disclosure and Model TransparencyWhat models power the product, whether AI generated outreach discloses itself, and whether scoring and routing logic is explainable.
CC on AI Disclosure and Model TransparencyThe product is described as AI powered with the stack, the disclosure behavior, and the scoring logic all unstated.
Vendor Published

The agent surface is named in detail and what sits underneath it is not. Individual agents are identified by function, covering research briefs, a natural language query interface, record maintenance and play execution, and the platform is exposed through a command line interface and a model context protocol server so a customer can reach it from their own tooling. That is architectural disclosure of a useful kind.

What is missing is the model layer itself: no provider, family or version is named anywhere, no model card exists, and no evaluation or error rate is published for either the resolution engine or the generated messaging. The resolution accuracy gap matters most, because a wrong merge attributes one person's activity to another and every downstream action inherits that error, and the only figures offered are relative comparisons against unnamed competitors. Ask which models generate research and messaging, and for measured precision and recall on identity resolution.

Operational and Outcome EvidenceOperational and Outcome EvidenceMeasured outcomes with a stated basis: replies, meetings, pipeline, win rates. Logos are not evidence and prestige is not measurement.
CC on Operational and Outcome EvidenceOutcome claims are headline percentages with no stated basis, or customer logos standing in for results.
Vendor Published

Named enterprise customers in quantity, comparative claims without method. The customer roster is unusually strong for a company of this age, spanning large software, security, design and data platform businesses, with more than four hundred customers reported, and one published enterprise reference states the platform was the only one to pass that customer's security and privacy review. That is a specific and checkable claim rather than a generic endorsement.

The performance claims are the weak half: match rates asserted as thirty to fifty percent higher than competitors and duplicate reduction of up to seventy nine percent, both stated without naming the competitors, the comparison method, the sample or the period. For an identity resolution product those are the central claims and they carry no methodology. Nothing published measures pipeline or conversion effect against a holdout. Ask how the match rate comparison was run, against which competitors and on what sample, and for conversion lift on signal sourced accounts against a matched control.

Compliance and Risk
Outreach Compliance PostureOutreach Compliance PostureHow the product handles regulated outreach: consent, DNC scrubbing, opt out mechanics, caller ID conduct, and the public enforcement record.
CC on Outreach Compliance PostureCompliance is mentioned as the customer’s responsibility, with little or no product enforcement described. The tool can be run lawfully, and nothing about it helps.
Vendor Published

The platform decides who gets contacted and hands the sending to someone else, which splits the obligation without resolving it. Qualifying individuals are enrolled automatically into sequences running in a connected engagement tool, so consent capture, suppression and unsubscribe handling execute on the customer's own estate under their own configuration. That is the right architectural place for those controls.

What is unaddressed is the handoff: nothing published states whether an objection recorded in the connected system prevents re enrolment by a workflow, whether suppression state is read before enrolment, or what governs contacting a person identified through community or open source activity who has no relationship with the customer. That last case is specific to this product, since signal is drawn from developer platforms and forums where participation is not a commercial approach. Ask whether suppression state in the connected sequencer is checked before automated enrolment, and what governs outreach to people identified through community activity.

Data Privacy PostureData Privacy PostureGDPR and CCPA posture: lawful basis, data subject rights handling, DPA availability, subprocessor disclosure.
BB on Data Privacy PostureA real privacy program is visible (DPA available, policy substantive) with a gap on the hard question, commonly lawful basis for enriched or tracked individuals.
Vendor Published

A concrete remedy rather than a policy statement, and a default that limits collection at source. The vendor publishes a programmatic integration for removing all personally identifiable information, which is an interface a customer can call rather than a request form, and that is a materially more useful control than a written commitment for a platform holding resolved person profiles.

Documentation states the tracking default plainly: website visitor tracking collects no personal information by default and identifies only the company, and linking a visit to a named individual occurs only where that person voluntarily submitted their details through a form or signup, governed by the customer's own terms. Stating where the person level line sits, and that crossing it requires the individual's own action, is a precise answer to the question this category usually evades.

Around it sit adherence to the European and California regimes, encryption in transit and at rest, and customer controls over access, retention and deletion. Held below the top band because several instruments were not located: no subprocessor list, no transfer mechanism, no stated retention period and no data protection officer. Ask for the subprocessor list, the retention schedule for resolved profiles, and the transfer mechanism.

