Setting boundaries for sales AI

What should AI never be allowed to do in sales?

Authority levels lighting in sequence

There probably isn't one universal list of things AI should never be allowed to do in sales.

Sending a routine meeting confirmation is very different from responding to a complaint.

Updating a customer's phone number is very different from marking a major opportunity as lost.

Retrieving an approved price is very different from deciding to offer a 25% discount.

AI might technically be capable of all of them.

That doesn't mean it should have the same authority over all of them.

A better question is:

WHAT HAPPENS IF THE AI GETS THIS WRONG?

The greater the consequence, the stronger the case for human control.

Can do
Read CRM
Write email
Change record
Create quote
Send message
Apply discount
≠
May do
Defined by:
Consequence
Reversibility
Certainty
Authority

Capability isn't authority.

Capability isn't authority

This distinction runs through everything we build around agentic selling.

An AI system may be capable of:

But:

CAN DO

does not automatically mean:

MAY DO.

The business decides the second one.

Start by separating access from action

Imagine you connect AI to your CRM.

People sometimes describe that as:

"The AI has CRM access."

That's too vague.

There are two completely different questions.

What can it see?
  • Customer details?
  • Emails?
  • Opportunity values?
  • Pricing?
  • Notes?
  • Contracts?
What can it do?
  • Create records?
  • Change fields?
  • Send messages?
  • Alter prices?
  • Mark deals lost?
  • Delete data?

Access and authority should be designed separately.

INFORMATION ≠ PERMISSION.

Four questions determine how much control AI should have

For every action, ask:

1. Consequence

If this is wrong, how much does it matter?

2. Reversibility

Can we easily undo it?

3. Certainty

Can the system reliably know when the action is appropriate?

4. Authority

Is this a decision the business actually wants software making?

Those four questions are more useful than a blanket rule that says:

"AI should never send emails."

Because sometimes sending an email is trivial.

Sometimes it absolutely isn't.

EASY TO REVERSE HARD TO REVERSE → LOW CONSEQUENCE HIGH CONSEQUENCE → Create draft Create follow-up task Send routine confirmation Change deal value Offer major discount Agree contractual term

Illustrative only. Authority depends on your business and workflow.

Example: sending an email

Consider these two messages.

Email A
"Your meeting is confirmed for Tuesday at 10am. Here's the link."

Low ambiguity.

Easy to check.

Limited consequence.

Highly reversible.

Now:

Email B
"We're sorry you're unhappy. We've reviewed your complaint and agree to refund the full project fee."

That's customer communication too.

But it contains:

Same action:

SEND EMAIL.

Completely different authority decision.

So what should AI be particularly careful with?

There are several areas where consequences can increase quickly.

1. AI shouldn't invent prices

AI may be able to:

That's different from making up a price because one isn't available.

For example:

Good

Approved installation price: £2,500.

AI retrieves:

£2,500

Not good

No approved installation price found.

AI estimates:

£2,250

because that seems reasonable.

If the price isn't known:

DON'T GUESS.

Pricing itself has several authority levels

Don't treat "pricing" as one permission.

01
RETRIEVE
Use an existing price.
02
CALCULATE
Apply an approved formula.
03
PREPARE
Put approved pricing into a quote.
04
RECOMMEND
Suggest a commercial price.
05
CHANGE
Alter the normal price.
06
DISCOUNT
Make a commercial concession.

More commercial judgement → more human control.

Those are very different jobs.

The further down the list you go, the stronger the case for human judgement.

2. AI shouldn't make commitments it isn't authorised to make

A customer asks:

"Can you guarantee this will be delivered by 1 November?"

The AI searches the available information.

It finds that normal delivery is approximately six weeks.

It replies:

"Yes, absolutely."

Problem.

An estimate is not necessarily a commitment.

A sensible workflow might instead say:

Needs you
Customer has requested guaranteed delivery by 1 November.
Normal estimated delivery falls within this period.
No approved guarantee found.
Recommended action: Confirm with delivery team.
[Review]

That's the system doing its job properly.

3. AI shouldn't turn uncertainty into certainty

This is one of the most important behaviours to control.

Imagine a prospect says:

"We'll probably move ahead once Finance has looked at it."

AI updates:

Deal stage

Verbal agreement

But that's not what the customer said.

They said:

probably.

and:

once Finance has looked at it.

