Platform · AI SDR

Four words decide what your AI SDR may do alone.

They are manual, assisted, supervised and autonomous, and they are not labels on a settings page. They are a type in our source code, and every action the agent can take is weighed against them before it runs. The whole table is further down this page, including the rows where the answer is no.

Included at $499 per seat per month

What each level may run alone

every action, every level

manual0 auto / 12 approval / 0 blocked
assisted4 auto / 8 approval / 0 blocked
supervised6 auto / 4 approval / 2 blocked
autonomous8 auto / 2 approval / 2 blocked
runs alonewaits for a humancannot run

The top rung is not a blank cheque. Two actions are refused even at autonomous, by a floor that is checked before any level is read.

How the gate runs

Two inputs, three possible answers, no discretion.

Before the agent does anything, the action and your workspace's autonomy level go into a single function. It returns run it, hold it for a named human, or refuse it outright. No model takes part in that decision, which is why the answer is the same every time you ask and why the whole table below can be published rather than described.

The gate, printed in full

action against level

manualassistedsupervisedautonomous
draft_emaillow
rep signsruns aloneruns aloneruns alone
enrich_contactlow
rep signsruns aloneruns aloneruns alone
summarize_calllow
rep signsruns aloneruns aloneruns alone
tag_leadlow
rep signsruns aloneruns aloneruns alone
schedule_meetingmedium
rep signsrep signsruns aloneruns alone
send_emailmedium / irreversible
rep signsrep signsrep signsruns alone
update_crmmedium
rep signsrep signsruns aloneruns alone
apply_discounthigh
rep signsmanager signsmanager signsruns alone
place_callhigh / irreversible
rep signsmanager signsmanager signsmanager signs
send_contracthigh / irreversible
rep signsmanager signsmanager signsmanager signs
delete_recordcritical / irreversible
rep signsmanager signscannot runcannot run
issue_refundcritical / irreversible
rep signsmanager signscannot runcannot run

Everything the gate is allowed to look at

Three properties on the action, and the level your workspace is set to. That is the entire input. If an action arrives carrying metadata the gate does not recognise, it is refused rather than guessed at, and that check runs before any level logic, so no autonomy setting can reach past it.

  • risklow, medium, high or critical
  • reversiblecan the effect be cleanly undone
  • externalSideEffectdoes it touch someone outside your company

Why this is different

The category configures restraint. We built it in.

An AI SDR is the first software most teams let speak to customers unsupervised, so the question is not how clever it is but what stops it. The table above is not a description of our policy. It is our policy: this page calls the same function the agent calls, and so does the autonomy screen inside the product, which is why none of the three can drift apart.

How an AI SDR usually ships

PlanDraftSend

The agent holds a send function and a preference decides whether it calls one. Switch the preference off and the wire is still there, one bad default away from being live again.

SAGARIS

PlanDraftProposeA person decidesOutbound gateSend

no send path exists for these four

  • queue_email
  • queue_sms
  • launch_campaign
  • book_meeting

The agent writes a proposal and stops. Sending lives in different surfaces entirely, behind a fail-closed gate and a suppression list, so there is nothing at this seam to switch back on.

  • Built in, not switched on

    For the four actions that reach a real person, the agent has no send function to call. It writes a proposal and stops. Safety that is a setting can be unset by whoever holds the admin password; safety that is a missing wire cannot.

  • A floor nobody can approve past

    Human sign-off sits on top of the gate, not above it. When the gate refuses an action outright, an approval does not lift it, and there is no seniority that changes the answer. Most approval queues work the other way round.

  • Decisions you can replay, not just read

    Each decision stores the numbers that produced it, not only the sentence explaining it. Months later you can feed those inputs back through the same function and tell a policy change apart from a model change apart from a data change.

FAQ

The questions you ask before you trust it with your market.

  • MOST ASKED

    There are two separate answers and both matter. The agent itself has no send path: for queueing an email or an SMS, launching a campaign or booking a meeting, all it can do is write a proposal, and the actual send happens in a different part of the system behind a gate that fails closed. Separately, the policy table decides whether a send is held for a person at all. At manual, assisted and supervised it is held. At autonomous, sending an email does self-run, and we would rather say that plainly than hide it behind a friendlier sentence.

Set the level yourself

We will not quote you a reply rate. We will hand you the controls.

Bring the actions your team actually takes and we will set the autonomy level live, then walk the table row by row until you can predict the verdict without us. If what your preferred level allows turns out to be more than you are comfortable with, it is far better to learn that inside a call than inside a quarter.

We use these details to contact you about SAGARIS. See our privacy policy.

Book a demo