Scratchpad
Scratchpad is a workspace that sits over Salesforce and exists to remove the reason sellers avoid it.
The original product was speed. Grid and sheet views let a representative edit large numbers of Salesforce fields inline, replacing the spreadsheet that usually lives beside the system of record. Notes, tasks and daily lists sit in the same place and link back to opportunities, leads, contacts and accounts. Kanban views and a browser extension put the same surface wherever the seller already works.
The current product is capture and inference on top of that. A recorder and notetaker join meetings across the main conferencing platforms, transcribe them, and produce summaries and action items. Agents then read calls, emails and notes and either propose or apply Salesforce field updates, including the qualification framework fields most teams struggle to keep current, with support named for several common methodologies. A deal and account agent answers questions against the full history of a record. Custom prompts can be built, and an administrator controls which are used, who may edit them and where they appear, with usage and performance tracked over time. A hygiene monitor runs daily against process adherence, flagging missing fields, stale opportunities and deals running outside process, with Slack alerts and deal rooms alongside.
The architecture is the distinguishing choice. Scratchpad connects through Salesforce's own interface using delegated authorisation, ships as a managed package an administrator provisions per user profile, and inherits the org's existing rules, permissions, layouts and workflows by default rather than presenting its own. It also supplies a field history view covering long form text fields, which Salesforce does not itself provide.
Pricing is metered in artificial intelligence credits, with the consumption rate of each action published.
Adjacent to the core product the company operates a services arm under a separate brand and has launched Clearskies, positioned as a context layer for third party assistants.
The company is Scratchpad, Inc., of San Francisco, California, founded in 2019 by Pouyan Salehi and Cyrus Karbassiyoon, who previously built the outbound platform PersistIQ. It has raised approximately 49.6 million dollars across a seed round and two later rounds.
Capability Axes
The workspace works without a model and the meter runs on one, which places this firmly mid to upper band rather than at either extreme.
What depends on inference: field updates derived from calls, emails and notes, call summaries and action items, a deal and account agent answering questions against a record's full history, and prompt driven insight across the team. Those are the capabilities the marketing leads with and the ones the pricing is built around, since every tier is denominated in artificial intelligence credits and the free tier's constraint is 100 of them a month.
What does not: the interface itself. Grid and sheet views for bulk field editing, notes linked to records, tasks and daily lists, Kanban boards and the browser extension are deterministic software, and they were the whole product for the company's first several years. A customer who exhausts their credits still has a working Salesforce workspace, which is a meaningful test.
The honest reading is a speed layer that has become a capture and inference layer, where the model now drives monetisation without yet being the thing that breaks if removed. Metering the product in model consumption is a stronger centrality signal than most vendors here provide, and it is the reason this sits at the top of the middle band.
Ask what proportion of active accounts exhaust their credit allowance in a normal month.
This is the most complete oversight design recorded in this index, and it is built rather than promised.
Permission inheritance is the foundation. The vendor states that when a user signs up it instantly implements the org's existing rules, permissions, layouts and workflows, and draws an explicit contrast with other tools using the same interface that do not inherit configuration. Because the layer adopts the customer's own controls, an administrator does not have to reproduce a governance model inside a second system.
Deployment is gated. A managed package can be provisioned on a per user profile basis, so the vendor states plainly that this is not all or nothing and the customer chooses who runs it.
Agent governance is separately controlled. Advanced controls cover workspace permissions for building and deploying models and agents. Custom prompts carry control over which are used, who may edit them and where they appear, with usage and performance tracked over time. Field updates are described as proposed or applied, with review available before submission.
The audit story exceeds the platform's own. The vendor supplies field history including long form text fields, which Salesforce does not provide, and separately retains logs for at least twelve months identifying each staff member who accessed or acted on customer data.
What is unstated is whether review before submission can be enforced centrally or is a per user choice.
Ask whether an administrator can require human review of agent field updates for a profile.