Data Licensing and ProvenanceData Licensing and ProvenanceWhere the data comes from and on what legal footing: licensed, contributed, public record, or scraped, and who stands behind the answer.
CC on Data Licensing and ProvenanceData is described by its size and coverage with its origin unstated. The provenance question is answerable only by asking the vendor.
Vendor Published

One supplier is named and the rest of the supply chain is described only by count. Waterfall enrichment is stated to run across dozens of providers with no per lookup charge, and a prospecting database of more than two hundred million business contacts is offered, and neither the enrichment providers nor the source of that contact database is identified anywhere.

The one exception is creditable and worth recording: intent topics are explicitly licensed from a named cooperative and the allocation is published per tier, so a buyer knows which upstream vendor supplies that signal and how much of it they get. That single disclosure demonstrates the vendor can name a supplier when it chooses to.

Signals collected from social, community and open source channels raise a further provenance question about what basis supports collecting and retaining public activity for commercial profiling, which the published surface does not address. Ask which providers the enrichment waterfall draws on, where the prospecting database originates, and on what basis community and open source activity is collected and retained.

Platform Terms ExposurePlatform Terms ExposureWhether the product operates inside the terms of the platforms it touches, and the restriction risk a buyer inherits when it does not.
BB on Platform Terms ExposureThe method is described and mostly conformant, with one real ambiguity the vendor does not resolve, or conformance asserted without the partnership evidence that would settle it.
Vendor Published

A stated conformance position exists and covers the whole estate, which is the right form of commitment for this axis. The security page states that all integrations use official interfaces and conform to the terms of service of third party providers, which is a general undertaking rather than a platform by platform one but is stated plainly and applies across the connector set.

That matters here more than for most vendors because of what is collected: signal spans social platforms, community forums and code hosting services, each governing programmatic access under its own rules, and a vendor collecting across all of them without such a statement would sit lower by default. Held below the top band because breadth is doing the work of specificity.

The claim names no individual platform, states no method, and sits alongside a browser extension whose collection behaviour is not described, which is the exact pattern the grading convention treats cautiously. A blanket assurance covering dozens of third parties is harder to verify than a named commitment covering one. Ask what the browser extension collects, and whether the conformance commitment appears in the customer agreement rather than only on the security page.

AI Safety and Data StewardshipAI Safety and Data StewardshipThe cross client boundary: whether customer data trains models that serve competitors, plus retention and deletion posture.
CC on AI Safety and Data StewardshipSecurity language exists but the training question, the one this axis turns on, is unanswered: a buyer cannot tell whether their pipeline data improves a competitor’s instance.
Vendor Published

A resolved profile is a more sensitive artifact than the signals it was built from, and no stewardship position covering it was located. The platform merges a person's product usage, community participation, open source contribution, social engagement and website behaviour into a single enriched record, which is a fuller picture of an individual than any one source holds and which the agent layer then reads to generate research and messaging.

Nothing published states whether that material trains or tunes any model, which providers process it when an agent runs, whether prompts and generated output are retained, or whether profiles cross a tenant boundary. A service organisation control report is referenced and customer controls over retention and deletion are described, both of which address who may reach the data rather than what the vendor may do with it. Ask whether resolved profiles or agent prompts train or tune any model, which providers process them, and whether any data crosses tenant boundaries.

Recipient Disclosure and AuthenticityRecipient Disclosure and AuthenticityHow the product presents itself to the people it targets: whether automated outreach and AI agents disclose themselves, whether sender personas are real, and whether personalization is grounded in verifiable fact. Measured as known compliance with Article 50 of the EU AI Act, in force since August 2, 2026, which requires AI systems that interact with individuals to disclose that fact.
CC on Recipient Disclosure and AuthenticityNothing published on whether recipients are told they are dealing with software. For a product whose AI talks to prospects, silence here is now a regulatory posture, not a style choice.
Vendor Published

A careful architectural line on identification, and silence on machine authorship. The documentation states that website tracking identifies the company rather than the person by default, and that linking activity to a named individual happens only where that person voluntarily submitted their details, which is a more restrained position than the person level identification several competitors in this lane market as a headline. Bot and cloud provider traffic is filtered.

