
Error Handling
Part of Marketing automation error handling
Building a safe stop switch for a marketing automation
Design an emergency stop that accounts for new, waiting and running marketing workflow actions, then reconcile records before restarting.
A safe stop switch must block the next unwanted action and show what work remains in progress. Cover new entries, waiting records, scheduled retries and actions already sent to another service. Record who invoked the stop, why and what must be checked before restarting.
Define the stop boundary
List every route that can produce the campaign action: the main workflow, scheduled sends, replay queues, connector retries and any recovery flow. Decide whether an incident warrants a campaign-wide stop or a hold on one action or record group.
Write down which controls stop each route and what work remains to be checked. Keep the stop visible to anyone who could restart or replay work.
| Work state | Decision to design |
|---|---|
| Not started | Block new entries or triggers. |
| Waiting or scheduled | Hold or cancel the pending action and record its disposition. |
| Already running | Check whether cancellation is possible; inspect the outcome if it is uncertain. |
Know what the platform switch does
Power Automate names a bulk run feature “Cancel or resubmit flow runs in bulk”. Use its cancellation option for runs identified for cancellation, and defer resubmission until reconciliation. Do not assume that turning off a cloud flow cancels its pending or in-progress runs; check the effect and inspect run history.
For instant-trigger flows, users can always resubmit their own runs. Administrators can enable or disable resubmission of runs initiated by other users with the “Power Automate flow run resubmission” setting in the Power Platform admin centre.
In HubSpot, open More > Automation > Workflows, or Automation > Workflows if More is not shown. Open the workflow and toggle “Workflow is ON” off; to turn off several workflows, select their checkboxes and choose Turn off. You need Publish permission or Super Admin permissions.
Turning off a HubSpot workflow prevents new records from enrolling. Existing records remain enrolled, but actions will not execute, except for delays, which are not skipped. Turning off a workflow does not pause enrolled records at a specific step, so reconcile enrolled records before restarting.
For any replay or retry mechanism, verify what disabling the relevant control does to scheduled attempts. Keep those routes in the stop boundary and review run history before making recovery decisions.
Platform-Specific Stop Mechanisms in Marketing Automation
- Power AutomateUse ‘Cancel or resubmit flow runs in bulk’; turning off flow does not cancel in-progress runs. Check run history.
- HubSpotToggle ‘Workflow is ON’ off to prevent new enrollments; existing records remain enrolled but actions won’t execute (delays are not skipped).
- ZapierReplay feature allows resubmission of failed triggers; disabling a zap stops new runs but doesn’t affect in-flight executions.
Guard the consequential action
Build a controlled hold check immediately before a consequential action, such as a customer send. Proceed only when the hold is confirmed clear; if the hold state cannot be read, stop that action and raise an exception. Scope the hold to the campaign or action version, restrict who can change it and record changes.
A guard cannot recall a request already sent to another service. Treat an in-flight outcome as uncertain until the destination provides evidence. Make the stop state visible to anyone who could restart or replay work.
Key Metrics for Safe Stop Validation
- Pending Actions Held
- All
- In-Flight Outcomes Uncertain
- Until destination confirmation
Resume from known outcomes
Before resuming, list records that completed, skipped, waited or need review. Confirm the current campaign version, audience and send eligibility. Restart only the actions still required, with an owner for every uncertain outcome.
For each action already sent to another service, resolve the uncertain outcome before replaying it. Repairing the cause does not by itself authorise a full workflow replay.



