Tradecraft
You have now read all seven playbooks, and each one delegated its mechanics to this chapter. Here is why: every public-signal playbook runs on the same underlying pipeline. The signal arrives, the junk is stripped out, the search expands, the right human is found, an address is obtained and verified, the note goes out, and the work is logged. This chapter specifies that pipeline once, honestly, with the software named at every stage, so the playbooks themselves could stay about judgement.
If you skip this chapter, the sample messages in the playbooks will still read well, but you will not actually know how to execute, and the gap between those two states is where most good intentions die. Read it with one real job posting or role change open beside the book, because every stage below is written to be runnable without guessing.
Minutes you will feel
Setup is about an hour once. Steady state for a serious hiring week is roughly ninety minutes of monitoring plus about forty-five minutes per live target you take all the way to a sent note. The hour figures on the playbooks are built from those numbers. If your arithmetic does not match a playbook’s claim, trust the stage minutes here and re-check the playbook.
What follows is not a recommended shopping list. It is an honest inventory of the software a working public-signal system usually needs when you run it yourself. No single product covers every stage. Each seat is another login, another credit balance, and another thing that stops working the month you get busy.
1. Set up monitoring so the signal arrives
A one-off search is not a system. You need boards and alert tools to push candidates into a single place on a fixed cadence.
Which surface each playbook actually reads:
- Playbooks 03–06 (hiring set): LinkedIn Jobs as the daily default. LinkedIn Sales Navigator Jobs when you want tighter company-size, seniority, and posted-date filters. One secondary board your buyers use (Indeed or Totaljobs in the UK, Otta or Work in Startups for tech-heavy ICPs). Optional multi-source job feed such as TheirStack if you want one inbox across boards instead of five tabs.
- Playbook 04 (Sideways) and Playbook 07 (New In Role): job-change and “started new position” signals more than static job ads. LinkedIn Sales Navigator’s job-change filters and saved searches do this by hand. Dedicated job-change products (Champify, UserGems) automate the same watch at a much higher subscription. Press and company blogs are secondary, not primary.
- Playbook 02 (Lookalikes): not a job board. LinkedIn company search, then people search. Lookalike and firmographic tools (Ocean.io, Apollo’s company search) speed the list once you have the pattern.
- Playbook 01: your own LinkedIn export and inbox. No monitor stack required.
Software you are actually logging into: LinkedIn (free Jobs + People), LinkedIn Sales Navigator Core for serious filters and job-change views, one secondary board with email alerts turned on, optionally TheirStack for aggregated job intent, optionally Champify or UserGems if Playbook 07 is your main motion and you refuse to miss role changes. Google Alerts on a few distinctive phrases is free and still useful as a backstop. Company career pages only for a short target-account list.
Saved searches and alerts, once:
- Title patterns you sell to, or the adjacent titles that trigger your playbook (keep the list under eight strings).
- Date posted: last 24 hours for the alert, last 7 or 14 days when you review the backlog.
- Company size band you can serve (for example 11–50, 51–200, 201–500).
- Geography you will actually travel to or serve remotely.
- Experience or seniority filters that match the playbook (senior for Fractional Fit, mid for Leadership Gap, junior for Outsource).
Turn on email or in-app alerts for each saved search. Name the search after the playbook angle, not after a vague keyword, so Thursday-you knows why Monday-you saved it.
Cadence: two fixed blocks, forty-five minutes each, Monday and Thursday. That is the monitor. Do not “check when free.” In each block: open alerts, walk the new posts top to bottom, classify or skip, and write keepers into the sheet. You are not writing outreach in this block.
One collection place: a single sheet (Google Sheets or Excel) or a lightweight CRM table shared across every public-signal playbook. Minimum columns for monitoring:
- Date seen, source board, posting URL
- Company (or “agency / client hidden”)
- Role title, playbook angle (02–07), keep or bin
- One public fact you will use if you write
- Status: new, expanded, contacts found, address ready, drafted, sent, replied, closed
Stage time: about 60 minutes one-time setup. About 45 minutes per review session. At two sessions a week that is 90 minutes of standing watch, every week you run a public-signal playbook.
2. Strip out recruiters and agencies
Agency noise is the largest time sink on a job board. The filter is not an attack on recruiters. It is a speed rule: you need a named company you can research, and a human inside it whose problem you can name.
Bin in about fifteen seconds when you see:
- Posting company is clearly a staffing or search firm, and the client is “confidential,” “our client,” or unnamed.
- Language built for candidates only: “CV,” “salary banding on application,” “immediate start,” “my client is looking,” with no product, market, or org detail you could verify.
- The same advert text under three different agency names in one week.
