Back to portfolio
AI Lead Scoring · Multi-Vertical · GDPR

LeadWise — AI Lead Qualification Engine

AI-powered lead qualification engine · Two verticals: Banking & Travel
Complete BA Specification Case Study · Business Analyst

FastAPI / Python Claude API (Anthropic) Salesforce CRM GDPR Art. 6/17/21 Pydantic v2 Streamlit Render
AuthorZahra · Business Analyst
Verticals🏦 Banking · ✈️ Travel
CodeGitHub — zahraeh/LeadWise
Versionv1.0 · 2026
StatusPortfolio · Sample/fictional data
6BDD User Stories
10Business Rules
8REST API Endpoints
<45slead processing time

Business Context & Problem Statement

BankWise Retail is a fictional French retail bank positioned on the digital-first segment. As part of its seasonal campaign Livret A Boosté — Spring 2025, the bank generates several thousand marketing leads per week through its digital channels (Google Ads, email, comparison sites, push notifications).

This entire flow is currently processed manually by branch advisors, with no prioritization tool or structured GDPR compliance system.

Diagnosis of Pain Points
Identified Pain PointOperational Impact
100% manual processing of inbound leadsTotal dependency on human effort, frequent data-entry errors
Callback delay exceeding 72hLoss of "Hot" leads to direct competitors
Conversion rate below 8%Estimated lost revenue of +€30K/month
No scoring or prioritizationOverloaded advisors, poor resource allocation
GDPR compliance not under controlRisk of CNIL sanctions and regulatory disputes
No traceability of consentsMaximum exposure in the event of an external audit
2025 Industry Benchmark
Average contact delay (leading banks): 4h
Conversion rate: 12–20%
Automated scoring: standard practice at 78% of digital banks
Project Objectives
#ObjectiveTarget
OBJ-1Reduce processing time< 24h
OBJ-2Improve conversion rate15%
OBJ-3Automate scoring100%
OBJ-4Ensure GDPR compliance0 CNIL non-conformities
OBJ-5Centralize tracking in Salesforce100% tracked
OBJ-6Contact 80% of leads within 48h80%

Project Framing — Scope & Governance

Functional Scope

✅ In Scope

  • Lead capture and qualification
  • Consent management & GDPR traceability
  • Automatic AI scoring (Claude API)
  • Automatic assignment to advisors
  • Full lead lifecycle tracking
  • Real-time KPI dashboard
  • Automatic deduplication

❌ Out of Scope

  • Existing customer management
  • Online subscription module
  • Financial reporting / accounting
  • Banking back-office integration
  • Native mobile application
  • Complaints management
  • Customer loyalty module
Regulatory & Legal Constraints
ReferenceRequirementCriticality
GDPR Art. 6Explicit consent required on every submissionCRITICAL
GDPR Art. 17DELETE /leads/{id} endpoint operational within 72hCRITICAL
GDPR Art. 21Opt-out → immediate stop + data anonymizationCRITICAL
CNIL · RetentionAutomatic deletion after 3 years if not convertedMAJOR
AML-CFTKYC verification before any commercial offerMAJOR
PSD2Encryption of banking data in transit and at restMAJOR
RACI Matrix
StakeholderRoleFramingSpecsTestsUAT
Marie DupontProduct OwnerAAIA
Jean-Marc LefebvreMarketing LeadCCIR
Sophie ArnaudGDPR CounselCRCA
Romain PetitTech LeadICRI
Zahra ★Business AnalystRRRR

R = Responsible · A = Accountable · C = Consulted · I = Informed

Functional Specifications

Business Rules
IDDescriptionPriority
RG-001Consent required — no lead is processed without explicit opt-inCRITICAL
RG-002Score < 3 → Cold segment → automatic nurturing sequenceCRITICAL
RG-003Score ≥ 7 → advisor contacts within 24h (SLA)CRITICAL
RG-004Prospect data deleted after 3 years if not convertedCRITICAL
RG-005Opt-out → immediate stop + anonymizationCRITICAL
RG-006Lead assigned to the advisor at the nearest branch (postal code)MAJOR
RG-007Duplicate (email OR phone) → silent merge + logMAJOR
RG-008Consent date/time archived in the database (audit trail)CRITICAL
RG-009Score 4–6 → advisor assignment within 48hMAJOR
RG-010Every AI call logged with input/output for auditMAJOR
User Stories — BDD Format
US-001 · Lead capture via web form Must Have · 5 pts

"As a prospect interested in the Livret A Boosté offer, I want to fill out an online form so that I can be contacted by a BankWise advisor."