A programmatic route exists to purge personal information. Against that, once a person is resolved the platform generates personalised messaging about them and enrols them into sequences automatically, and nothing published states whether the resulting message carries any indication that a machine composed it or that the trigger was their browsing and community activity.

A recipient receives what reads as a personal approach, prompted by behaviour they did not know was observed and written by a system. Ask whether agent generated messaging is marked as such for the sender or the recipient, and what a person is told about the signals that triggered the approach.

Integration and Deployment
Ecosystem and Integration DepthEcosystem and Integration DepthDocumented depth of CRM and stack integration: objects, sync direction, API surface, marketplace presence that matches the claims.
BB on Ecosystem and Integration DepthSolid primary CRM integration documented, with depth unstated at the edges (sync direction, custom objects, failure behavior).
Vendor Published

Unusually open delivery for a data product, with the platform exposed as infrastructure rather than only as an application. A model context protocol server and a command line interface are available across all plans, not gated to an enterprise tier, so the intelligence can be queried from a customer's own agents and scripts rather than only through a dashboard, and an official application for a major conversational assistant lets non technical users query signals in natural language.

That is a deliberate headless posture and it is rare in this category. Signal collection spans more than fifty channels, and the published integration list names specific partners across review platforms, spreadsheets, community tooling, data activation, support systems, marketing automation and publishing. Documentation and an academy are maintained publicly.

Held below the top band because gating shapes what a buyer receives: product signal integration and recurring data exports sit at the enterprise tier, record maintenance actions are an add on, and no interface rate limits or authentication documentation were verified on this pass. Ask which integrations and export capabilities exist at the tier quoted.

Deployment Model and Data ResidencyDeployment Model and Data ResidencyWhere the product runs and where customer data lives, including residency options for EU buyers.
CC on Deployment Model and Data ResidencyCloud hosted is the whole public answer. Region and residency questions require a sales conversation.
Vendor Published

Nothing published locates the data. No hosting provider or region is named, no European or United Kingdom residency election is described, no tenancy model is stated, and no recovery time or recovery point objective appears. The gap carries more weight here than for a conventional application because of what accumulates: resolved person level profiles built from community, social and open source activity of individuals across jurisdictions, including people who never transacted with the customer.

A European buyer cannot establish from the published surface where profiles of European individuals are processed or stored, and the acquisition adds a further question the surface does not answer, since the acquirer operates its own global infrastructure and nothing states whether that changes the hosting position. Ask which regions resolved profiles are stored in, whether regional residency is available, and whether the acquisition changes the hosting arrangement.

Security Certifications and Trust CenterSecurity Certifications and Trust CenterVerifiable security posture: enumerated current certifications and a trust center an outsider can actually read.
BB on Security Certifications and Trust CenterCertifications named and plausible with a gap: no trust center, stale dates, or asserted without enumeration.
Vendor Published

A real attestation with an enumerated control set, and a customer willing to say the review was passed. A service organisation control report is held and referenced directly, security documentation is described as accessible, and the security page enumerates controls rather than gesturing at them: single sign on, role based access control, security assertion markup and directory provisioning through named identity providers, encryption in transit and at rest, and customer controls over access, retention and deletion.

A published enterprise reference from a security company states that this was the only platform to pass their security and privacy review, which is an unusually specific third party endorsement of exactly this axis. Held below the top band on three counts. No certificate, report or audit period is published openly and no auditor is named. No international information security standard is claimed alongside the attestation.

And the vendor's own pricing material describes itself as certified for an attestation that is a report rather than a certification, a small imprecision on the page a buyer reads first. Ask for the report with its audit period and auditor, and whether any certification is held alongside it.

Commercial and Operational
Commercial TransparencyCommercial TransparencyWhether a buyer can budget without a sales call. Published pricing graded on completeness, not on the price itself.
CC on Commercial TransparencyA pricing page exists and communicates structure without numbers, or numbers so qualified they do not budget anything.
Third Party Estimated

The structure is published in detail and the figures are not, or not consistently. What the vendor does publish is a full comparison across three named tiers with the limits that decide the bill enumerated: seat counts, contact ceilings, research and prospecting credit allocations, website activity volumes per year, deanonymization limits per month, and licensed intent topic counts stepping through six, twelve and twenty five.