- Company page has no employees, no product, no site that matches the claim, or a generic “recruitment” about line.
Try to unmask before you bin when: the role is a rare fit and the description has distinctive product or stack detail. Search a unique sentence from the body in quotes (stage 3 does this properly). If the true employer surfaces, treat it as a company-posted signal. If nothing surfaces in two minutes, bin and move. Do not spend a research hour on a ghost client.
Playbooks 03 through 06 all use this filter. Playbook 05 and 06 are not exempt because the titles look junior. An agency-hidden bookkeeping seat is still a hidden company.
Stage time: most posts are a fifteen-second call. Ambiguous ones take one to two minutes. Budget about 0.5 minutes average across a full board pass, inside the monitor block.
3. Expand the search from the posting copy
This is the single most valuable move in the whole pipeline, and the one most operators never run. One distinctive sentence turns a single listing into a cohort.
Procedure:
- Open a keeper posting. Copy one sentence that is specific enough that a generic template would not contain it (a product claim, an unusual stack, a phrase about “first senior hire in X,” a metric, a location hybrid line that is oddly precise). Avoid pure clichés (“fast-paced environment”).
- Paste it into a web search in quotation marks. Run the search.
- Skim the first page of results and sort what you get into three buckets.
What the three returns are worth:
- Same role, other boards. Often reveals the employer when LinkedIn only showed an agency, or shows a richer applicant-tracking page with location, salary band, or team detail the board stripped out. Update the company field and the URL on your sheet.
- Same description at other companies. Whoever wrote the brief copied it, or a recruiter re-used a template across clients who share a problem shape. Each extra company is a ready-made lookalike for this week’s playbook. Add them as new rows with the same playbook angle and the shared sentence as your public fact.
- Original ATS or careers page. Usually more text, a hiring-manager name, or a team paragraph. Harvest anything that improves the observation you will send. Prefer this URL as canonical.
Stop after one strong sentence and one search page. If the sentence was too generic, pick a different line once. Then move to finding people. Expansion is not a research hobby.
Stage time: about 7 minutes per keeper you still intend to work. Skip expansion only when the company is already fully named, the careers page is already open, and you can see the org clearly without it.
4. Find the people who matter at the company
“Usually the CEO” is a starting guess, not a method. You need a way to enumerate who is there and pick the person whose problem the signal is about.
Software that enumerates an org:
- LinkedIn company People tab (included with a normal LinkedIn account). First pass for almost every company. Incomplete on small firms and on people who never update their profile.
- LinkedIn Sales Navigator (paid seat). Lead filters by current company, title, seniority, and geography. Required before the filters are useful at volume. Free LinkedIn will not replace it for weekly pipeline work.
- Apollo (paid). Company and people database with title filters and often a direct path into an email waterfall. Stronger on some regions and industries than others. A miss is not proof the person is absent.
- RocketReach or Lusha (paid, credit-based). Useful when LinkedIn shows the human but not enough contact data. Credit packs usually expire on a monthly or annual clock whether you finished the list or not.
- Wiza (paid, credit-based). Works on a LinkedIn or Sales Navigator list rather than one profile at a time, and returns verified addresses with the export. This is the tool that turns Playbook 01's connections file, or a saved search of forty companies, into something you can actually write to. Another subscription, and it does not remove the verification step.
None of these is a full org chart. You still read the list and apply judgement. Enterprise directories such as ZoomInfo exist above this tier if you are buying for a team. A boutique firm rarely needs more than one seat for the playbooks in this book.
Enumerate the org:
- Open the company on LinkedIn. Use the People tab. Filter by current company. Sort or scan by seniority keywords: Chief, VP, Head, Director, Founder, Partner.
- If the company is small (under ~40 people), read the whole people list. It is faster than guessing.
- Cross-check the company website team or about page when LinkedIn is thin.
- Note who posted the job if LinkedIn shows a face. That person is often an HR partner or the hiring manager. They are a participant, not always the buyer.
Title ladder for “whose problem is this?” Start from the function named in the signal. Walk up until you hit the most senior person who owns that outcome and still sits close enough to feel the pain. Examples: a Head of Marketing hire with no senior marketer above them points at the CEO or founder. A Marketing Manager hire under a vacant Head seat points at the CEO (strategy layer) not the manager candidate. A junior data clerk points at Head of Ops or Finance. A new Head of Sales with no demand counterpart points at that Head of Sales first, CEO second.
Decision-maker vs participant: a decision-maker can approve budget or stop a hire. A participant feels the pain or screens CVs. Prefer the decision-maker for the first note when the playbook is commercial (03–06). Prefer the newly hired leader when the playbook is Sideways or New In Role and they hold the mandate. If the only visible senior is pure HR with no business title, keep looking for a founder or function lead before you write.
