AI outbound sales
AI outbound sales: an SDR agent that works inside server-enforced limits
AI outbound sales means an agent does the preparation and routine work of outbound: it turns a product brief into an ICP, a lead plan, a sequence and a send plan, and helps with replies. In Dooxout the SDR agent works inside limits the server enforces, recommends infrastructure and never buys it, and needs a person's approval for the first campaign and for mass sends.
What is an AI SDR, and what does agent-run outbound look like?
An AI SDR is an agent that takes on sales development tasks: working out who to contact, finding them, writing the sequence and sorting the replies. Outbound sales automation without an agent runs fixed steps. With an agent, the steps adapt to your brief, and the limits matter more, because software that writes and sends needs boundaries it cannot talk its way out of.
Dooxout makes the boundaries part of the server. The agent is a client of the same MCP and API as any other agent and has the same limits. We do not publish reply or meeting figures, and this page makes no claim about results.
The SDR agent flow, step by step
From brief to launch approval, the agent produces a draft and a person decides at each gate.
| Step | What the agent produces | Who decides |
|---|---|---|
| Brief | You give a product description, site, offer, region, language, channels and a target weekly volume. The agent asks questions when the brief is thin and saves a versioned brief. | You review it |
| ICP | A draft profile of the buyer: titles, industries, company sizes, countries and exclusions. | You edit it |
| Lead plan | Filters for the lead finder, an estimate of count and cost, and a request to run the search under your budget. Results are deduplicated, checked against suppressions and verified. | You approve the run |
| Sequence | Steps across the channels you chose, A/B variants of the first message, personalization from each lead's briefing and checks against text rules such as links and length. | You review the draft |
| Send plan | Schedule, sending windows, pacing profile and a forecast of duration within your caps. | You review it |
| Infrastructure | How many domains and mailboxes the volume needs, name ideas, a cost estimate and what is missing. It never buys anything. | A person buys |
| Preflight | A deliverability check of each sending mailbox through DeliverProbe, shown as a report. | A failing check blocks launch |
| Launch approval | A card with what is sent, to whom, from which mailboxes, the preflight result and a forecast. | A person approves |
| Follow-up | Reply triage, suggested next steps, reply drafts, a weekly report and A/B suggestions. | You act within your limits |
Autonomy levels
You choose how much the agent may do on its own, per workspace. The levels are set by a person, and the agent cannot raise its own.
| Level | What the agent does |
|---|---|
| Level 0 | Proposes only. Nothing happens until a person acts. |
| Level 1 | Acts after a person approves each action. |
| Level 2 | Acts on its own inside the caps and budgets you set. A person switches it on for a workspace. |
What the agent can and cannot do
The table holds at every autonomy level. The limits sit in the policy check behind the console, the API and the MCP server, not in a prompt.
| Action | Agent |
|---|---|
| Read caps, budgets and approval rules | Yes |
| Search for leads under a budget | Yes, with the approval your policy requires |
| Draft sequences, replies and A/B variants | Yes |
| Recommend domains and mailboxes | Yes |
| Buy domains or mailboxes | No. A person buys |
| Change caps, budgets, autonomy level or approval rules | No |
| Start the first campaign, send in bulk or change recipients | Only after a person approves |
| Override a failed deliverability check or lift a suppression | No |
Guardrails around the agent
- Caps, budgets and approvals are checked on every action, and a kill switch stops the agent and the sending.
- Outside text is data. Replies, websites and lead notes are screened before an agent reads them, so they cannot give it instructions.
- Every step is logged, with the tool calls the agent made, and changes to sensitive settings go to the audit log.
- Suppression is absolute. An address that unsubscribed or complained is never contacted again from that workspace, in any channel. It is the one rule that cannot be turned off.
The platform warns and recommends, and the client decides. For the deeper picture, read Safe AI agent access to outbound sales and security and data handling.
Choosing an AI outreach tool: seven questions
Whichever AI outreach tool or sales outreach tools you evaluate, ask the vendor these before you hand over a mailbox.
- Where do the limits live: in a prompt, or enforced by the server?
- Can the agent change its own caps, budgets or approval rules?
- Can it spend money or buy infrastructure without a person?
- Is there a kill switch that stops the agent and the sending?
- Is every step and tool call logged?
- Is text from replies and websites treated as data, not instructions?
- Can an unsubscribed address ever be contacted again?
Dooxout's answers are on security, in the MCP quickstart and in this page's tables.
Where to go next
- Size the sending side on cold email infrastructure and learn what preflight checks on email deliverability.
- See the add-on units that an agent spends on pricing.
- Run the agent for clients with agency workspaces and white label cold email.
- Connect channels and tools on integrations, read the blog or return to the home page.
AI outbound questions
What is an AI SDR?
An AI SDR is an agent that does the routine work of a sales development rep: researching an audience, finding leads, drafting sequences and replies. In Dooxout the SDR agent does that inside limits the server enforces, and people approve the steps that matter.
Does the AI agent take over my sales team?
No. The agent prepares plans and drafts and handles routine steps at the autonomy level you set. People approve the first campaign, mass sends and changes of recipients, and they make the purchases and the decisions.
Can the agent buy domains and mailboxes?
No. It recommends how many you need and what they cost, and a person buys them, at every autonomy level. See cold email infrastructure.
Can I use my own agent, such as Claude or Cursor?
Yes. Connect it over the email MCP server with a token that has its own role, scopes and budget. The same limits apply as to the built-in agent. See the MCP quickstart.
What do the autonomy levels mean?
Level 0 only proposes, level 1 acts after approval and level 2 acts on its own inside your caps and budgets. A person sets the level, and the agent cannot change it. See security.
Run the SDR agent on your own brief
Request a demo and bring a product description. We reply within one business day.