  • Required fields: Last Name, First Name, Email, Phone, Postal Code, Source
  • Explicit, mandatory GDPR checkbox — submission blocked if unchecked
  • Automatic confirmation email within 5 minutes
  • Lead created in Salesforce with status "Prospect"
  • Consent timestamp archived (RG-008)
  • Duplicate detection on email AND phone (RG-007)
US-002 · Automatic scoring by the AI agent Must Have · 8 pts

"As a marketing manager, I want every new lead to be automatically scored by AI so that I can prioritize outreach."

  • Score computed on a 1–10 scale in under 3 seconds
  • Weighted criteria: source (25%), web behavior (20%), age (20%), postal code (20%), time of day (15%)
  • Classification: Cold (1–3) / Warm (4–6) / Hot (7–10)
  • Score and AI justification visible in Salesforce within 2 minutes
  • Scoring log retained (input, output, timestamp) for auditability
US-003 · Automatic assignment to an advisor Must Have · 8 pts

"As a branch manager, I want qualified leads to be automatically assigned to an available advisor."

  • Assignment based on geolocation (postal code) AND workload
  • Advisor notification: email + Salesforce alert upon assignment
  • Priority queue if no advisor is available within the SLA
  • Hot SLA: 24h | Warm SLA: 48h
US-004 · Right to object management (GDPR opt-out) Must Have · 5 pts

"As a prospect, I want to be able to withdraw my consent at any time via an unsubscribe link."

  • Unsubscribe link present in every marketing email
  • Opt-out request processed and confirmed within 72h (GDPR Art. 21)
  • Immediate stop of all marketing communications upon opt-out
  • Data anonymized (retained only if legally required under AML-CFT)
US-005 · Real-time KPI dashboard Should Have · 5 pts

"As a marketing manager, I want to view my campaign performance indicators in real time."

  • Lead volume, conversion rate, opt-in rate, average contact delay
  • Data refreshed every 60 minutes — filters: campaign, date, channel, segment
  • CSV export available for external analysis
US-006 · Automatic lead deduplication Should Have · 3 pts

"As an advisor, I want to avoid receiving the same prospect twice in my pipeline."

  • Detection on email AND phone for every new submission
  • Silent merge: enrichment of the existing lead record
  • Notification to the original advisor with a diff of the information

Technical Architecture & AI Agent

Technology Stack
🖥️
Streamlit
Frontend — form & KPI dashboard
FastAPI
Backend — REST API, flow orchestration
🤖
Claude API
claude-sonnet — AI scoring & justification
Pydantic v2
Schema validation & business rules
☁️
Salesforce
Simulated CRM (JSON) — leads & assignments
📊
Locust
Perf. testing — 50/200/500 concurrent users
Data Flow — End-to-End Architecture
1
Streamlit — Form

Prospect submits contact details + GDPR consent

2
FastAPI — POST /leads <0.5s

Pydantic validation, consent timestamp, deduplication

3
Claude API — AI Agent <3s

Profile analysis, 1–10 score calculation, text justification

4
FastAPI — Assignment Engine <0.5s

Advisor selection (geo + workload), SLA creation

5
Salesforce Mock — CRM <0.5s

Lead record created with score, segment, assigned advisor

6
Email + Notification <5 min

Prospect confirmation + advisor alert (email + CRM)

AI Scoring Matrix
CriterionWeightMax ScoreMin Score
Lead source25%Direct email formUnsolicited push notification
Web behavior20%3+ visits > 5 min0 product page visits
Age bracket20%25–45 years<18 or >65 years
Geographic area20%Paris, Lyon, BordeauxIsolated rural area
Submission time15%Mon–Fri 9am–6pmNight or weekend
Segment Classification
Cold (1–3)No assignment — Email nurturing sequence: D+3, D+7, D+14
Warm (4–6)SLA 48h — Advisor assignment + standard notification
Hot (7–10) ★SLA 24h — Immediate assignment + urgent alert + SLA follow-up
API Endpoints — FastAPI
MethodEndpointGDPR Constraint
POST/leadsConsent verified
GET/leadsToken required
GET/leads/{id}Token required
POST/leads/{id}/scoreToken required
PUT/leads/{id}/statutToken required
DELETE/leads/{id}Admin + mandatory logging
GET/dashboard/kpisToken required
POST/leads/{id}/optoutNo token required