Second contact rule: one primary is the default. Add a second only when the playbook explicitly needs two seats (Sideways: new leader plus CEO) or when the primary is interim, outbound, or clearly not commercial. Two notes, two angles. Never the same paragraph twice.
Stage time: about 12 minutes per company you have not researched before. Small companies go faster. Enterprises go slower. If you cannot name a human in twelve minutes, bin the row and protect the week.
5. Get to an address: the waterfall
The book expects you to send. A work email is still the cleanest channel for a specific observation. Finding that email is where the stack multiplies.
Why a waterfall exists at all: each provider only holds part of the world, and the parts do not overlap neatly. Hunter may resolve a UK marketing director and miss a US ops lead. Apollo may be strong on one industry band and empty on a twenty-person firm. RocketReach may have the record and return it stale. Dropcontact may win on European formats and lose elsewhere. A single lookup that returns nothing does not mean the address does not exist. It means you asked one source. A waterfall is the sequence: ask source one, and only on a miss ask source two, because each call costs money or a credit.
Run cheapest and most certain first. Stop when you have one verified address. Do not run every tier on every name for sport.
The cascade, in order:
- Already known (free). Prior thread in Gmail or Outlook, calendar invite, proposal, newsletter reply. Sixty seconds. If it is there, stop.
- Pattern guess + verify (free or low-credit). If you already hold one good address at that domain (firstname.lastname@, first@, firstlast@), build the candidate from the LinkedIn name. Verify before you send (tier 7). Do not send an unverified guess.
- Public pages (free). Team page, press contact, author byline, podcast notes, conference bio. Rare for seniors. Free when it exists. Still verify.
- Hunter (Email Finder / Domain Search). Strong first paid finder for many professional domains. Good when the pattern is standard. Weak when the company uses a rare format or hides behind a catch-all. One credit-style lookup per person on most plans.
- Apollo. Often already open from the people stage. Different coverage graph from Hunter. Useful second source on a miss. Same rule: a miss is not proof of absence.
- Prospeo. Third paid tier, and the one most operators reach for when the target is on LinkedIn but nowhere else. You feed it the profile URL rather than a name and a domain, which is a different question to the one Hunter and Apollo answer, so it resolves people the first two tiers cannot see. Credit-based.
- Findymail. Fourth paid tier. Verification is built into the find rather than bolted on, so it returns fewer addresses and bounces less. Useful precisely when the earlier tiers gave you something you do not trust.
- Dropcontact or LeadMagic. Fifth paid tier, for the misses that are regional rather than obscure. Dropcontact is often stronger on European name-to-email patterns. LeadMagic charges on valid results rather than on lookups, which changes the maths when your hit rate is poor. Pick one as your fifth seat unless volume forces both. You are paying for non-overlapping coverage, not for a brand preference.
- Verify every candidate before send. NeverBounce, ZeroBounce, MillionVerifier, or Hunter’s own verifier. Invalid means do not send. Catch-all or risky means the mailbox server will accept anything, so “valid” is not proof a human is there. On catch-all or risky, prefer LinkedIn for first touch, or send only when the observation is strong and you accept a silent fail. Never blast five guessed names into a catch-all domain. An unverified guess can burn domain reputation you cannot un-burn.
- RocketReach or Lusha (deeper paid). Use when the target is worth it and every finder above has failed. Credit packs, another monthly balance, another interface. This is the tier where the middle stops feeling clever, because you are now five or six subscriptions deep to find one address for one person you have not spoken to yet.
- LinkedIn as fallback, not default. Connection note or Sales Navigator InMail when email fails or stays risky. Better for short observations. Worse for logging and longer threads. Email remains preferred when clean.
That is what “get an email” actually is: an ordered set of paid sources with different coverage maps, plus a verifier that decides whether you are allowed to hit send. One tool does not replace the cascade. Operators who pretend otherwise re-learn it the week a whole region comes back empty.
If you doubt that you need all of them, look at what the market built. There is a whole product category whose only job is to call the other providers for you. FullEnrich and BetterContact do not hold a database of their own. They chain fifteen or twenty finders in sequence, exactly as described above, and hand you whichever one hit. Those companies exist because a single source is not enough, and enough people learned that the hard way to make automating the cascade a business. You can buy one of those instead, which is another subscription and still charges you per lookup, or you can run the cascade by hand, which is the eight to fifteen minutes below. What you cannot do is buy one finder and be finished.
