Autonomy dials decide whether Duma may send. Guardrails decide whether a specific message is allowed to leave at all — and they apply at every autonomy level, including when you approve a draft by hand. Think of them as a stack of gates: a message must clear all of them, or it is held, throttled, or dropped.
Content gates
- Hallucination / citation check. AI drafts run a pre-send check against the contact’s intel brief; claims that aren’t supported are flagged rather than sent.
- Hot-reply handoff. A reply that mentions a call, meeting, or phone number is routed to a human instead of being auto-answered.
- Suppression & opt-out. Contacts on your suppression list, or who have opted out, are never messaged again.
Deliverability gates
- Send-rate caps & warmup. New mailboxes start with conservative daily/hourly limits that rise as the mailbox warms. See Send-rate caps & warmup.
- Bounce / spam auto-throttle. If a mailbox’s bounce or spam rate crosses the threshold, Karibu automatically pauses it to protect your domain reputation.
- Send windows. Messages are timed to sensible local hours for the recipient rather than fired at any moment.
Account & policy gates
- Workspace state. Paused, suspended, or dunning-suspended workspaces do not send — the core send loop skips them.
- Capability & tier checks. Actions that arm outbound or spend AI tokens are gated on server-side capability flags, not just hidden in the UI.
- Autopilot circuit breaker & daily cap. Autonomous sending stops if error signals spike or the daily auto-send cap is reached.
Guardrails are not the autonomy dials
You can approve every message by hand and guardrails still apply — a hand-approved opener to a suppressed contact, or from a throttled mailbox, is still held. The autonomy dials control automation; guardrails protect quality and deliverability regardless.
When a message is held
Held messages surface in your review queue with the reason, and mailbox health issues appear under Settings → Deliverability.