Permission Density


Permission is not a simple yes-or-no; it builds in layers—starting with attention, then moving to behavioral data, then preferences, and finally identity. When a layer is obtained easily, it becomes easier to request the next one. However, if a layer is skipped, all subsequent requests must carry a weight they don't need.
On the same day, two organizations request the same audience; one obtains a response rate of 40 percent while the other gets 4 percent. The offers are similar, and the channels used are the same. The reason for the difference is what each organization had established before it sent the message.
In 1999, Seth Godin identified the fundamental concept, known as permission marketing—the notion that communication that is anticipated, personal and relevant performs better than communication that interrupts. Instead of viewing the original description as a simple binary situation, in which either permission is held, or it is not held, it is more accurate to see it as a continuous variable. Organizations do not simply have or not have permission from an audience; rather, they have accumulated more or less of it over a longer or shorter period, across a greater or smaller number of dimensions. It is this accumulation that determines the cost of all future requests.
Permission density refers to the amount of that accumulated relationship that an organization actually has. In the case of low-density permission, the relationship is superficial: the audience provided their email address once, received a newsletter, and has no further contact with the organization. With high-density permission, the relationship is multi-layered because the audience has shared their preferences, engaged with the content, responded to requests, made purchases, referred others, and has thus built up a record of interaction which shows a real commitment to the relationship. If an organization with high-density permission makes a substantial request, the request is made within a context of existing trust. In contrast, if an organization with low-density permission makes the same request, it does so with almost no basis.
Why Density Changes the Cost of Asking
Any request has two parts to its cost: the friction the audience feels when responding and the risk they believe they'll face if they say yes. Having high-density permission decreases both.
Friction is reduced since the organization already has the necessary relationship infrastructure. A customer who has made three purchases does not have to re-enter their payment details or reestablish trust in how their orders are fulfilled. A subscriber who has already clicked through on five previous recommendations does not need to be persuaded that the next one is worth reading. The earlier interactions have set the stage for the present request to be carried out easily. In the case of low-density relationships, there is no such infrastructure, so every request has to start from scratch when making the case for the relationship.
The perceived risk level declines because the accumulation of permissions serves as evidence that the organization has behaved well in the past. If an audience has shared an email address and as a result received something useful, they are more likely to share their phone number. When an audience has provided a phone number and is not subsequently harassed, they are more likely to indicate a preference or complete a survey. Each positive interaction causes the audience to reduce their estimate of the risk for the next one. It is this mechanism that causes progressive relationship-building to have a compounding effect: the return from each exchange is not only the value of the exchange itself but also the lower cost of all future exchanges it makes possible.
The immediate value of each exchange is not the only thing at stake; the lower cost that results from every future exchange it facilitates is also at stake. It is this compounding effect that distinguishes organizations with dense permission from those that make expensive, low-conversion requests to small audiences.
What Organizations Get Wrong About Building Permission
The biggest error is to view permission as something obtained once and for all, rather than as something that builds over time. Suppose an organization runs a campaign, increases its list by 10,000 contacts, and then regards the question of permission as being settled. In fact, all it has done is add 10,000 weak relationships to its database. The size of the list has increased, but the density has not.
Another mistake is requesting too much too soon. Take the case of an organization that protects access to its most valuable content by asking for a name, an email address, company size, job title, and a budget range. It is demanding fifth-layer permission before it has even won the first. Although some audience members will fill out the form because they genuinely want the content, most will not, and those who do will have a different relationship with the organization than they would have if the initial interaction had been lower-stakes. Asking for all that information at once drains the goodwill that could have been built up through a progressive approach.
The period during which the GDPR (Europe's data privacy and security law) was enforced from 2018 served as an unexpected test of this very situation. Those companies that had depended on either assumed or purchased consent found themselves losing large sections of their contact lists when it became necessary to obtain explicit permission. It was the organizations that kept their lists that had audiences who actually wanted to receive communications from them. This difference wasn't mainly a matter of compliance; it was a question of density. Some companies had truly earned people's permission, while others had built up contact information on the assumption that permission would follow. It didn't.
