AI Outbound · Case Study

How Autonomous AI Agents Can Run Your Outbound

Primary operating evidence
One verified daily cohort inside an outbound system with more than 20 leads.
An anonymized TCP Hermes Slack connector readback for one July 2 cohort, showing eight leads added, nine total leads at that checkpoint, nine connection requests sent, and one accepted connection.
This dated July 2 readback proves one enrollment batch, not the total size of the system. The broader workflow handled more than 20 leads across discovery, QA, enrollment, and provider states. The readback is reformatted for privacy and is not a native Slack screenshot.

A client asked Ink Persuasion for an autonomous outbound operator: find qualified companies, write signal-based outreach, run follow-ups, watch replies, and keep the CRM current. The client chose LinkedIn for this deployment. We made that constrained channel work, while building the underlying agent so the same operating model can run even more fluidly over email.

This was not a chatbot waiting for a prompt. It was an operating agent with scheduled work, source-backed research, copy rules, sending access, CRM permissions, monitoring, and exception handling. Once the team set the strategy and guardrails, it did not stop to ask what to send for every lead.

Why LinkedIn: the client specifically wanted this system to operate on LinkedIn. That meant working around a connection-acceptance gate, sender state, platform timing, and imperfect provider readback. We made it work. Email removes the connection-acceptance bottleneck and gives an autonomous agent a more direct path from a send-ready record to a sequenced message, reply, and CRM event. It still needs deliverability, suppression, compliance, and sender guardrails, but the orchestration can be substantially more fluid.

System architecture
Four controlled layers replaced a pile of manual handoffs.
1. DiscoverFresh signal and portfolio research

Scheduled runs searched for recent funding, debt, acquisition, expansion, and portfolio-company signals.

2. QualifyICP, identity, and copy QA

Freshness, geography, stage, role, company match, dedupe, and evidence rules could reject a lead before outreach.

3. ExecuteClient-selected LinkedIn sequence

Qualified profiles entered one live campaign with a blank connection request and three signal-based post-acceptance DMs.

4. OperateAttio lifecycle plus Hermes monitoring

CRM records, notes, campaign status, replies, failures, and Slack handoffs were tracked from one client-specific agent.

Humans approved the strategy, copy system, access, and guardrails upfront. The agent then operated independently inside those boundaries instead of requesting approval for every connection or message.

What an autonomous AI outbound agent actually does

The answer is not one model or one automation tool. A useful autonomous outbound agent connects research, qualification, message generation, sequence execution, reply handling, and CRM state without allowing any single provider response to become the whole truth.

It wakes up on schedule, searches the allowed signal lanes, rejects weak matches, prepares copy from an approved framework, enrolls qualified leads, watches delivery state, follows up, routes replies, and updates the system of record. People define the commercial judgment and intervene on exceptions. They do not need to operate every handoff.

Step 1: find signals, then prove the lead fits

The discovery agent ran twice daily in UK time. Its source lanes included recent LinkedIn posts, funding and capital events, and a bounded portfolio-directory lane for accelerators such as Y Combinator and Techstars. Directory membership was only a clue. A company still needed a fresh original event, an in-scope market, and a valid decision-maker.

This was an unusually narrow market. The target was not every B2B company; it was a small set of founder-led technology companies with large, recent financing events and a plausible credit need. Companies raising tens or hundreds of millions of dollars do not appear every day. Across the bounded sources and operating period, the team estimates that the system captured roughly 98% of the observable companies that met the agreed criteria. That is an internal coverage estimate for this defined lead pool, not an audited share of every funded company.

Each accepted record needed a dated source, an evidence excerpt, the company, the contact, the ICP reason, and personalization context. Deterministic checks then looked for stale signals, out-of-scope geographies, weak roles, duplicates, missing evidence, and fabricated fields. A second model review checked the same output before it could move forward.

This mattered in practice. One high-profile candidate was stopped before contact when HeyReach's live profile readback showed a company mismatch. Another historical row was later removed when the provider resolved the person as an editor rather than a founder. The visible failure count therefore included a deliberate ICP cleanup, not a sending malfunction.