A better interpretation might be:

Current position

Positive interest expressed.

Finance review still required.

Suggested stage

Review required.

UNCERTAIN ≠ CONFIRMED.

Your AI system should be allowed to preserve uncertainty.

4. AI shouldn't silently make consequential CRM changes

Some CRM updates are low consequence.

Contact number

Old → New.

Probably straightforward.

Others aren't.

Deal value

£15,000 → £150,000.

Stage

Proposal → Lost.

Owner

Sarah → James.

Status

Active customer → Closed.

These changes can affect:

The more consequential the field, the more useful review becomes.

A CRM permission model might look like this

CRM actionSensible starting authority
Read contactAutomatic
Add meeting noteAutomatic
Create follow-up taskAutomatic within rules
Update factual contact detailAutomatic / review
Suggest next-action dateRecommend
Change opportunity stageRecommend / approve
Change deal valueRecommend / approve
Mark opportunity wonHuman approval
Mark opportunity lostHuman approval
Delete recordHuman

The exact model will vary by business. That's the point. You design it.

5. AI shouldn't delete important information casually

Deletion is different because recovery may be difficult or impossible.

An AI system might identify:

That doesn't necessarily mean:

DELETE IT.

A safer pattern may be:

And if the AI doesn't need deletion authority to do its job:

don't give it deletion authority.

6. AI shouldn't independently handle every complaint

A customer says:

"Thanks, can you resend the meeting link?"

Routine.

A customer says:

"Your team has caused us a serious financial loss and I'm considering legal action."

Not routine.

Both arrive through email.

Both are technically messages.

But one should probably take a completely different path.

A useful workflow should recognise situations that require escalation.

ROUTINE→Continue.
SENSITIVE→Escalate.
HIGH CONSEQUENCE→Stop and bring in a person.

7. AI shouldn't negotiate beyond defined limits

Negotiation involves more than generating persuasive language.

A customer might ask:

"If we sign today, can you reduce the price by 20%?"

AI could easily write:

"Absolutely, we can offer 20% off if you confirm today."

The words are easy.

The authority isn't.

A safer workflow might know:

Automated authority

Discount up to 5% for approved product category.

Customer requested:

20%

Therefore:

ESCALATE.

The AI doesn't need to become a negotiator simply because it can produce negotiating language.

8. AI shouldn't invent product or service capabilities

This is particularly dangerous because generative AI can make invented capabilities sound completely plausible.

Customer asks:

"Does your system integrate with Platform X?"

The information source contains nothing confirming that.

A bad AI says:

"Yes, we offer seamless integration with Platform X."

A useful AI says:

Information not found

No approved information confirming Platform X integration.

Next action: Technical review.

That's a success.

"I DON'T KNOW" CAN BE THE CORRECT ANSWER.

9. AI shouldn't decide a customer isn't worth pursuing without appropriate rules

AI can help qualify opportunities.

But imagine it decides:

"This lead is unlikely to convert."

and silently stops follow-up.

Why?

Perhaps:

That's a consequential decision.

There is an important difference between:

PRIORITISE

and:

ABANDON.

AI might help identify which opportunities need attention.

But automatically removing opportunities deserves much more scrutiny.

10. AI shouldn't keep contacting someone indefinitely

An AI follow-up system needs stop conditions.

Without them, "persistent sales agent" can become:

software that annoys people very efficiently.

Define when it stops.

For example:

A useful sales agent knows when not to continue.

Stop conditions are part of the design

Every agentic workflow should answer:

WHEN DOES THIS STOP?

Suppose the job is:

"Follow up this opportunity appropriately."

The stop conditions might include:

The goal isn't endless autonomy.

It's controlled continuation.

11. AI shouldn't hide what it has done

If AI can act in your sales systems, you should be able to understand what happened.

For example:

Acme Ltd
AI action: Updated target date.
Previous: December.
New: January.
Reason: Customer email on 17 September: "Project has moved back until January."

That's far more useful than:

Record updated successfully.

For important actions, visibility matters.

12. AI shouldn't quietly expand its own role

Suppose you build an AI workflow to:

Prepare meeting briefs.

It needs read access to relevant CRM records.

Later somebody decides:

"While it's in there, it could update the CRM too."

Then:

"And send the follow-up."

Then:

"And create the quote."

Then:

"And adjust the opportunity."