GDPR did not cause the density problem; it was brought to light. The companies that lost their lists had not, in fact, obtained proper permission; instead, they had gathered contact information on the mistaken belief that permission would be granted automatically.
Four Ways to Build Density Deliberately
Permission density is added sequentially; the various layers cannot be swapped, and if you attempt to skip them, you end up with weak relationships that make all subsequent requests costly.
First Stage — Attention
The first stage is attention. When an audience decides to read, watch or listen to what an organization puts out, it is giving a small but significant kind of approval—that is, permission to be included in their consideration set. Most organizations regard this as a marketing result rather than as a valuable asset. Those organizations that build up dense permission see it as the foundation on which all the other layers are built. The practical result of this is that the initial content and communication should not aim to convert people right away but should instead be genuinely worthwhile for the attention it receives. A newsletter that someone reads every week because it is useful is building up permission with each issue. On the other hand, a newsletter that exists solely to push people towards a conversion event is wasting the permission it has never fully earned.
Second State — Behavioral Data
The second level involves behavioral data: when an audience performs certain actions, those actions constitute a form of permission that allows one to get to know them better. The error lies in gathering this kind of data without making it visible. Companies that regard behavioral signals as intelligence about the audience are in fact setting up a system of surveillance rather than building a relationship; on the other hand, those that create density take a different approach: they use behavioral data to make the following interaction more relevant and carry out this process in such a way that the audience realizes what is going on. The canonical example of this is Amazon's recommendation engine, not because of the technical skill involved but because the audience understands and accepts what is happening—that their history is being used to display items they are more likely to want. The permission in this exchange is genuine, as the exchange’s value is clear.
Third Stage — Preferences
The third stage is stated preferences. It is here that progressive profiling becomes a strategy rather than just a tactic. It is a significant request to ask an audience to tell you something about themselves, and it should only be made once the relationship has established that the organization will use the information to serve the audience rather than against it. The order in which the requests are made is important: an email address should be requested before a phone number, a phone number before a preference, and a preference before an opinion is sought on a sensitive matter. Each step should be based on the quality of the previous one. Organizations that fail to follow this sequence and ask for all the information in the first interaction achieve lower completion rates and lower-quality data, since the audience has not yet decided whether the organization is worth giving information to.
Fourth Stage — Identity Permission
The fourth level concerns identity permission, that is, the audience's readiness to publicly associate their identity with the organization, recommend it to others, co-create content, and act as a reference. This is the form of permission of highest density and the most valuable since it is the one most resistant to disruption by competition. When an audience member has publicly linked their identity to an organization, they have made a social commitment that extends beyond the transactional. Reaching this stage requires that all the previous layers have been properly addressed; it cannot be bought, offered as an incentive or created artificially, since it is the reward resulting from accumulated trust.
The Strategic Implication
Groups that grasp the concept of permission density end up making different decisions about how to allocate their resources than those that don't. This is because they realize that the benefits accumulate over time, so they invest in the quality of early contacts. They also do not give in to the urge to ask for a lot too early, since they know that the short-term increase in conversions is less than the long-term cost of reduced permission density. Instead, they assess more than just the size of their lists and their open rates—the depth of the relationship their audience has with them.
The most useful diagnostic question isn't about how big the audience is but rather what the audience has already said yes to. An organization with 50,000 contacts, each of whom has filled in only one form, has a lower level of permission density than one that has 5,000 contacts, each of whom has made several purchases, engaged with content, completed surveys, and referred a fellow customer. The larger list will consistently fail to meet the most important requests because it hasn't established the foundation that makes it cheap to execute significant requests.
In situations where privacy is taken into account, and people's attention is limited, it is not the organizations that find new ways to interrupt large audiences that can grow without obstruction. Rather, it is those that have, over the years, built up a certain level of permission, enabling their audience to agree in advance even if they don't know exactly what is being asked.
The kind of request you are about to make depends not on the quality of your offer but on what you had previously built.
Some ideas are worth discussing in the context of your organization.