Step 2: write personalized copy and enroll the same profile

Leads that passed the configured gates moved into a signal-to-copy layer. The team had already defined the copywriting framework, acceptable personalization signals, financing angles, sequence timing, and fallback language. The agent generated three LinkedIn messages tied to the source event and financing relevance.

It did not ask us to choose a connection request or approve each DM one lead at a time. In this production sequence, the connection request was deliberately blank. After acceptance, the agent viewed the profile, waited for the configured delay, sent DM1, followed up, and sent a closing message. Any reply ended the automated path.

The enrollment helper checked that the profile passed the founder-level role rule, the personalized fields existed, the campaign, list, and sender matched allowlists, the UK schedule was correct, and the profile appeared in both the live list and campaign readback.

This is stricter than accepting a successful API response. HeyReach's own guidance says leads can be added to a live campaign by API or integration and recommends checking the campaign totals and pending state after adding them. Its status documentation distinguishes Pending, which means a lead has not entered the campaign yet, from In Sequence, which means actions are being executed.

Step 3: monitor delivery and keep Attio current

A client-specific Hermes agent monitored the live campaign and reply state on a ten-minute schedule. It separated campaign status from lead status, checked for missing senders and provider failures, and stayed silent when there was nothing actionable.

The earlier July 2 cohort produced a direct CRM proof: nine Attio lifecycle records were written with the status HeyReach Listed, and the Slack readback reported zero failed updates. The Attio API supports creating and updating people or company records; this implementation also preserved existing records where possible and blocked delete requests.

The reply path was designed to classify responses, update lifecycle fields, add notes or tasks, and surface action-needed events. However, the published live checkpoints contained zero new replies. The reply-stage writeback was implemented and tested, but this case study does not claim a real positive-reply CRM transition that had not happened yet.

The system handled more than 20 leads, not eight

Evidence by checkpoint
The eight-lead updates were batches inside a system that handled more than 20 leads.
Broader system20+ leads handled

Records moved through discovery, evidence checks, copy QA, enrollment, active delivery, and intentional removal states.

Later live snapshot19 active, 18 requests sent

Three connections had been accepted, ten leads were still in sequence, and active failures were zero.

July 2 checkpoint8 added, 9 CRM rows written

One daily batch produced a nine-row Attio lifecycle readback with zero failed updates.

July 13 expansion8/8 requests sent

All eight reviewed profiles appeared in the live campaign and later reached ConnectionSent with zero batch errors.

The provider snapshot contained 19 active leads. The wider system count also includes candidates processed through research and QA plus an intentionally removed non-ICP row. The team therefore describes the implementation as a 20-plus-lead system, while preserving the exact 19-active campaign checkpoint.

What the system proved

What this production window did not measure

Autonomy came from guardrails, not repeated permission

The agent could not create a new daily campaign, start an unapproved campaign, use an unapproved sender, delete Attio data, duplicate an active company contact, or call list presence a completed send. It also kept the client's memory isolated from the default Hermes profile.

Those were system-level controls, not a queue of messages waiting for manual approval. Once the ICP, signal rules, personalization method, sequence, sender, and campaign were configured, the agent could discover, qualify, write, enroll, monitor, follow up, and update records autonomously. It escalated exceptions instead of asking for routine decisions again.

The most important rule was simple: an accepted lead was not complete until copy, enrollment, list readback, campaign readback, and delivery state all agreed. That is the difference between a demo and an operated B2B sales pipeline.

For the broader operating contract, read what belongs in a sales agent runbook. For the data layer underneath provider handoffs, see how to build a single source of truth for lead lists. For a cross-channel implementation, use the LinkedIn engagement to cold email handoff to coordinate identity, suppression, and reply ownership.

Why email can make the same agent more fluid

LinkedIn was the client's requirement, and it introduced unavoidable waiting: a prospect generally had to accept a connection before the personalized DM path could continue. The agent also had to reconcile platform and provider states such as Pending, In Sequence, Paused, Failed, and Finished.

