Skip to content
← Notes
3 min readproduct

Why we keep two of three campaigns on a human leash

Campaign C runs unattended. Campaigns A and B still stop at a person before every send, and that is not a temporary state.

Keldari runs three campaign states for every tenant: A, B, and C. C is autonomous — it sources, scores, drafts, and sends without a person in the loop for any individual message. A and B are not. Every draft those two campaigns produce sits behind a human contract gate before it goes out. People who hear “autonomous SDR” and then see two-thirds of the campaign states still gated sometimes ask if that is a hedge, or a feature we have not finished yet. It is neither. It is the actual design.

The distinction between A, B, and C is not about capability. The drafting model does not get better at C. Sourcing does not skip steps for A. The only thing that changes is who signs off on the send, and that changes because the risk profile of the message changes, not because we trust the system more or less on a given day.

Campaign A carries first-touch outreach into cold accounts where a wrong read on the target profile costs you a relationship you have not built yet. Campaign B carries the reply-handling sequences, where the model is responding to something a real person just said and a misread tone or a wrong fact lands directly in front of that person, not into a queue. Both of those are situations where a bad message has a specific, findable person on the other end of it, and a specific, findable person on our end who should have seen it first. Campaign C runs the later-stage nurture cadence for accounts that have already been qualified and have already replied favorably at least once — a narrower, lower-variance slice of the funnel where the cost of an autonomous miss is a slightly awkward follow-up email, not a burned first impression.

We built the contract gate once, for every campaign, and Solara Pro runs it in production on all three states today, no exceptions carved out for the launch account. What differs by state is only whether a draft clears that gate by itself (C) or waits for a person to clear it (A and B). The gate’s logic does not know or care which state a given draft came from.

The honest reason we have not moved A and B to autonomous is not technical maturity. It is that we do not yet have enough production hours on those specific message types, from enough tenants, to be confident the failure modes we would ship autonomously are the failure modes we have actually seen and priced. C earned its autonomy by running long enough, on real replies, that we could watch what it got wrong and decide those misses were acceptable. A and B have not had that runtime yet. When they do, and if the misses stay small and recoverable, we will move them. Until then, the leash is not caution theater. It is the actual boundary of what we have evidence for.

The uncomfortable version of this note is that “autonomous SDR” as a category name promises more than any single tenant’s production data can back up on day one. We would rather ship the boundary honestly, in the product itself, than imply a confidence we have not earned in the two campaign states where a miss actually costs something.