This is the most complete artificial intelligence disclosure recorded in this index, and it answers the question buyers actually ask.
The vendor names the provider outright, names the specific commercial tier it purchases, and states the consequences that tier carries: the provider will not store the queries, no customer data is used for any model training, inputs are processed in real time, and nothing is stored or linked to any personal identifier. It then states what the capability is used for, generating summaries of call transcripts and answering relevant Salesforce fields, and that the outputs are displayed to the end user for further application rather than written silently.
Provider, tier, retention, training, linkage, purpose and output handling in one passage is more than any other record here supplies. The two other vendors graded A on this axis in the current sweep each answered part of it: one named the provider and the transfer mechanism without describing the data flow, the other described the contractual position across a portfolio without naming any provider. This record does both.
Naming the enterprise tier rather than the provider alone is the detail that matters, since the retention and training terms differ by tier and a buyer can verify the claim against the provider's own published terms.
Two gaps remain. No model version is given, so a silent upgrade would not be visible. And no accuracy figure or evaluation supports field update suggestions, which is output that lands in a system of record and feeds a forecast.
Ask for the accuracy rate on suggested field updates and how errors are detected.
The independent review base is the largest recorded in this index, and named executives attach figures to it.
The principal enterprise review platform carries more than 1,470 reviews at 4.8, with the vendor recognised there as both a leader and a high performer. That volume exceeds every other record graded here, including the enterprise resource planning vendor built earlier in this session, and it is concentrated on the platform enterprise buyers actually consult.
Attribution goes further than a rating. A head of revenue at a named payments company is quoted on 6,000 hours reclaimed from administration to selling. A senior director of revenue operations at a named maintenance software company describes adoption arriving without chasing people or running audits, which is a behavioural claim rather than a time saving one and harder to manufacture. A further customer figure covers more than 9,000 model driven Salesforce updates and 455 hours saved monthly. A use case page states more than 80 percent field completion following a backfill.
What holds the record short of complete is method. Every figure is customer reported inside a testimonial, with no measurement window, no baseline and no denominator, and two passes located no case study carrying a stated methodology.
The combination still clears the top band, because the review volume supplies the independent corroboration the figures lack.
Ask for the field completion rate before and after, measured over a stated period.
The product does not prospect, and the compliance question it does raise goes unanswered.
On the conventional reading the axis barely applies. Mail integration reads messages for context and logs activity rather than sending campaigns. There are no sequences, no contact lists, no sending volume and no recipients the product selects. Two passes located no outbound capability of any kind, and the vendor makes no claim to one, so the absence of suppression lists and unsubscribe handling reflects a product that does not need them.
The corporate compliance posture behind it is strong, with an independent audit report over a period, stated alignment with two privacy regimes, a maintained supplier list and a published trust portal.
What is genuinely missing sits elsewhere. A recorder and bot join customer conversations across three conferencing platforms and transcribe them. Recording consent is a real legal obligation that varies by jurisdiction, with several requiring all parties to agree, and two passes located no consent capture mechanism, no recording notification behaviour, no jurisdictional guidance and no administrator control over where recording is permitted.
That is the compliance surface for this product and it is undescribed, which is why the grade sits mid band rather than being set aside as inapplicable.
Ask how the recorder obtains and evidences consent in all party consent jurisdictions.
The commitments published are specific and unusually operational, and the governing documents were not examined in this pass.
What the vendor commits to in writing: collecting the minimum data needed to power features, with a stated choice to opt out; encryption of all sensitive data in transit and at rest under a named standard, with keys generated and stored to prevent loss, theft or compromise; least privileged access with regular audits so only employees whose role requires it can reach customer data; retention of logs for at least twelve months identifying each staff member who accessed or acted on customer data; daily encrypted backups; and a maintained current list of third party subprocessors. It opens by stating it will never sell customer data or hold it hostage.
Access logging at that granularity, published as a commitment rather than mentioned in an audit summary, is rare here and does real work for a buyer assessing insider risk.