Test Strategy & Validation Results

Overview
LevelToolCoverageStatus
Unit testspytest90% of codeDONE
Integration testspytest + httpxAll endpointsDONE
Functional testsSquash TM6 US / 10 BRIN PROGRESS
GDPR testsSquash TM6 GDPR articlesIN PROGRESS
UAT testsExcel / Notion5 scenariosTO SCHEDULE
Performance testsLocust3 load scenariosTO SCHEDULE
Functional Test Cases
IDTitleStatus
CT-001Valid form submissionPASSED
CT-002Blocked without GDPR consentPASSED
CT-003Invalid email blocked (422)PASSED
CT-004Hot lead scoring (score ≥ 7)PASSED
CT-005Cold lead scoring (score ≤ 3)PASSED
CT-006Automatic advisor assignmentTO RUN
CT-007GDPR opt-out via email linkTO RUN
CT-008Duplicate detection (same email)TO RUN
CT-009Dashboard CSV exportTO RUN

KPI Tracking & Delivery Summary

Target KPI Dashboard
IndicatorBaselineTargetCurrent Result
Lead → opportunity conversion rate<8%15%To be measured
Lead processing time>72h<24h~45s ✔
Leads contacted within 48h80%To be measured
Opt-in consent rate60%To be measured
AI scoring response time<3s~1.8s ✔
System availability>99%To be measured in prod
BA Skills Demonstrated
Requirements gathering & analysisAdvanced
User Story & spec writingAdvanced
GDPR regulatory complianceAdvanced
Test strategyAdvanced
Applied AI for business use cases (Claude API)Intermediate
KPI-driven managementAdvanced
6BDD User Stories
18%target conversion rate
5destinations covered
<24hadvisor callback time

Business Context & Problem Statement

LinguaWise International is a fictional language-travel agency, inspired by the EF Education First model. Its flagship campaign, Intensive English Course — Summer 2025, generates several thousand prospect inquiries per week via Google Ads, travel comparison sites, web forms and social media.

These leads are currently processed manually by travel advisors, with no prioritization or structured pipeline. The conversion rate stalls below 10%, well behind the sector's leading players.

Diagnosis of Pain Points
Identified Pain PointOperational Impact
100% manual processing of inbound inquiriesAssignment errors, frequent oversights, uneven workload
Callback delay exceeding 72hLoss of hot leads to competitors (EF, Kaplan)
Conversion rate below 10%Estimated lost revenue of +€25K/month
No scoring or prioritization by destination/budgetGeneralist advisors instead of destination specialists
GDPR compliance not structuredCNIL risk on sensitive data (minors, passports)
No prospect lifecycle trackingFollow-ups based on gut feeling, no nurturing sequence
Destinations Covered — Summer 2025
🇬🇧 London 🇮🇪 Dublin 🇺🇸 New York 🇲🇹 Malta 🇨🇦 Toronto
Target: 18–35 year-olds + professionals looking to improve their English
Sector benchmark: conversion rate 15–25%
Project Objectives
#ObjectiveTarget
OBJ-1Reduce callback delay< 24h
OBJ-2Improve conversion rate18%
OBJ-3Automate AI scoring100%
OBJ-4Ensure GDPR compliance0 CNIL non-conformities
OBJ-5GDPR opt-in rate65%
OBJ-6Contact 85% of leads within 48h85%

Project Framing — Scope & Governance

Functional Scope

✅ In Scope

  • Prospect capture and qualification
  • Consent & GDPR traceability
  • AI scoring by destination and profile
  • Assignment to the specialist advisor
  • Full lead lifecycle tracking
  • Real-time KPI dashboard
  • Automatic deduplication

❌ Out of Scope

  • Online booking and payment
  • Visa and passport management
  • Accommodation / housing module
  • Native mobile application
  • Existing customer management
  • Loyalty module
  • Accounting back-office
Regulatory & Legal Constraints
ReferenceRequirementCriticality
GDPR Art. 6Explicit consent required — minor prospects require parental consentCRITICAL
GDPR Art. 17DELETE /leads/{id} endpoint operational within 72hCRITICAL
GDPR Art. 21Opt-out → immediate stop + data anonymizationCRITICAL
CNIL · RetentionAutomatic deletion after 3 years if not convertedMAJOR
Sensitive dataPassport/ID data collected only at booking, not at lead stageMAJOR
RACI Matrix
StakeholderRoleFramingSpecsTestsUAT
Sarah MorelProduct OwnerAAIA
Antoine LebrunMarketing LeadCCIR
Claire VidalGDPR CounselCRCA
Karim BenaliTech LeadICRI
Emma RousseauSr Travel AdvisorCCRR
Zahra ★Business AnalystRRRR

