Bottom line

Use seven durable stages: constrain the brief, research from approved sources, propose the campaign, validate mechanically, obtain human approval, execute conservatively, and learn from reconciled outcomes.

1. Constrain the brief

Start with the offer, real sender, business website, geography, physical address, exclusions, monthly ceiling, and what a successful conversation means. Make missing information an error, not an invitation to invent.

The brief should also state the permitted email category. Permission-based newsletters, customer lifecycle messages, and non-opt-in B2B outreach are different programs. Route them to infrastructure and policies intended for that use.

2. Research with provenance

Ask the agent to identify why each account fits and which first-party page supports the conclusion. Store the URL, observation time, and a compact evidence note. A lead record without provenance is difficult to review and easy to overgeneralize.

Respect source restrictions, minimize collection, and avoid turning broad crawling into a substitute for a clear ICP. Verification can estimate whether an address is deliverable; it does not establish relevance, consent, or lawful basis.

3–4. Propose, then validate

The proposal should include audience rules, excluded segments, representative accounts, source plan, sequence, claims, call to action, sending schedule, stop conditions, and infrastructure assumptions. Require the agent to name uncertainties.

Then let deterministic code validate types, URLs, geographic boundaries, audience ceilings, mailbox ratios, sending limits, required unsubscribe content, and budget. Validation should reject unsafe or incomplete plans instead of “fixing” them invisibly.

5. Approve consequences, not a vague goal

The approver should see who will be contacted, why, what they will receive, which sender and domains will be used, the maximum scale, and the cost. Save the exact approved version and make the authorization single-use or version-bound.

Domain purchases, mailbox creation, and a first production send are distinct consequences. A mature system can gate each separately when risk warrants it.

6–7. Execute conservatively and learn from reconciled events

Provision DNS and mailboxes, verify authentication, age or ramp new identities, start with a small cohort, and pace by mailbox and receiving network. Replies, hard bounces, complaints, and opt-outs must create immediate deterministic suppression before an agent classifies or summarizes them. [2][3]

At the end of a review window, give the agent normalized outcomes with stable denominators. Let it propose a revised audience or message, then repeat the approval cycle. Never let it edit the live campaign and the historical record at the same time.

Questions, answered plainly

What should an AI email agent produce?

A structured, reviewable proposal containing audience logic, evidence, exclusions, messages, scale, infrastructure assumptions, limits, and uncertainties.

Where should human approval happen?

After deterministic validation and before irreversible provisioning or sending. The approval should bind to the exact campaign version.

Should the agent classify replies before suppression?

No. A reply or opt-out should stop future automated steps immediately; classification can happen afterward.

Sources and methodology

Product capabilities were checked against first-party documentation available on September 9, 2026. Policies, plans, and prices can change; verify them before buying. General guidance is educational and is not legal advice.

  1. Actually Agentic product overview Actually Agentic. Product scope and operating model.
  2. Email sender guidelines Google. Authentication, DNS, spam-rate, formatting, unsubscribe, and volume guidance for Gmail.
  3. CAN-SPAM Act: A Compliance Guide for Business U.S. Federal Trade Commission. Official U.S. guidance for commercial email, including B2B messages.

Your agent can do the thinking.
The infrastructure still needs a grown-up.

See how Actually Agentic works