That is more structural disclosure than most vendors at this grade offer and it lets a buyer see what they would be choosing between. What cannot be established is the price. Two independent sources give conflicting figures for the entry tier, one reporting a commitment above twenty thousand dollars annually and another around thirty thousand, and no figure was confirmed on the vendor surface on this pass, so this grade records structure published with price unconfirmed rather than a finding that nothing is published.

The upper two tiers are quote only by the vendor's own description. Billing is annual only, which removes the monthly option a smaller buyer would use to limit exposure, and load bearing capabilities including product signal integration and record maintenance actions are add on only. Ask which entry figure is current, what the upper tiers cost, and the price of each add on.

Exit and Data PortabilityExit and Data PortabilityWhat happens when a customer leaves: completeness of data export, rights to enriched or licensed data after termination, deletion commitments, and auto renewal mechanics, graded from published terms and documentation.
CC on Exit and Data PortabilityExport exists as a feature claim while the terms that govern exit, data rights after termination, deletion, and auto renewal mechanics, are not published anywhere a buyer can read.
Vendor Published

Export exists as a product feature and sits behind the top tier, which is the finding. Automatically recurring data exports are listed as an enterprise capability rather than a baseline one, so a customer on either lower tier does not have a documented bulk route out as part of what they bought.

A command line interface and a protocol server are available on all plans and would let a technically capable customer extract data programmatically, which is a genuine alternative path though it requires engineering rather than a setting. Beyond that the surface is silent: no statement of export scope or format, no retention period after termination, no deletion timeline and no renewal or notice terms.

The asset at stake is specific and hard to rebuild, being a resolved identity graph assembled over the contract term from signals across dozens of channels, where the raw sources remain with the customer but the resolution does not. Ask whether the resolved graph and enrichment exports in usable form on the tier quoted, and what the deletion timeline is after termination.

Deliverability and Sending DisciplineDeliverability and Sending DisciplineThe operational craft of sending: warmup, rotation, volume governance, spam rate monitoring, and what happens when reputation degrades.
CC on Deliverability and Sending DisciplineDeliverability is invoked as a benefit with no documented mechanism. For senders this is the axis where marketing most outruns evidence.
Vendor Published

No sending infrastructure exists and the platform still decides what gets sent. Messages leave through a connected engagement tool on the customer's own domains and sending estate, so reputation, warmup, bounce handling and complaint thresholds all belong to that system and to the customer, and there is no shared pool where one customer's behaviour affects another.

What this platform contributes upstream is both the recipient list and, through the agent layer, the message content, and both of those drive deliverability outcomes downstream. Nothing published describes address validation before automated enrolment, which is the control that matters given enrichment supplies the addresses, nor whether a workflow responds to bounces by suppressing further enrolment. Ask whether addresses are validated before automated sequence enrolment, and whether bounce feedback from the connected sequencer suppresses further enrolment.

Segment and Market CoverageSegment and Market CoverageWho the product actually serves, evidenced: segments, geographies, languages, and customers that match the claim.
BB on Segment and Market CoverageSegment focus is clear and evidenced with a gap in geographic or language specifics.
Third Party Estimated

The served motion is named with unusual precision, which is more useful than an industry list. Rather than segmenting by company size or vertical, the vendor publishes use case pages for the specific go to market motions it serves, naming commercial open source, product led sales, community led growth, account based sales and job change tracking, alongside team pages for account based marketing, demand generation, revenue operations, account executives and sales development.

A buyer running one of those motions can identify themselves immediately, and a buyer running none of them learns something too. The customer roster corroborates the claim, concentrating in software companies with developer audiences and community or open source distribution.

Held below the top band by a boundary the vendor does not state and independent analysis does: the signal coverage is community and product oriented, which fits companies whose pipeline starts with free tier signups, repository activity or forum participation, and fits poorly for enterprise account teams whose deals turn on earnings commentary, leadership change and strategic initiatives. The entry commitment also sits well above what a small team would spend. Ask what the smallest viable deployment is and what proportion of signal coverage applies outside developer oriented markets.