The system has moved from:

READ

to:

CHANGE + SEND + COMMIT

without anyone properly redesigning its authority.

Every new capability should be treated as a new permission decision.

MORE CAPABILITY SHOULD NOT QUIETLY BECOME MORE AUTHORITY.

The Authority Ladder

A useful way to design this is:

01
READ
AI can inspect information.
02
RECOMMEND
AI suggests what should happen.
03
PREPARE
AI prepares the work.
04
ACT WITH APPROVAL
A person confirms.
05
ACT WITHIN LIMITS
Routine defined actions happen automatically.
06 ESCALATE
Anything outside those limits goes to a person. Escalation can happen from any level when something falls outside the system's information, certainty or authority.

The objective isn't to push every process towards Level 5.

The objective is to find the appropriate level for each action.

One AI sales agent can have several authority levels

Imagine an enquiry-handling agent.

It can:

That's much more realistic than saying:

"Our AI agent has autonomy."

Autonomy over what?

That's the question.

Consequence matters more than whether something is customer-facing

It can be tempting to say:

"Internal actions can be automated. Customer-facing actions need approval."

That's too simple.

An internal action such as:

MARK £100,000 OPPORTUNITY LOST

may have greater consequence than sending:

"Your meeting is confirmed for Tuesday."

So don't divide the world into:

Look at the action itself.

Reversibility matters too

Compare:

Create draft

Wrong? Delete it. Easy.

Send email

Wrong? You can apologise, but you can't unsend what the customer read.

Change CRM field

Often reversible.

Delete customer record

Potentially difficult.

Agree contractual term

Much harder.

The harder something is to reverse, the stronger the case for control before it happens.

A simple consequence test

Before giving AI authority over an action, ask:

IF THIS IS WRONG...

The answers tell you a lot about the right authority level.

What about high-value sales?

Value alone isn't the only consideration.

But it changes the consequence.

An automated follow-up on a £50 standard product enquiry may be perfectly reasonable.

An automated message during a £500,000 negotiation may deserve very different controls.

Same technology.

Different context.

That's why authority belongs in the workflow design rather than being a universal AI setting.

Approval isn't the same as checking everything

There's another trap.

You decide AI needs human oversight.

So every action produces:

Approve?
Approve?
Approve?
Approve?

All day.

Now the human has become a button-clicking component in the automation.

That's not necessarily good control.

Good approval should happen where judgement matters.

And when approval is needed, show enough information to make the decision.

A useful approval looks like this

Northstar needs you
Customer requested a 15% discount.
StandardPermitted discount up to 5%.
ProposalCurrent proposal £18,500.
ReasonBudget reduced following internal review.
AI ACTION
No discount offered.
RECOMMENDED NEXT STEP
Commercial review.
[Review opportunity]

AI prepares the decision. You make it.

The human doesn't have to investigate from scratch.

AI prepares the decision.

The person makes it.

Human in the loop only works if the human adds something

This phrase gets used constantly:

Human in the loop.

But putting a human somewhere in the process isn't automatically useful.

Ask:

WHAT JUDGEMENT IS THE HUMAN PROVIDING?

If the person is approving a completely routine action 200 times a day, perhaps the boundary is wrong.

If they're reviewing:

their involvement has a purpose.

Put people where human judgement actually changes the quality of the decision.

What happens when AI is uncertain?

Give it a failure path.

Stop

Don't take the uncertain action.

Explain

Show what is missing or conflicting.

Escalate

Bring in the right person.

For example:

Technical question

Customer asks whether Product A supports Platform X.

No approved compatibility information found.

STOP · No response sent.
EXPLAIN · Compatibility cannot be confirmed from available information.
ESCALATE · Technical review requested.

That is good agentic behaviour.

The AI doesn't have to finish every job

This is a really important mindset change.

An AI agent's job isn't necessarily:

Complete everything without human help.

It might be:

Move this process forward until either the job is complete or human judgement is required.

That's much safer and often much more useful.

A successful outcome can be:

DONE.

Or:

NEEDS YOU.

Both move the work forward.

Start with the least authority needed

Suppose you're introducing AI into sales follow-up.

Don't start with:

"Send whatever follow-up you think is appropriate."

Start with:

Watch

Identify what needs follow-up.

Then:

Recommend

Tell us what should happen.

Then:

Prepare

Draft it.

Then:

Act with approval

Person sends.

