The Approval Gate: Why AI Should Never Send Without You
Our position on AI autonomy in marketing: real hands, hard guardrails, and a human yes before anything reaches a subscriber. Here’s the reasoning, and where we draw every line.
We build an AI with real hands in your email account — it reads your data, builds your segments, sets up your campaigns. The most important design decision in the product is about what those hands may not do: nothing sends without a human’s explicit yes. Ever. This post is the reasoning, written down so you can hold us to it.
The asymmetry that decides everything
An email is unrecallable. A bad draft costs a review-minute; a bad send costs subscriber trust, complaint-rate damage, and reputation you’ll spend months rebuilding. The cost of requiring approval is seconds. The cost of not requiring it is unbounded and lands on the one asset — your list’s trust — that compounds.
When the downside is irreversible and the safeguard costs seconds, the safeguard wins. That’s the whole argument, and no capability improvement in the model changes it, because the asymmetry isn’t about intelligence — it’s about reversibility.
What the gate actually is
“Human in the loop” has become a marketing phrase, so here’s ours in concrete terms:
- Confirm-before-create. Anything user-facing — a segment, a draft, a campaign — is announced before it’s built, and reported after. No silent artifacts.
- The send gate. Scheduling or sending requires your explicit go-ahead in the conversation. There is no “confidence threshold” above which Airis sends on her own. The threshold does not exist.
- Drafts, then your publish. Automations — flows that will run unattended forever — are drafted by Airis and set live by you. An AI initiating a standing behavior is a different category of action from an AI proposing one, and we keep the categories separate.
- The allowlist. Airis operates under an explicit list of permitted operations. Destructive actions — deleting assets, touching suppression rules — aren’t gated; they’re absent. Suppression especially: no AI enthusiasm overrides an unsubscribe, ever.
- Scoped credentials. Account access is per-organization and encrypted. The blast radius of any mistake is bounded by design, not by promises.
“Doesn’t this defeat the point of AI?”
The point of AI in marketing is not autonomy — it’s leverage. The production work (analysis, drafting, building) collapses from hours to minutes; your work becomes reviewing and deciding. A team of one gets a department; the department gets an approver.
Reviewing three drafted emails takes minutes. Writing them took the afternoon. The gate costs you almost nothing precisely because the AI did everything up to it.
There’s also a subtler benefit: the gate keeps you the marketer — the person whose taste and judgment the program expresses — rather than the audience of an autonomous system whose output you experience. Tools should mean more of your judgment shipping, not less.
The test to run on any AI marketing tool
Ask the vendor three questions:
- What can it do without asking me? (The honest answer should be: nothing your subscribers will ever see.)
- What can it never do, even if I ask? (There should be a real list. Ours starts with destructive operations and suppression overrides.)
- Where’s the line between drafted and live? (If the tool can quietly set a flow live, the line doesn’t exist.)
A tool with impressive capabilities and vague answers here has made its choice — it just hasn’t told you.
Our bet
We think the winning shape of conversational email marketing is maximal hands, minimal autonomy: an AI that can do everything and decides nothing that ships. If we’re wrong, we’ll be wrong safely. If we’re right, “the AI that always asks” stops being a limitation and becomes the reason you trusted it with your list in the first place.