UK compliance, once: when you cold-email a named individual at their work address about a matter relevant to their job, the practical basis most operators rely on is legitimate interest under UK GDPR, with PECR in view. Keep the note relevant to their role, identify yourself clearly, offer an easy opt out, and do not use scraped consumer or personal addresses. If they opt out, stop. This is not legal advice. It is the operating standard this book assumes.
Stage time: about 8 minutes when tier 1 or 2 hits. Ten to fifteen minutes when you walk the paid cascade. Cap at fifteen. Then LinkedIn or bin.
6. Send, log, and follow up
Channel order: work email first when you have a clean address. LinkedIn second when email is missing, risky, or the person lives on the platform. Do not double-send the same text on both channels the same day. If you use both, wait for silence, then a shorter bump on the other channel that references the first.
Follow-up rule: one follow-up only on a public-signal playbook, four to six business days later, shorter than the first note, adding one new fact or offering to close the thread. Then stop unless they reply. A third chase is volume posture. Ceiling: two outbound touches total per person per signal.
Minimum log so the playbook survives delivery week (shared sheet, every public-signal playbook and Playbook 01):
- Date, person, company, title
- Signal source and playbook number
- Channel used, address or profile URL
- One-line observation you sent
- Status and next date
- Outcome when it lands (replied, meeting, no, later)
Log the same day you send. A sheet updated weekly is a diary. A sheet updated at send time is a system.
Stage time: about 3 minutes to send and log. About 5 minutes for the single follow-up when it comes due.
Add it up: hours
Per live target you take from keeper to sent note, after monitoring has already surfaced the row:
- Expand: ~7 minutes
- Find people: ~12 minutes
- Waterfall: ~8 minutes (longer when the cascade runs deep)
- Draft (playbook-specific): ~10 minutes
- Send and log: ~3 minutes
- One follow-up later: ~5 minutes
About 45 minutes per live target. Add the standing monitor: ~90 minutes a week when a public-signal playbook is your main motion. Five researched sends in a week is roughly 3 hours 45 minutes of pipeline work plus 90 minutes of watch, about 5 hours 15 minutes total. Across a year that is about 270 hours for the hiring set on one client type, before you multiply by extra client types. That is the labour cost the later chapters quote.
Add it up: the software stack (indicative, 2026)
Prices and credit models move constantly. Treat the bands below as indicative 2026 ranges in pounds, not a quote. The point is not the exact figure. The point is that a working stack is several products held at once, and credits often expire whether you used them or not.
What one client type usually forces you to hold at the same time:
- LinkedIn Sales Navigator Core: about £80–100 / month. Filters and job-change views that free LinkedIn will not give you at volume.
- Apollo (or equivalent people and company database): about £60–90 / month. Org enumeration and a finder tier in the waterfall.
- Hunter (or equivalent first-line email finder): about £40–80 / month depending on credit pack.
- Prospeo (profile-based finder): about £30–50 / month. Exists because Hunter and Apollo answer a different question and cannot see people who only exist to you as a LinkedIn profile.
- Findymail (verified-on-find): about £30–50 / month. Exists because the cheaper tiers hand you addresses you should not trust.
- A regional finder (Dropcontact or LeadMagic): about £30–60 / month. Exists because the tiers above miss whole countries.
- A verifier (NeverBounce, ZeroBounce, or MillionVerifier credits): about £15–40 / month at modest volume. Non-negotiable if you send from a domain you care about.
- Board aggregation (a jobs data product, or living with six open tabs): about £40–60 / month if you buy it. Free if you pay in tab-switching instead.
Indicative total for that working set: about £330–540 / month (roughly £4,000–6,500 / year), before you touch job-change automation. Note what the list is: three or four email finders, held at the same time, on purpose. That is not indecision. It is what non-overlapping coverage costs. Dropping one finder or the verifier does not simplify the job. It fails silently on more rows, which is worse, because a silent miss looks exactly like a company that has nobody worth writing to.
If Playbook 07 is a primary motion and you refuse to miss role changes, dedicated job-change products such as Champify or UserGems sit in a different band entirely, often high hundreds to low thousands of pounds per month depending on contract. Manual Sales Navigator watching is the cheaper substitute. It is also the one that dies first in a delivery week.
Hours and money together, one client type, hiring set as main motion: about 270 hours a year of operator time, plus about £4,000–6,500 a year in the core stack subscriptions above, with no single product doing the whole path. That is the middle. The outcome is still correct, and the process is the right one. What most operators underestimate is the cost of personally assembling and feeding the middle, until the month they pay four overlapping credit balances and still cannot reach a founder in Manchester.
When the hours start to bite
Or run all of this in the background and read the prepared output on a Monday. The closing chapter is where that choice is spelled out. Not here.