AutopilotReplies

Reply autopilot modes

Off, Ask, Review, Plan, Auto — what each reply autopilot mode does, why review is the default, and how the auto safety net works.

When a contact replies, reply autopilot decides what Duma does about it. The mode is set per workspace (with a per-sequence override) and runs from least to most automated: off → ask → review → plan → auto. The workspace default is review, and autopilot is safe by default — an unrecognized or missing setting is treated as off.

ModeAutomationSends?
offSuggested-response helper onlyNo
askSuggests 3 angles to choose fromNo
reviewDrafts one reply, heldNo
planDrafts a multi-step plan, heldNo
autoAnswers on its ownYes (gated)

off

Autopilot is disabled. Replies are still classified so your pipeline stays accurate, and you get the classic three-angle suggested response helper when you open a conversation — but Duma writes nothing until you ask.

ask

Duma offers three different angles for a reply (for example: answer the question, propose a call, share a relevant itinerary). You pick the direction and write the message. Good when you want a nudge on strategy but keep full authorship.

review (default)

Duma drafts a single, complete reply in your voice and holds it for you. You edit if needed and approve — nothing goes out on its own. This is the default because it gives you Duma’s full drafting help with zero risk of an unwanted send, and your edits quietly teach it your preferences over time.

plan

Like review, but instead of a single message Duma drafts a short conversational plan — a sequence of steps toward the booking — and holds it for approval. Useful for multi-touch threads where you want to see the whole arc before committing to the next reply.

auto

Duma answers autonomously. This is owner opt-in and never the default. Even when it’s on, every autonomous reply passes the safety net before it can leave:

  • Shadow mode (on by default) keeps autopilot in observe-only — it logs what it would send without delivering, so you can audit its judgement first.
  • Hot-handoff (on by default) routes any reply mentioning a call, meeting, or phone number to a human instead of auto-answering.
  • A confidence threshold, a daily auto-send cap, and a circuit breaker that stops autonomous sends if error signals spike.

Per-sequence override

The workspace mode is the default, but any individual sequence can set its own autopilot mode. A sequence set to off (or left unset) inherits the workspace default; anything else overrides it for that sequence only.

Where to set it
The workspace default and safety switches live in Settings → Autopilot. For the bigger picture on how this dial relates to cold openers, see How autonomy works.