Two things keep this out of the top band. The subprocessor list and the privacy policy itself were not opened in this pass, so the commitments are credited from the security page that describes them rather than from the documents. And no retention schedule was located for the artefacts this product creates rather than reads, meaning call recordings, transcripts and generated summaries, which is the material a customer would most want a deletion timeline for.
Ask how long recordings and transcripts are retained and whether the period is configurable.
The vendor supplies no data and says what it will not do with the customer's, which is the better half of this axis.
Everything the product works on originates with the customer: Salesforce records they already own, calls their own people hold, emails their own people send. Two passes located no contact database, no enrichment offering, no lookup credits, no profile count and no third party data supplier. A buyer inherits no pool of unknown origin and no licence they cannot see.
What lifts this above a bare absence is that the vendor addresses its own use of customer material explicitly rather than leaving it to inference. It states that no customer data is used for any model training, that inputs are not stored or linked to personal identifiers, and that it will never sell customer data. Those are affirmative commitments about the most valuable asset the product touches, which is the accumulated record of what customers actually said on calls.
The ceiling is what happens in aggregate. The vendor commits to collecting the minimum needed and offers an opt out, but two passes located no statement covering whether de identified or aggregated transcript material informs product development, benchmarking or prompt tuning across the customer base.
For a product built on conversation data that question is worth asking directly.
Ask whether aggregated or de identified call content is used for product development.
Every surface this product touches is one it is licensed to touch, and the integration model is the sanctioned one throughout.
Authentication runs through Salesforce's own delegated authorisation, with the vendor stating explicitly that this lets a team connect without entering login credentials into its system. Distribution includes a managed package an administrator provisions per user profile, which is the platform's supported extension mechanism rather than a workaround. The application is built on a platform owned by Salesforce itself. Single sign on works with standard identity providers.
Conferencing and mail connections use the published integrations for each platform, and the browser extension operates over the customer's own Salesforce rather than a third party site the vendor does not own.
Two passes located no scraping, no social network automation, no unofficial interface use, no credential storage and no capability whose operation depends on a platform not noticing. In a sweep where several records this week were built on exactly those practices, this one carries none of them.
The residual risk is concentration rather than violation. The product exists to make one platform tolerable, that platform now ships competing native functionality and its own agent layer, and there is no second system of record to fall back to.
Ask what the position is if the platform's native agents absorb the field update layer.
The provider tier was chosen for its data handling, and the engineering practice around it is documented in detail.
On the model side: an enterprise tier purchased specifically so queries are not stored and no customer data trains the provider's models, real time processing with no linkage to personal identifiers, and outputs displayed to the end user rather than applied silently. Permission controls govern who may build and deploy agents, prompt governance controls which prompts run and who may edit them, and prompt usage and performance are tracked so drift is visible.
On the stewardship side the record is thorough. Continuous network vulnerability testing runs alongside independent third party penetration testing contracted at least annually. Disaster and incident response plans are maintained, tested and audited annually. A status page publishes incidents and scheduled outages. A vulnerability disclosure policy exists with a contact route and a stated commitment to resolve quickly. Employees and contractors take security awareness training at hire and annually, developers additionally receive secure development lifecycle training covering the standard top ten coding vulnerabilities, and deployment runs through version control, code review and both automated and manual testing.
The gap is measurement of the output rather than of the process. No accuracy figure, error rate or evaluation covers suggested field updates, and those updates populate the system of record that produces the forecast.
Ask what happens downstream when an agent writes a wrong close date or next step.
Nothing here contacts a stranger, and something here joins their meeting.
On the outbound reading the axis does not apply. The product sends no prospecting messages, adopts no persona, generates no sender identity and answers no replies. Two passes located no outreach capability, and undetectability appears nowhere as a concept, let alone a selling point. A buyer comparing this against records built earlier this week should register that difference rather than read the grade as a criticism of restraint.
