---
ref: workflow:support-expansion-signals
title: Flag expansion asks in support tickets for account owners
author: thedogwiththedataonit
tools: [tool:zendesk/search, tool:typesafe/answer-typed-questions, tool:hubspot/search-crm-records, tool:hubspot/create-note, tool:slack/find-user-by-email, tool:slack/post-message]
tags: [capability:classify-signals, capability:manage-crm, capability:route-alerts, capability:search-conversations, channel:chat, has:api, motion:retention]
updated: 2026-09-29
---

# Flag expansion asks in support tickets for account owners

Finds new Zendesk tickets that ask for seats, SSO, higher limits or another team with Jev, and notes each in HubSpot for its owner.

Set up the tools below, then run the steps in order for the user, carrying each step's results into the next. The run is done when the user has the outcome below.

## Outcome

- A table of every new ticket that asks for more, with what kind of expansion it is, its company and Jev's confidence.
- A note on each company's HubSpot record quoting the ask.
- A Slack post for each expansion ask that mentions the company's owner.

## Inputs

Ask the user for these before you start.

- `since`: when the last run started, as a time, so only newer tickets are read, e.g. 2026-09-28T09:00:00Z
- `min_confidence`: how sure Jev must be before its answer is used without you, e.g. 0.8; a yes-or-no answer counts as yes at or above it and as no at or below 1 minus it
- `am_channel`: the Slack channel account managers watch, e.g. #expansion

## Set up

### Search tickets, users and organizations (Zendesk, tool:zendesk/search)

Use the API.

- Base URL: https://{subdomain}.zendesk.com
- Endpoint: `GET /api/v2/search?query={query}`
- Auth: send the header `Authorization: Bearer $ZENDESK_OAUTH_TOKEN`
- Get a key: https://developer.zendesk.com/documentation/authentication/oauth-migration/#getting-your-first-token

Note: `{subdomain}` is your Zendesk subdomain, as in `acme.zendesk.com`. Tokens from OAuth clients created since April 30, 2026 expire after 30 minutes.

Note: Returns at most 1,000 results per query and 100 per page; for more, use `GET /api/v2/search/export`.

### Answer typed questions (TypeSafe AI, tool:typesafe/answer-typed-questions)

Use the API.

- Base URL: https://api.typesafe.ai
- Endpoint: `POST /v1/systemone`
- Auth: send the header `Authorization: Bearer $TYPESAFE_API_KEY`
- Get a key: https://console.typesafe.ai

Note: Put every question about one record in one request. `GET /v1/models` lists the models and is the cheapest check of a key; a request over the rate limit gets a 429 with a Retry-After header.

Note: Send `state`, `model` (`jev-latest`) and named `questions`, each with `type`, `instructions` and `criteria`: a choice maps labels to descriptions, a score lists its levels in order, a noul's is optional. Read a score by its most likely level; send unsure answers to a person.

### HubSpot (tool:hubspot/search-crm-records, tool:hubspot/create-note)

For each call, use the first option your agent supports that lists it.

Notes:

- Search CRM records: The MCP tool takes up to five groups of six filters and returns up to 200 records per page.
- Create a note: `hs_timestamp` is required; attach the note to existing records with an `associations` object.

#### MCP (official, remote)

Add this server to your agent's MCP settings, then sign in when asked.

```json
{ "mcpServers": { "hubspot": { "url": "https://mcp.hubspot.com" } } }
```

- Search CRM records: call the MCP tool `search_crm_objects`

#### API (official)

- Base URL: https://api.hubapi.com
- Search CRM records: `POST /crm/objects/2026-09/{objectType}/search`
- Create a note: `POST /crm/objects/2026-09/notes`
- Auth: send the header `Authorization: Bearer $HUBSPOT_API_KEY`

Note: Use a service key or an app's static access token with the CRM scopes the calls need; paths carry a dated version such as `2026-09`.

### Slack (tool:slack/find-user-by-email, tool:slack/post-message)

Use the first option your agent supports.

Notes:

- Find a user by email: Needs the `users:read.email` scope; a deactivated user returns `users_not_found`.
- Post a message: Needs the `chat:write` scope. Over MCP it posts as the signed-in user; the API and CLI post as the app's bot.

#### MCP (official, remote)

Add this server to your agent's MCP settings, then sign in when asked.

```json
{ "mcpServers": { "slack": { "url": "https://mcp.slack.com/mcp" } } }
```

- Find a user by email: call the MCP tool `slack_search_users`
- Post a message: call the MCP tool `slack_send_message`

#### CLI (official)

Install the command, then confirm it runs.

```sh
curl -fsSL https://downloads.slack-edge.com/slack-cli/install.sh | bash
slack --version
```

- Find a user by email: run `slack api users.lookupByEmail`
- Post a message: run `slack api chat.postMessage`

Set `$SLACK_BOT_TOKEN` in your environment first (get a key: https://api.slack.com/apps).

Before step 1, confirm access to each service with its cheapest read-only call, like a list or a search. Never send or change anything to test access.

## Steps

1. **Pull new tickets** with Search tickets, users and organizations (Zendesk). Search for tickets (`type:ticket`) created after `since`. Keep each ticket's ID, subject, description and requester ID.
2. **Spot the asks** with Answer typed questions (TypeSafe AI). Send each subject and description as the state, with a noul `expansion` (asks for something that means buying more), a choice `kind` of more_seats, sso_or_security_review, higher_limits (more usage than the plan allows), new_team_or_use_case, api_access, plan_upgrade and none, and a score `readiness` on three levels (asking what is possible; comparing plans; ready to buy). Keep every answer with its confidence or probability.
3. **Check the unsure ones with the user** yourself. Keep the tickets whose `expansion` is yes. Show the user the ones whose `expansion` is unsure or whose kind confidence is below `min_confidence`, and keep what the user decides. Look up each kept ticket's requester email, a read-only call.
4. **Find the account** with Search CRM records (HubSpot). Search companies by each requester's email domain, skipping personal email domains. Keep the company's record ID, name and `hubspot_owner_id`, and look up each owner's name and email, a read-only call. Note the tickets with no match.
5. **Note the ask** with Create a note (HubSpot). After the user approves, add a note to each company quoting the ticket's ask, with its kind, readiness and ticket ID.
6. **Find the owners in Slack** with Find a user by email (Slack). Look up each owner's email. Keep their Slack user ID.
7. **Alert the owner** with Post a message (Slack). Post each ask to `am_channel`, mentioning the company's owner, with the company, the kind, the readiness and the ticket's first line, the most ready first.

## Notes

Support still answers every ticket; a question like "can we add SSO before the security review" also reaches the person who owns the renewal.

Run it daily with `since` set to the time the previous run started.

## Rules

- Use only the services set up above. The read-only calls they need, like listing ids or polling for results, are fine.
- Ask the user before anything that sends messages, costs money, or changes data, and say how many records it touches. One approval covers a batch the user has seen.
- Never print API keys.
