For CRM & retention teams

Bring permissioned customer intelligence into the systems you already own.

Customer Intelligence is designed to help brands use approved, consented customer attributes in CRM and brand-owned AI workflows, while keeping permission, provenance and revocation visible.

Permission is established by the shopper, not the brand.Attributes follow the approved data model. read the privacy position

◍ herm · permissioned data flow Illustrative attribute · subject to approved data specification

shopper-initiated connection · brand-owned destination · Acme

  1. 01
    Shopper

    A person with an existing Herm consumer relationship.

    holds the permission
  2. 02
    Customer connection

    The shopper explicitly permits the relevant brand connection through Herm.

    explicit · scoped · revocable
  3. 03
    Herm

    Checks the permitted scope and derives only what the data model allows.

    derivation happens here
  4. 04
    Approved attribute

    A defined attribute and value, carrying its permission state and provenance.

    the only thing that travels
  5. 05
    Brand CRM · brand-owned AI

    An approved CRM field or a brand-operated AI-enabled experience.

    brand-owned destination
What enters the brand system defined by the data model
  • Approved derived attributes defined by the Customer Intelligence data model
  • The permission state that supports each attribute
  • A provenance reference for where the attribute was derived from
  • The date the attribute was last updated
What does not outside the permitted scope
  • Unrestricted access to a shopper's full Herm history
  • Any attribute where the required permission does not exist
  • Attributes whose permission has been revoked by the customer
  • Herm's internal model reasoning

Boundary The exact contents of both columns follow approved Herm product and legal definitions. Where a specific attribute is not yet specified, this page labels it as illustrative rather than stating it as a product capability.

02The customer-data gap

Your CRM sees the relationship you have. It does not always see the wider buying context.

A customer may buy through multiple retailers, marketplaces and channels. Brand-owned data can describe the direct relationship well while still missing signals that exist elsewhere in the customer's purchasing life.

Herm's consumer relationship creates the possibility of adding new context only when the shopper has explicitly permitted the relevant brand connection.

Brand view · known today
  • Direct orders
  • Email engagement
  • Loyalty activity
  • Known product ownership

Owned, governed and already in the customer record.

Wider context · not visible to the brand

Conceptual. Nothing here is available to a brand, and nothing here is transferred as raw purchase history.

After an explicit customer connection Illustrative attribute · subject to approved data specification
Discount-responsiveApproved attribute · to be specifiedApproved attribute · to be specified

A small number of approved derived attributes, not an external purchase history. The permitted set is defined by the Customer Intelligence data model, and each attribute carries its permission state.

03How the connection works

Permission should be part of the product, not hidden in the policy.

Five explicit stages. Each stage depends on the permission established in the one before it.

Connection lifecycle · permission → derivation → controlled use → revocation the shopper starts it and the shopper can end it
  1. 01 Consent

    Shopper chooses to connect

    The shopper deliberately establishes the relevant relationship with the brand through Herm.

    Who controls this shopper
  2. 02 Scope

    Herm checks the permitted data scope

    Only information allowed by the approved product and consent model should participate.

    Who controls this approved data model
  3. 03 Derivation

    Herm derives approved attributes

    The brand receives only the approved outputs defined by the Customer Intelligence data model.

    Who controls this Herm, within scope
  4. 04 Controlled use

    The attribute enters a brand-owned system

    For example, an approved CRM field or brand-owned AI workflow.

    Who controls this brand
  5. 05 Revocation

    Permission remains manageable

    The customer should be able to revoke the relationship according to the approved Herm data model.

    Who controls this shopper
The mechanism is the proof Nothing in this sequence depends on a general assurance that the platform is secure. Each stage is a specific step your data and privacy stakeholders can review against the approved Herm data model.
04With better context

Use new context where it improves an owned customer experience.

Each use case is a new input into a decision the brand already makes and already owns.

  • Lifecycle understanding

    Recognise change

    Recognise when the customer's purchasing context may have changed, using attributes the customer has permitted.

    New input
    approved derived attribute
    Brand-owned decision
    lifecycle stage and timing in your own programme
  • Segmentation

    More relevant groups

    Create more relevant customer groups using approved derived attributes alongside your existing segmentation.