Where the axis does bite is the recorder. The vendor ships a desktop application and a bot that capture calls across three conferencing platforms, transcribe them and generate summaries. The person on the other side of that call is the analogous recipient, and what they are told is undescribed.
Two passes located nothing on whether the bot appears in the participant list, under what name it appears, whether an announcement is made when recording begins, whether the external party can decline, or whether an administrator can restrict recording by region or by counterparty type. Products in this category vary widely on all of these and the differences matter to the person being recorded.
The grade reflects a real and unanswered disclosure question rather than an absent one.
Ask what an external participant sees and hears when the recorder joins their call.
The connected surface is well chosen and the programmable surface is absent.
What connects: Salesforce at maximum depth through a managed package, delegated authorisation, inherited configuration and support for multiple record type layouts rather than the default alone. Conversation capture works with a leading revenue intelligence recorder as well as the two main conferencing platforms and the vendor's own notetaker, with a third platform noted as coming. Mail integration covers both dominant providers. Team messaging carries alerts and deal rooms with the second platform in progress. A browser extension extends the workspace to wherever the seller is, and single sign on works with standard identity providers.
The company has also published a machine readable file describing itself for language models and launched an adjacent product positioned as a context layer for three named third party assistants, which shows the direction of travel.
What is missing is anything a developer could build on. Two passes located no public interface documentation, no authentication scheme for external callers, no webhooks and no model context protocol server, which stands out in a sweep where five other vendors shipped the last of those. A published customer review flags the integration ecosystem as the product's weak point.
One integration is tiered rather than universal, with the revenue intelligence recorder available only from the middle plan upward.
Ask whether hygiene and prompt usage data is reachable programmatically outside the interface.
The hosting is named specifically and the residency has exactly one option.
What is stated: multi tenant software as a service hosted on a named public cloud on servers located in the United States, with the application itself built on a platform owned by Salesforce. Backups run daily and are encrypted. Disaster and incident response plans are maintained, tested and audited annually. A status page publishes current platform state, incidents and scheduled outages.
Naming both the underlying cloud and the application platform, and stating the server location as fact rather than implying it, puts this ahead of most records in this index, where deployment is frequently described as nothing more than software as a service.
The limitation is that the single option is presented as a fact rather than as a choice. A buyer in the United Kingdom or the European Union with a residency requirement finds no region selection, no alternative hosting arrangement and no statement acknowledging the constraint, and two passes located no self hosting or private deployment path.
The artefacts this product creates rather than reads deserve their own answer and do not get one. Where call recordings and transcripts are stored, and whether they follow the same residency as the workspace data, is not addressed anywhere.
Ask whether any European hosting option exists and where recordings are stored.
An audit over a period, a dedicated trust portal, and a security page that describes practice rather than posture.
The attestation is a service organisation control report of the type covering operating effectiveness across a period rather than design at a point in time, stated with continuous monitoring alongside it, plus stated alignment with two privacy regimes. A trust portal runs on its own subdomain, and a security page sits beside it in the site footer under company rather than buried.
What that page contains is the reason for the grade. Encryption in transit and at rest under a named standard with described key management. A stated password policy. Least privileged access with regular audits. Staff access logs retained at least twelve months and attributable to an individual. Daily encrypted backups. Continuous network vulnerability testing plus independent third party penetration testing contracted at least annually. Incident and disaster response plans tested and audited annually. A maintained subprocessor list. Security awareness training at hire and annually, with secure development lifecycle training and named coding vulnerability coverage for developers. Version control, code review and both automated and manual testing before deployment. A vulnerability disclosure policy with a contact route.
The company also carries a named information security and data privacy officer.
What the public page omits is the audit period, the auditor, and the process for requesting the report, all of which presumably sit behind the trust portal.
Ask for the audit period, the auditor and the most recent penetration test summary.
This vendor publishes the burn rate of its own meter, which almost nobody in this index does.