Once the process is understood and trusted, selected routine cases might move to:

ACT WITHIN LIMITS.

Autonomy can be earned.

It doesn't need to be granted on day one.

A practical AI Sales Control Check

Before giving AI a new sales action, ask:

1
DOES IT NEED THIS PERMISSION?If not, don't give it.
2
WHAT COULD GO WRONG?Be specific.
3
HOW CONSEQUENTIAL WOULD A MISTAKE BE?Low, medium or significant?
4
CAN WE UNDO IT?Easily?
5
WHAT INFORMATION IS THE DECISION BASED ON?Can we trust it?
6
WHAT ARE THE LIMITS?Price? Frequency? Customer type? Action type?
7
WHEN MUST IT ESCALATE?Define the exceptions.
8
CAN WE SEE WHAT HAPPENED?Important actions should be traceable.

If you can't answer those questions, the system probably isn't ready for more authority.

Don't use AI permissions as a substitute for process design

Suppose nobody in the business agrees:

You don't have an AI permissions problem.

You have a business-process problem.

AI simply makes it visible.

Define the process first.

Then encode the boundaries.

What should a small business do?

Keep it simple.

You don't need a 94-page AI governance manual before AI prepares a meeting brief.

Start by listing what the workflow can:

SEE

and what it can:

DO.

Then mark actions:

That's already a useful control model.

More autonomy isn't the goal

Imagine two systems.

System A
  • send,
  • discount,
  • change CRM stages,
  • delete records,
  • create proposals,
  • and contact customers independently.
System B
  • prepares enquiries,
  • keeps routine information current,
  • makes sure follow-up isn't forgotten,
  • and escalates anything commercially important.

System A has more autonomy.

That tells us nothing about which system creates more business value.

AUTONOMY IS A DESIGN CHOICE.

VALUE IS THE OBJECTIVE.

So, what should AI never be allowed to do in sales?

There isn't a universal list.

But AI should not be given unchecked authority simply because it is technically capable of an action.

Be particularly careful where AI could:

For every action, ask:

WHAT'S THE CONSEQUENCE IF IT'S WRONG?

CAN WE UNDO IT?

DOES THE AI HAVE ENOUGH INFORMATION?

DOES THIS DECISION ACTUALLY BELONG TO SOFTWARE?

Then give it the least authority needed to do the job properly.

Because the question that matters isn't:

HOW AUTONOMOUS CAN WE MAKE THIS?

It's:

HOW MUCH AUTHORITY DOES THIS PARTICULAR JOB ACTUALLY NEED?

That's how you put AI into sales without quietly handing it the keys to the business.

Quick answers

Should AI be allowed to send sales emails automatically?

It can be appropriate for defined, routine communications where the context and rules are clear. Sensitive, unusual or commercially consequential messages may warrant human review.

Should AI be allowed to offer discounts?

AI can potentially apply discounts within clearly defined approved rules. Unusual or larger commercial concessions may be better escalated to a person.

Should AI change CRM records automatically?

Some low-risk factual updates may be suitable for automatic changes. More consequential fields such as deal value, opportunity stage, won/lost status or deletion may need stronger controls.

Should AI negotiate with customers?

AI can help prepare information or responses, but independent negotiation can involve commercial judgement and commitments. Businesses should define clear limits and escalation points.

Should AI be allowed to delete CRM data?

Only where there is a genuine need and appropriate safeguards. In many sales workflows, the AI does not need deletion authority at all.

What happens if an AI sales agent doesn't know the answer?

A well-designed workflow should be able to stop, explain what is uncertain and escalate to a person rather than inventing an answer.

How much autonomy should an AI sales agent have?

Enough to perform its defined job safely and usefully. More autonomy is not inherently better.

What is human-in-the-loop AI?

It describes workflows where a person remains involved in selected decisions or actions. Human review is most useful where genuine judgement, uncertainty or consequence exists.

Next

CONTROL IS ONE PART OF THE DECISION. COST IS ANOTHER.

So what does an AI sales agent actually cost?

The answer depends heavily on whether you're buying a tool, connecting existing systems or building something around your own process.

Or go deeper into control:

Related reading: what is an AI sales agent, AI sales agent vs sales automation, can AI update my CRM, can AI write sales proposals, can AI follow up sales leads, can AI qualify sales leads, how a small business can use AI for sales, and build an agentic sales workflow.

Related