R = Responsible · A = Accountable · C = Consulted · I = Informed

Functional Specifications

Business Rules
IDDescriptionPriority
RG-T01Consent required — parental consent required if prospect < 18 years oldCRITICAL
RG-T02Score < 4 → Cold segment → automatic email nurturing sequenceCRITICAL
RG-T03Score ≥ 7 → destination specialist advisor contacts within 24h (SLA)CRITICAL
RG-T04Prospect data deleted after 3 years if not convertedCRITICAL
RG-T05Opt-out → immediate stop of all communications + anonymizationCRITICAL
RG-T06Lead assigned to the specialist advisor for the chosen destinationMAJOR
RG-T07Duplicate (email OR phone) → silent merge + log + advisor notificationMAJOR
RG-T08Consent timestamp archived (GDPR audit trail)CRITICAL
RG-T09Score 4–6 → advisor assignment within 48hMAJOR
RG-T10Average AI score < 6 for a destination → alert to marketing managerMAJOR
User Stories — BDD Format
US-T01 · Submitting a language-travel inquiry Must Have · 5 pts

"As a prospect interested in a language-immersion trip, I want to fill out an online form so that I can be contacted by a LinguaWise advisor specializing in my destination."

  • Required fields: Last Name, First Name, Email, Phone, Destination, Duration, Budget, Desired Date
  • Explicit GDPR checkbox — parental consent mandatory if age < 18
  • Automatic confirmation email within 5 minutes
  • Lead created in Salesforce with destination and budget segment
  • Consent timestamp archived (RG-T08)
US-T02 · Automatic scoring by the AI agent Must Have · 8 pts

"As a marketing manager, I want every prospect to be automatically scored based on their profile and destination so that I can prioritize advisors."

  • Score computed on a 1–10 scale in under 3 seconds
  • Criteria: source (25%), departure urgency (20%), budget (20%), traveler profile (20%), time of day (15%)
  • Classification: Cold (1–3) / Warm (4–6) / Hot (7–10)
  • AI justification visible in Salesforce within 2 minutes (e.g., "Budget > €3,000, departing in 6 weeks")
US-T03 · Assignment to the destination specialist advisor Must Have · 8 pts

"As a sales director, I want every lead to be automatically assigned to the advisor who is an expert in the requested destination."

  • Assignment based on chosen destination AND advisor availability
  • If specialist unavailable → escalation to the senior travel advisor (Emma Rousseau)
  • Advisor notification: email + Salesforce alert upon assignment
  • Hot SLA: 24h | Warm SLA: 48h (RG-T03, RG-T09)
US-T04 · Right to object management (GDPR opt-out) Must Have · 5 pts

"As a prospect, I want to be able to withdraw my consent at any time via a link in every email I receive."

  • Unsubscribe link present in every communication
  • Opt-out processed and confirmed within 72h (GDPR Art. 21)
  • Immediate stop of all marketing communications
  • Data anonymized in Salesforce CRM
US-T05 · KPI dashboard by destination Should Have · 5 pts

"As a marketing manager, I want to view performance indicators for each destination in real time."

  • Lead volume, conversion rate, average score per destination
  • Filters: destination, date, channel, segment · Refreshed every 60 minutes
  • CSV export for monthly reporting
US-T06 · Automatic deduplication Should Have · 3 pts

"As an advisor, I want to avoid receiving the same inquiry twice for the same destination."

  • Detection on email AND phone for every new submission
  • Silent merge with destination/budget enrichment if changed
  • Notification to the original advisor with the diff

Technical Architecture & AI Agent

Technology Stack — same as the Banking vertical
🖥️
Streamlit
Travel form + KPI dashboard
FastAPI
REST API — lead flow orchestration
🤖
Claude API
AI scoring — destination + profile
Pydantic v2
Travel business schema validation
☁️
Salesforce
Simulated CRM — leads & assignments
🚀
Render
Cloud deployment — app available online
Data Flow — End-to-End Architecture
1
Streamlit — Travel form

Prospect enters destination, budget, desired dates + GDPR consent

2
FastAPI — POST /leads <0.5s

Pydantic validation (valid destination, budget > 0, consistent dates), deduplication