Commercial

Pricing

What this vendor charges, what it commits to in writing, and where the bill can move. Figures the vendor publishes itself are labeled Vendor Published. Figures labeled Estimated come from other sources and the vendor has not confirmed them.

What it costs
Third Party Estimated
Structure published, figures unconfirmed on this pass
In short
  • Common Room publishes what each of its three plans includes in real detail, and does not clearly publish what any of them costs.
  • You can see exactly what you would be choosing between: how many people can use it, how many contacts you can hold, how many research and prospecting credits you get, how many website visitors it will identify each month, and how many intent topics you can track. That is more than most tools in this index tell you.
  • What you cannot see is the price. Outside sources report the smallest plan at somewhere between twenty and thirty thousand dollars a year, and they disagree with each other by about a third. The two larger plans have no published price at all.
  • You can only pay yearly, not monthly, so the first commitment is a full year.
  • Some important features cost extra on top: connecting your own product usage data, letting the AI update your customer records, and phone numbers are all add ons.

How the price works

What you are charged for, and what makes the bill go up.

Annual subscription across three named tiers with a fourth free entry path, billed annually only with no monthly option. Each tier carries published allocations rather than published prices: seats, contact ceilings, research credits, prospecting credits, website activity volume per year, website deanonymization volume per month, and licensed intent topic counts. All tiers include unlimited alerts, workflows and segments, the identity resolution engine, job change tracking, core customer record and messaging integrations, and both the command line interface and model context protocol server.

Product signal integration and recurring data exports are enterprise tier capabilities. Record maintenance actions, premium phone enrichment and additional prospecting credits are add ons at every tier.

What the contract says about your data

What the vendor commits to in writing once your data is in the product.

A service organisation control report is held and referenced on the security page, with security documentation described as accessible. Adherence to the European and California privacy regimes is stated, alongside encryption in transit and at rest and customer controls over data access, retention and deletion. A programmatic integration is published for removing all personally identifiable information, which is an interface rather than a request process and is the most concrete privacy remedy located for this vendor.

Identity and access run on single sign on, role based access control, security assertion markup and directory provisioning through named identity providers. Not located on this pass: a subprocessor list, a transfer mechanism, a stated retention period, a data protection officer, or any international information security certification alongside the attestation. Note that the vendor's own pricing material describes the attestation as a certification, which is imprecise since it is a report.

Getting started

What it costs and what is included before the product is running.

Not published. No onboarding, implementation or professional services fee appears on any surface, and a free entry path and self serve start are offered alongside a demo request. The enterprise tier includes a dedicated customer success manager, indicating support tiering by plan rather than separate charge. The material cost above the licence is add on consumption: additional prospecting credits, premium phone enrichment and record maintenance actions are each separately purchased, and product signal integration is available only at the top tier or as an add on.

What to watch for

Where this pricing can surprise a buyer who has not read it closely.

Structure published in unusual detail, figures unconfirmed, and the two upper tiers quote only by the vendor's own description. The published comparison enumerates what actually decides the bill across three named tiers: seat counts, contact ceilings, research and prospecting credit allocations, website activity volumes per year, website deanonymization limits per month, and licensed intent topic counts stepping through six, twelve and twenty five. Capability gating is also published, with product signal integration and recurring data exports at the enterprise tier and record maintenance actions and premium phone enrichment as add ons at every tier.

What could not be established is price. Two independent sources give conflicting figures for the entry tier, one reporting an annual commitment above twenty thousand dollars and another around thirty thousand for five seats, and no figure was confirmed on the vendor surface on this pass. Those same third parties also disagree with the vendor's own comparison table on the entry intent topic allocation, giving five where the vendor publishes six, which is a reminder that the third party pricing summaries for this vendor are not reliable in detail.

Billing is annual only, removing the monthly option a smaller buyer would use to limit exposure. entryPriceUsd left blank: no figure was confirmed on a vendor surface and the two third party figures conflict by roughly fifty percent. One structural note for buyers: intent topics are licensed from a named third party cooperative that is separately indexed here, so a customer already contracting with that cooperative directly may be paying for the same signal twice.

Contact us

Found a vendor we missed? Have feedback on the index? We’d love to hear from you.