What should an AI agent never do alone?
Send anything external, spend money, delete or merge records, change a deal stage, or contact someone on a suppression list. Everything reversible and internal can run unattended.

The short answer
- An AI agent should never, unattended, send anything external (email, LinkedIn message, SMS, a marketplace proposal), spend money, delete or merge records, change a deal's stage, or contact someone on a suppression list.
- Everything reversible and internal, research, tagging, drafts, lead scores, summaries, can run without a person reviewing each instance, since a mistake there is cheap to catch and nobody outside the team ever sees it.
- The dividing line is not how smart the agent is or how long it has been running well. It is whether the action is visible outside the company or hard to undo; both properties make a mistake expensive in a way a wrong internal tag never is.
- This is a sensible default policy, not a fixed rule imposed by any one tool. A team can widen or narrow it, but the reasoning, external and irreversible actions need a human, should hold regardless of which system enforces it.
Why 'never alone' beats 'never at all'
The instinct when listing what an agent should not do is to describe entire agents as safe or risky: the research agent is fine, the outreach agent is dangerous. That framing breaks down quickly, because most agents worth building do a mix of both kinds of work in the course of one job. An agent that drafts a follow-up email is doing something reversible, low-stakes work, right up until the moment it sends that draft, which is neither reversible nor low-stakes. The agent is the same; the action changed.
That is why the list below describes action classes, not agent types. A single agent can run entirely automatically for the reversible half of its job and queue every instance of the irreversible half for a person, and that split is normal, not a sign the agent is half-broken.
A sensible default policy
Action class and a reasonable default; teams adjust this, but the reasoning behind it should hold.
| Action class | Default |
|---|---|
| Research, enrichment, tagging, logging, scoring, summaries, internal tasks, suggested contacts | Runs automatically |
| Classify a reply, pause a cadence on reply, suppress on unsubscribe or bounce | Runs automatically |
| Any external send: email, LinkedIn message, SMS or WhatsApp, marketplace proposal | Waits for review |
| Create a deal from a positive reply, book a meeting | Waits for review, can move to automatic after a clean track record |
| Stage changes, contact merge or delete | Waits for review |
| Any spend (credits, connects, ad budget) and anything outside the CRM | Human only, no automatic path |
Why these five, specifically
Sends are on the list because the audience is outside the company; a bad draft that reaches a prospect cannot be quietly fixed the way an internal note can. Spend is on the list because it is money leaving the business on the agent's judgment alone. Deletes and merges are on the list because they are close to irreversible, a merged contact's history does not cleanly un-merge. Stage changes are on the list because they distort forecasting and can misrepresent a deal's real status to everyone downstream. Suppressed contacts are on the list because contacting them again is not only a mistake, it can break a commitment the business made or an obligation the law imposes.
Disclosure: SalesCrew is our product, and this exact policy table is what ships as the default, seeded on every new instance and editable in Agents → Guardrails. Every agent starts in review mode regardless of the action class, and even after a class is moved to automatic, a confidence threshold routes anything the agent is unsure about back to a person.
This is a policy per action, not per agent
Questions
- Is this list the same for every agent?
- The list is per action, not per agent. One agent might be trusted to draft replies automatically while its stage-change suggestions still need review; the same rule applies across every agent that could take that action, not only to one labeled 'risky.'
- Why single out suppression lists specifically?
- A suppression list exists because someone asked not to be contacted, or because contacting them creates legal exposure (bounced, unsubscribed, opted out). An agent that skips the suppression check is not making a business mistake, it is potentially violating a commitment or a regulation.
- Can these actions ever move to automatic?
- Some can, gradually and per action class, after a clean track record in review mode. External sends generally stay in review the longest because the audience for a mistake is outside the company. Deletes and merges rarely graduate at all, since they are the hardest to reverse.