Four tiers carry figures: a free plan with its limits enumerated exactly at three views, ten hours of recording a month and 100 credits per user, a solo plan at 19 dollars monthly billed yearly or 24 monthly, a team plan at 49 or 62 on the same basis, and a custom enterprise tier. Showing both billing bases side by side lets a buyer compute the annual discount rather than infer it. A feature matrix runs across all tiers, and credit allowances are stated per tier both annually and monthly.
The consumption disclosure is the exceptional part. Each action carries a published rate: one credit for a single call field update suggestion, five for a multi call suggestion, one for a call summary, one for a call level question and five for a record level question. A worked example then estimates monthly consumption from a stated call and update pattern. Elsewhere in this index credit model vendors publish the allowance and conceal the rate at which it depletes, which makes the allowance meaningless; this one publishes both and does the arithmetic for the reader.
Running out is addressed with three named options, credits are stated to reset each cycle, and pooling is stated as available only from the middle tier. The vendor states plainly that there are no platform fees, no setup costs and no minimums.
What is not published: the price of additional credits, the enterprise band, and the rate for the services engagement.
Ask what additional credits cost once an allowance is exhausted.
The data a customer cares about was never held here, and the data this product creates has no described exit.
The structural position is strong. Records live in the customer's own Salesforce org throughout, with the vendor writing into it rather than maintaining a competing system of record. Opportunities, fields, notes and history therefore remain in place when the layer is removed, and the managed package can be deprovisioned per user profile rather than torn out wholesale. The vendor states outright that it will never sell customer data or hold it hostage, and separately that customers may opt out of data collection, both of which are anti lock in commitments rather than marketing lines.
The gap concerns the artefacts the product generates. Call recordings, transcripts, generated summaries, prompt libraries and the hygiene and prompt performance history accumulate inside the vendor rather than inside Salesforce. Two passes located no export mechanism for any of them, no format, no scope statement, no deletion timeline after cancellation and no interface for programmatic extraction.
For a team that has spent two years building a prompt library and accumulating conversation history, that is the asset most worth taking and the one least addressed.
Commercially the exit is clean, with monthly billing available on the published tiers and no stated minimum.
Ask what happens to recordings, transcripts and custom prompts when the subscription ends.
The product sends nothing, and the grade should be read as scope rather than as failure.
Mail integration exists for both dominant providers, and its purpose is to read messages for context and log activity against records. Two passes located no sequence builder, no campaign function, no contact list, no sending volume, no mailbox rotation and no warmup, because none of those belong in a workspace whose job is keeping a system of record accurate.
What matters for calibration is that the vendor makes no claim in this territory either. There is no volume figure, no deliverability boast, no promise about limits and no marketing of sending capability of any kind. In a sweep where two vendors this week advertised the absence of daily sending limits as a benefit, a product that neither sends nor claims to send occupies a different position entirely, and the mid band grade records an axis that does not engage rather than one that is failed.
The one adjacent surface is alerting, where hygiene notifications and deal room updates reach internal users through team messaging rather than external recipients through mail.
A reader comparing this grade against a vendor sending at campaign scale with no discipline described should treat them as measuring different things.
Ask whether any customer facing message can originate from the product rather than from the seller's own mailbox.
The prerequisite is absolute and stated, and the range above it is genuine rather than nominal.
A buyer must run Salesforce. Everything about the product assumes it, from the managed package to the inherited permissions to the record type layout handling, and the vendor never pretends otherwise. That single condition disqualifies a large share of the market cleanly and early.
Above that line the coverage is real. The tier structure runs from a free plan usable by one person through a solo plan, a team plan and a custom enterprise arrangement, and the free plan is functional rather than a trial, carrying working views, recording hours and a credit allowance. Roles are named specifically as sellers, sales leaders and revenue operations, and the hygiene and adherence features are built for the second and third of those rather than the first.
Process support is named where it counts. Several common qualification methodologies are supported by name, which tells a buyer whether their own framework is covered rather than leaving them to ask.
