Skip to the article
Cordanis

Governance

What AI should prepare and what it should never execute alone

Sales AI should prepare work that improves a seller's judgment: research accounts, organize evidence, identify coverage gaps, and draft reviewable actions. It should never send messages, enroll contacts, change CRM records, spend scarce resources, or delete data on its own. Preparation may scale; authority over consequential action should remain specific, visible, and human.

Two people passing a worn blue account folder between closing elevator doors.
Two people passing a worn blue account folder between closing elevator doors.
← All research

The boundary is consequence, not intelligence

The useful question is not whether an AI system is capable of taking an action. It is what happens if the action is wrong.

A weak account summary wastes a few minutes and can be rewritten. A message sent to the wrong executive cannot be unsent. A mistaken CRM update changes the shared record another person may trust. An enrollment can start a sequence of future work. A data purchase can consume credits. Deletion can erase something the team still needs.

The same permission should not cover all of these acts. AI can work broadly where the result remains visible and revisable. Its authority should narrow when the work crosses into a customer's inbox, changes a record coworkers rely on, spends a limited resource, or cannot be reversed.

That line does not diminish the AI. It makes the system useful at scale without confusing capability with authority.

What AI should prepare

Preparation turns scattered context into something a seller can inspect and use. In a complex sales motion, that can include:

  • researching an account and organizing the supporting evidence;
  • ranking accounts against a visible set of criteria;
  • mapping a buying committee and showing relationship gaps;
  • drafting a shared outreach sequence;
  • preparing a meeting brief or an opportunity update;
  • identifying work that is ready, incomplete, stale, or blocked;
  • proposing a specific next action with its reason and source context.

Prepared work should be visible before it matters, revisable without hidden side effects, and clear about where its facts came from. A seller should be able to correct the account, change the message, reject the recommendation, or do nothing.

This is where scale is valuable. AI can prepare work across accounts while the seller is focused elsewhere. That effort helps only if it returns in a form the seller can judge.

What AI should never execute alone

The other side of the line contains actions that create an external effect or change shared operating state. The important examples in sales are simple:

Action Why it needs a person
Send a message It reaches a customer in the seller's name and cannot be recalled reliably.
Enroll a contact It commits that person to future outreach, not just the first message.
Change a CRM record It alters shared state that forecasting, handoffs, and other workflows may use.
Spend enrichment or data credits It consumes a scarce resource and may write provider data into the account record.
Delete or suppress data It can remove access or change who may be contacted.
Represent an outcome A meeting, reply, or opportunity should come from observed evidence or a person's attestation, not the model's confidence.

This is not an argument against every form of automation. A configured sync that copies a verified field under a known rule is different from a model deciding, from changing context, that a CRM record should be altered. The boundary concerns discretionary model action. Deterministic operations can run automatically when people have defined their scope, inputs, and failure behavior in advance.

Human control must be more specific than a general setting that says the AI is allowed to act. Before words leave in the seller's name, the seller should see the recipient and the message. Approval of one message is not approval of every future message. Permission to read a CRM is not permission to change it.

In Cordanis, the Assistant can research, explain, draft, and propose. It cannot approve its own proposal or send an email. Consequential actions pass through a separate authenticated confirmation and a validated operation. The point is not to add ceremony. The point is to keep the person who owns the relationship in control of the exact act performed in their name.

Approval is not a guarantee

A human can approve the wrong thing. A polished review screen can still hide a bad assumption. Keeping a person on the boundary does not make the work correct by itself.

Approval does something narrower and more important. It assigns authority. It creates a moment where the exact action can be inspected, edited, or refused. It also leaves a clear record of what was proposed, what the person saw, what they approved, and what actually happened.

That is why review quality matters as much as the presence of a button. A confirmation that hides the recipient, message, changed fields, or cost encourages rubber-stamping. So does a blanket approval granted before the system knows what it will do.

Explicit intent should shorten the path, not erase the boundary

There is a difference between asking twice and reviewing once.

If a seller says, "Send this approved message to Maya," the system does not need to ask whether they really meant to prepare a draft. Their intent is clear. It should show the exact message and recipient in the send surface and let the seller complete that action directly.

Clear language can remove conversational friction. It should not allow a model to translate a sentence into an invisible external effect. The faster path is still a visible path.

A practical test

Ask four questions about any proposed AI action:

  1. Can the result be inspected before another person or system relies on it?
  2. Can it be changed or discarded without an external effect?
  3. Does it spend money, consume a scarce resource, or commit future work?
  4. Is the action performed in a person's name or against a shared record?

If the first two answers are yes and the last two are no, preparation can usually run broadly. If the action reaches a customer, commits future work, spends resources, or changes a record coworkers depend on, require a person to approve that specific action.

The line may move as systems improve and teams learn what they can trust. The principle should not: scale preparation, preserve human authority over consequence.


Cordanis is the operating system for complex B2B sales. It prepares work from shared account context and keeps consequential action behind the seller. Read What is an AI sales harness? and How Cordanis is secured.

Keep reading

All research

The New York City skyline rising across dark water at blue hour.

Bring your book.

Bring your accounts to a working session. Leave with a plan for tomorrow.

Book a working session