    New input
    approved derived attribute
    Brand-owned decision
    segment definitions held in your CRM
  • CRM orchestration

    Owned journeys

    Use permitted attributes alongside existing brand-owned customer data in journeys you already operate.

    New input
    permitted attribute in an approved field
    Brand-owned decision
    journey entry, suppression and content
  • Brand-owned AI

    Your assistant

    Make approved customer context available to an assistant or AI experience operated by the brand.

    New input
    permitted context, permission state included
    Brand-owned decision
    what your own assistant says and offers
Brand-owned, not everywhere.

Be Relevant requires the brand to enable the Customer Intelligence connection. The rung scores the brand's own surfaces, its site assistant and its CRM. It does not measure, and Herm does not influence, what a frontier AI assistant recommends to an individual shopper.

05Provenance, not a black box

Every useful attribute should have an understandable provenance.

A CRM team should be able to open any attribute and answer two questions: where did this field come from, and what permission allows my company to use it?

Permission state · active Illustrative attribute · subject to approved data specification Fig. 01 · attribute detail
Customer Intelligence · Attribute detail
Customer c-40118 · permission read at request time
Attribute Discount-responsive
Permissioned
status
Permissioned active customer connection
derived from
Verified receipts per approved specification
shared as
Defined attribute and value not raw records
last updated
04 Sep 2026 09:14 example timestamp
permission
Active read at request time
raw purchase history shared
No according to approved specification
revocable
Yes according to approved product policy
Attribute type Derived Not a copy of a source record.
Permission Active Checked when the attribute is requested.
Destination Brand-owned Approved CRM field or brand AI workflow.
Derivation trail
  1. Customer connection established shopper-initiated, brand-specific, example reference
  2. Permitted scope checked attributes outside the approved scope do not participate
  3. Attribute derived output defined by the Customer Intelligence data model
  4. Delivered to the approved field brand-owned destination, permission state travels with it
Revocation

The customer can withdraw this connection according to the approved Herm data model. Withdrawal is reflected in the attribute state rather than left to a manual process.

Never shared
  • Payment details & card stays with you
  • Full purchase history never sent
  • Identity & contact never sent
Field names, values and states shown here establish the interface structure. Each is replaced by the approved data specification before implementation.
06Capabilities and boundaries

Customer Intelligence should make its boundaries as clear as its capabilities.

Stated here so a data stakeholder does not have to infer it later.

Herm Customer Intelligence can
  • Provide approved derived customer attributes where the required permission exists.
  • Make those outputs usable in approved brand-owned systems.
  • Preserve provenance and permission state alongside every attribute.
Herm Customer Intelligence does not
  • Give a brand unrestricted access to a shopper's full Herm history.
  • Imply access to hidden model reasoning.
  • Personalise independent frontier AI systems such as ChatGPT on the brand's behalf.
  • Override the shopper's permission.
07Where this fits in Herm

Customer Intelligence is the readiness dimension for context you control.

Customer Intelligence is the readiness dimension concerned with using permissioned customer context inside systems the brand controls. It is separate from measuring how public AI systems talk about the brand.

  • Be Visible Brand Visibility Live Does AI know and recommend you?
  • Be Sellable Product Readiness Live Can AI actually complete the recommendation: specs, price, stock, where to buy?
  • Be Relevant Customer Intelligence Live Are your own experiences right for the shopper in front of them?
  • Be Preferred Offers Live Do the shoppers who buy your category buy you, and keep buying you?
08Trust

The data model is part of the product.

A CRM team should be able to understand what data enters the system, where it came from and what permission supports its use before implementation begins.

The data-flow specification, the consent model and the security documentation are reviewed with your data and privacy stakeholders during evaluation. They are not published here, and this page makes no compliance claim in place of them.

See whether Herm Customer Intelligence fits your data model.

Review the connection, the permitted outputs and how they would enter your existing CRM or brand-owned AI environment.

starts with
A review of the connection model and the permitted outputs
you evaluate
Which approved attributes could enter which brand-owned system
stays with the shopper
The permission, and the ability to withdraw it
to validate
The approved data specification, before any implementation