3
Claude API — AI Agent <3s

Traveler profile analysis, departure urgency, budget — 1–10 score + text justification

4
FastAPI — Assignment Engine <0.5s

Selection of the destination specialist advisor + availability check

5
Salesforce Mock — CRM <0.5s

Lead record created with destination, score, segment, assigned advisor

6
Email + Notification <5 min

Confirmation email to the prospect + destination advisor alert

AI Scoring Matrix — Travel Vertical
CriterionWeightMax ScoreMin Score
Lead source25%Direct form / referralUntargeted social ad
Departure urgency20%Departure < 6 weeksDeparture > 12 months
Stated budget20%> €3,000< €1,000
Traveler profile20%Professional, 25–40 years oldMinor without parental consent
Submission time15%Mon–Fri 9am–6pmNight or weekend
Segment Classification
Cold (1–3)No assignment — Email nurturing: D+3 (destination brochure), D+7, D+14
Warm (4–6)SLA 48h — Destination advisor + personalized quote
Hot (7–10) ★SLA 24h — Senior advisor + priority offer + SLA follow-up

Test Strategy & Validation Results

Overview
LevelToolCoverageStatus
Unit testspytest90% of codeDONE
Integration testspytest + httpxAll endpointsDONE
Functional testsSquash TM6 US / 10 BRIN PROGRESS
GDPR testsSquash TM5 GDPR articlesIN PROGRESS
UAT testsExcel / Notion5 scenariosTO SCHEDULE
Performance testsLocust3 load scenariosTO SCHEDULE
Functional Test Cases
IDTitleStatus
CT-T01Valid form (destination London, budget €2,500)PASSED
CT-T02Blocked without GDPR consentPASSED
CT-T03Invalid email blocked (422)PASSED
CT-T04Hot lead scoring (budget >€3K, departure <6 weeks)PASSED
CT-T05Cold lead scoring (budget <€1K, departure +12 months)PASSED
CT-T06Assignment to the New York specialist advisorTO RUN
CT-T07GDPR opt-out via email linkTO RUN
CT-T08Duplicate (same email, different destination) → enrichmentTO RUN
CT-T09Parental consent required if age < 18TO RUN

KPI Tracking & Delivery Summary

Target KPI Dashboard
IndicatorBaselineTargetCurrent Result
Lead → booking conversion rate<10%18%To be measured
Advisor callback delay>72h<24h~45s ✔
Leads contacted within 48h85%To be measured
Opt-in consent rate65%To be measured
Average qualified score (≥ 6/10)≥ 6To be measured
AI scoring response time<3s~1.8s ✔
BA Skills Demonstrated
Requirements gathering & analysisAdvanced
User Story & spec writingAdvanced
GDPR regulatory complianceAdvanced
Applied AI scoring (Claude API)Intermediate
Multi-vertical test strategyAdvanced
White-label adaptation (config.py)Advanced

Appendices — Business & CRM Glossary

Lead CRM
A prospect who has expressed commercial interest and provided explicit GDPR consent
Opt-in GDPR
A prospect's explicit, informed consent to have their data processed for marketing purposes
Opt-out GDPR
The act by which a prospect withdraws consent — triggers the immediate stop of all processing
Scoring AI / CRM
Assigning a 1–10 score that assesses a lead's maturity and conversion potential
Hot Segment CRM
Lead with score ≥ 7 — contact SLA: 24h — priority advisor assignment
Warm Segment CRM
Lead with score 4–6 — contact SLA: 48h — standard processing
Cold Segment CRM
Lead with score 1–3 — no assignment — automatic nurturing sequence
Nurturing Marketing
A sequence of automated communications designed to mature a lead toward purchase readiness
White-label Product
Architecture that lets the same LeadWise engine be deployed into a new industry via config.py alone
SLA Contract
Service Level Agreement — a committed level of service (e.g., contact within 24h)
RACI Governance
A responsibility-assignment matrix: Responsible, Accountable, Consulted, Informed
Audit trail Compliance
A traceability log that allows the full history of every system action to be reconstructed
Author's note: This document covers both verticals of the LeadWise project — Banking (BankWise Retail) and Travel (LinguaWise International). All names, data and scenarios are fictional and created for educational purposes. Source code is available on GitHub — zahraeh/LeadWise.

Want to know more?

Check out the source code, the Notion documentation, or my other projects.