An email version can move directly from a verified send-ready contact into a sequenced message and follow-up path. Modern email APIs expose campaigns, leads, sending state, and scoped access, so the agent can coordinate research, copy, delivery, reply classification, and CRM writeback through a cleaner event chain. Email is not effortless: domain health, throttling, unsubscribe handling, suppression, compliance, and reply monitoring remain mandatory. But for an autonomous outbound operator, it is usually a substantially smoother execution channel.

The capabilities are broader than one campaign

The useful limit is not a fixed list of bot features. It is the quality of the agent's access, evidence, and guardrails. The same operating layer can discover accounts, enrich contacts, deduplicate records, select an approved angle, write channel-specific copy, launch sequences, follow up, classify replies, stop automation, update the CRM, create tasks, alert the right person, and explain why a record changed.

That is why we describe this as an autonomous outbound agent rather than a LinkedIn automation. LinkedIn was one client-selected execution surface. The real product was the decision and operating layer around it.

How much would a system like this cost?

Pricing depends on scope, integrations, data readiness, compliance, and how much of the process already exists. For a current external benchmark, Tenfold's June 2026 pricing guide places autonomous workflow agents that call tools and update records at $30,000 to $120,000.

Ink Persuasion can scope a focused outbound implementation like this from roughly one-fifth of that $30,000 entry point, subject to the final systems, sender setup, and data condition. The point is not a cheaper clone. It is a tighter build around the workflow you actually need, with proof at every handoff.

Frequently asked questions

What is an autonomous AI outbound agent?

It is an operating system that moves a prospect from discovery through qualification, personalized outreach, follow-up, response handling, and CRM state. It runs routine work independently inside predefined commercial and technical guardrails.

How do you build a B2B sales pipeline with AI?

Start with a versioned ICP, source-backed signals, deterministic rejection rules, and a traceable lead record. Add copy generation only after qualification, then connect an allowlisted sending system and require provider readback before treating a lead as active.

Does the agent need approval before every message?

No. The team should approve the ICP, allowed signals, personalization framework, sequence, sender, compliance rules, and escalation policy upfront. Once those controls are in place, the agent can run routine sends and follow-ups autonomously while escalating exceptions.

Can the same outbound agent run email?

Yes. The research, qualification, copy, monitoring, reply, and CRM layers are channel-independent. Email replaces LinkedIn's connection-acceptance gate with deliverability, sender-health, suppression, and compliance controls.

Should an AI sales agent update the CRM?

Yes, when it is limited to approved fields, preserves existing records, records provenance, and blocks destructive operations by default. CRM writes should be verified independently from campaign writes.

Is one evergreen campaign better than a new campaign every day?

For this workflow, yes. One stable campaign preserved reporting, sender limits, and sequence logic. New reviewed leads were added continuously and monitored until HeyReach moved them into sequence.

Sources and methodology

  1. Ink Persuasion internal TCP operating records: verified HeyReach enrollment/readback artifacts, Attio lifecycle write results, the client-specific Hermes runbook, and the July 2 TCP Hermes Slack status reply. Reviewed July 14, 2026. Published metrics are aggregate and anonymized.
  2. HeyReach, How to add Leads to campaigns?: help.heyreach.io/en/articles/11657798-how-to-add-leads-to-campaigns
  3. HeyReach, Why are my leads Pending; In Sequence; Failed; Finished?: help.heyreach.io/en/articles/9935919-why-are-my-leads-pending-in-sequence-failed-finished
  4. Attio, Create a record: docs.attio.com/rest-api/endpoint-reference/records/create-a-record
  5. Instantly, API documentation: developer.instantly.ai. Reviewed July 14, 2026; the current API documents scoped access and REST endpoints for programmatic email operations.
  6. Tenfold, How Much Does It Cost to Build a Custom AI Agent in 2026?: usetenfold.ai/blog/how-much-does-it-cost-to-build-a-custom-ai-agent-in-2026
Ink Persuasion

Want autonomous agents running your outbound?

Comparable autonomous workflow-agent builds are currently quoted from $30,000. Ink Persuasion can scope a focused version from roughly one-fifth of that entry point, with research, email or LinkedIn execution, follow-up, CRM, and monitoring built around your systems.

DM us or book a build call
faizan@inkpersuasion.com · Scope and final pricing depend on integrations, data, and sender readiness.