What is missing: no industry vertical is named, no geography is stated, and United States only hosting implies a market boundary the vendor never acknowledges. One integration being gated above the entry tier segments buyers in a way the positioning does not discuss.
Ask which markets are supported for customers with non United States data requirements.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
| Entry Price | Pricing Basis | Data Processing Terms | Implementation | Source |
|---|---|---|---|---|
|
Free tier available; Solo at 19 dollars per user monthly billed yearly, or 24 monthly
$19 baseline
|
Per user subscription metered in artificial intelligence credits, with monthly and annual billing published side by side across four tiers. A free plan carries three views, ten recording hours monthly and 100 credits per user monthly. Solo is 19 dollars per user monthly billed yearly or 24 monthly, carrying 4,800 credits per user annually or 400 monthly. Team is 49 dollars per user monthly billed yearly or 62 monthly, carrying 9,600 credits per user annually or 800 monthly, and adds pooled credits shared across the team, advanced workspace permissions for building and deploying agents, prompt insights, the hygiene monitor, the revenue intelligence recorder integration and access to a services engagement. Enterprise is custom with unlimited credits. Credits reset each billing cycle, and additional credits may be purchased on any paid tier at an unpublished rate. An existing Salesforce subscription is a prerequisite and a separate cost. | The vendor publishes a service organisation control report of the operating effectiveness type with continuous monitoring alongside, states alignment with the European and Californian privacy regimes, and maintains a current list of third party subprocessors. A privacy policy and terms of service are published, and a trust portal runs on its own subdomain. Commitments stated on the security page include encryption in transit and at rest under a named standard with described key management, least privileged access with regular audits, staff access logs retained at least twelve months and attributable to an individual, daily encrypted backups, data minimisation with a stated customer opt out, and an explicit undertaking never to sell customer data. No retention schedule was located for call recordings, transcripts or generated summaries, and the subprocessor list and privacy policy were not opened in this pass. | None charged. The vendor states directly that there are no platform fees, no setup costs and no minimums. The product is self serve from a functional free tier, connects to Salesforce through delegated authorisation without a configuration project, and ships as a managed package an administrator provisions per user profile rather than as an all or nothing deployment. An optional white glove engagement called Agent Services is offered on the middle and enterprise tiers, covering one to one work with the vendor's specialists to design, build and test agents matched to a customer's sales process and data, including prompt creation and ongoing improvement. It is marked available with no price published. A separately branded services arm operates alongside the product and is linked from the site navigation. | Vendor Published |
The distinguishing disclosure is the credit burn rate, published per action with a worked example. Across this index, credit model vendors routinely publish an allowance and withhold the rate at which it depletes, which renders the allowance uninterpretable. This vendor publishes both.
Published consumption rates: one credit per single call Salesforce field update suggestion, five credits per multi call field update suggestion, one credit per call summary, one credit per call level question, and five credits per record level question against an opportunity or account. The worked example estimates roughly 800 credits monthly for a seller averaging five calls a day with four field updates per call at a mixed rate, which maps that seller onto the middle tier's allowance and lets a buyer size the plan before purchase.
Also published: both monthly and annual pricing shown side by side so the annual discount is computable rather than implied; a full feature matrix across tiers; free plan limits enumerated exactly at three views, ten recording hours monthly and 100 credits per user monthly; three named options when an allowance is exhausted, being upgrade, add credits or wait for the cycle reset; a statement that credit pooling across a team is available only from the middle tier upward; and a statement that credits reset each billing cycle. The vendor states there are no platform fees, no setup costs and no minimums.
What is withheld: the price of additional credits, which matters because adding them is one of the three stated remedies for exhaustion; the enterprise band, which carries unlimited credits and is quoted only as custom; and any rate for the white glove services engagement covering agent design, setup and performance tuning, which is marked available on the middle and enterprise tiers without a figure.
One structural cost sits outside the licence entirely and is not mentioned: the product requires an existing Salesforce subscription, which is a separate and larger expense for any buyer.