“A person is always in the loop” is an easy thing for any vendor to say. This page names the specific gates instead: the risk score that has to clear before AutoApply opens a browser session, the confidence threshold a draft has to clear before it can even be generated unsupervised, the click that always has to happen before a draft reaches a funder, and the audit row written every time an agent makes a decision on its own.
This is the real per-organization configuration schema, not an illustration — nine independent settings, every one off until an owner or admin turns it on. A writer or viewer account cannot change any of them.
When any of the toggles above is on and an agent acts without a person driving it in that moment, the decision is written to an audit trail: which agent made it, what it decided, its reasoning, its confidence score, the action actually taken, and whether that decision is flagged as requiring human review. A flagged row carries the reviewing person’s identity, the time they reviewed it, and their verdict — an actual record, not a log line nobody reads.
Above every other check, automated submission can be halted at four levels — platform-wide, a specific domain, a specific funder, or a single organization — and each one is checked before an item runs. Stopping one funder’s submissions doesn’t require pausing the whole platform, and a problem traced to one organization doesn’t require touching anyone else’s queue.
An agent-authored draft still gets created and stored even though it’s structurally blocked from submission — a reviewer still has to actually open the Draft Queue and act on it. Turning on the drafting toggle produces more items in a review queue, not fewer things for a person to look at.
The non-email outreach tasks (LinkedIn, phone, mail) track whether a person marked the task complete, not whether the message was actually sent, the call actually placed, or the letter actually mailed outside the platform.
Security model, data handling, and the platform-wide governance page these gates feed into.
Watch the risk engine, the CAPTCHA check, and the approval click happen on a real application, not a diagram of them.