Core conceptRead before changing settings

How autonomy works (start here)

Karibu has two independent autonomy dials — one for cold openers, one for replies. Both are safe by default. This is the article to read before you change any setting.

Karibu has two separate autonomy dials, and they are independent. One governs cold openers (the first message to a brand-new contact). The other governs replies (what Duma does when someone answers). Turning one up does not touch the other. Both ship in their safest position, and this page explains exactly what each does — so you can raise them deliberately rather than by accident.

Dial 1 — Cold openers

This is your active goal’s autonomy level. It decides what happens to the openers Duma drafts for newly found contacts. It has three settings and defaults to review:

LevelWhat Duma does with a drafted opener
reviewDefault & safe. The opener is held in your review queue. Nothing is sent until you approve it.
assistDuma sends openers for you (within the guardrails) instead of holding them — you supervise after the fact rather than before.
autoDuma sends openers on its own at the goal’s drip pace, hands-off.

Dial 2 — Reply autopilot

This is your workspace’s reply autopilot mode (default_mode). It decides what happens when a contact replies. It has five settings and defaults to review:

ModeWhat happens when a reply arrives
offAutopilot is disabled — you get the classic 3-angle suggested-response helper only.
askDuma suggests three angles; you pick one and write the reply.
reviewDefault & safe. Duma drafts a single reply and holds it for your approval.
planDuma drafts a multi-step conversational plan and holds it for your approval.
autoDuma sends replies autonomously. Owner opt-in only, and still gated by the safety net below.

The full behaviour of each mode is in Reply autopilot modes. You can also override the workspace default on an individual sequence.

The reply dial's safety net

Even when you choose auto, three safeguards ship on and stay on unless you change them:

  • Shadow mode (on by default). Autopilot produces what it would send and logs it, but does not deliver — so you can watch its judgement for a while before trusting it live.
  • Hot-handoff (on by default). A reply that mentions a call, a meeting, or a phone number is always handed to a human, never auto-answered — a false positive there costs one extra review; a false negative costs a botched hot lead.
  • A confidence threshold and a daily send cap, plus a circuit breaker that halts autonomous sends for the workspace if something looks wrong.

How to change the dials

  • Cold-opener level lives on your active goal — raise it from review to assist or auto there when you’re ready.
  • Reply autopilot mode and its safety switches live in Settings → Autopilot.
A sensible ramp
Watch drafts on review for a week. Turn shadow mode off and watch what auto would do. Only then move a dial to a sending level — and keep hot-handoff on. Guardrails still apply at every level; see Guardrails.