Quillreach

LinkedIn outreach guide

AI drafts the message. You approve it.

How human-in-the-loop LinkedIn outreach works, why an approval step that can be switched off is not an approval step, and what to verify before you trust a tool with your account.

By Burhan, Founder of Quillreach. Published September 2026·Last updated: September 12, 2026

The short answer

Human-in-the-loop LinkedIn outreach means AI researches each prospect and drafts the message, but a person approves, edits, or rejects it before anything sends. Nothing leaves your account on its own. The distinction that matters when choosing a tool is not whether approval exists, but how hard it is to switch off: many tools make review a per-campaign setting that quietly turns them back into autonomous senders. Quillreach defaults every AI step to human review, so an AI-drafted message parks in an operator review queue and a person approves it before it sends. Turning that off is deliberately not a single switch: it takes both a per-step opt-in and a separate server-side gate, so review cannot drift off by accident. Steps that send a template you wrote yourself are not AI drafts and send as written, because you already approved that text when you wrote it.

What is human-in-the-loop LinkedIn outreach?

Human-in-the-loop LinkedIn outreach is a workflow where AI does the research and the writing but a person makes the send decision. The tool pulls real signals from a prospect's profile, drafts an opener or a follow-up from those signals, and then holds that draft for a human to approve, edit, or reject. It is sometimes called a human-approved AI SDR. The defining property is negative rather than positive: there is no path by which a message reaches a prospect without someone having read it first. Everything else, including how good the drafting is, is secondary to that guarantee.

It sits between two things people often confuse. It is not a mail merge with AI-generated variables dropped into a fixed template, and it is not an autonomous agent working your pipeline unattended. The AI does the part that scales badly for a human, which is reading every profile properly, and the human keeps the part that does not delegate well, which is judgment about whether this specific message should reach this specific person.

Why does fully automated sending get accounts into trouble?

Because the failure mode of autonomous sending is not a bad message, it is a bad message at volume. An AI that misreads a profile writes one awkward opener, and an AI that misreads a segment writes four hundred of them before anyone notices. The recipients respond the way people do to obviously automated outreach: they ignore it, they report it, or they mark that they do not know the sender. A high rate of those reports is one of the fastest routes to a LinkedIn restriction, and it is entirely self-inflicted. A review step caps the blast radius of any single mistake at one message, because a person sees the draft before the prospect does.

This is why approval belongs next to the other safety constraints rather than in a separate category. Volume caps limit how much you send, and review limits what you send. Both exist to keep automated activity indistinguishable from a person working their network, which is the pattern least likely to attract a LinkedIn restriction.

Optional approval vs enforced approval: what is the difference?

Almost every AI outreach tool now advertises a review step, so the word approval no longer distinguishes them. What distinguishes them is whether approval can be turned off. When review is a setting, it is a setting someone disables the first week the pipeline looks thin, and the tool reverts to being an autonomous sender with a human-in-the-loop label on the website. When approval is enforced by design, there is no toggle: an unapproved draft simply never sends, and the queue is the only path out. Ask which of the two you are buying, because the marketing language is identical and the risk profile is not.

Approval modelHow it worksWhat happens if nobody reviewsWho is accountable for the messageMain risk
Fully autonomous AI SDRAI researches, drafts, and sends on its own, with no review step in the pathMessages send anyway, on scheduleNobody reads it before the prospect doesGeneric or wrong-context messages reach real prospects at volume, which drives reports and damages the sender's reputation
Approval as an optional settingA review queue exists, but it can be switched off per campaign or per accountDepends entirely on the setting, and the default is usually offWhoever remembered to leave the toggle onIt reads as human-in-the-loop in the marketing and behaves as autonomous in practice, because the toggle drifts off under pressure to send more
Approval enforced by designEvery AI-drafted message enters a review queue and cannot leave it without a person acting on itNothing sends. The draft waitsThe named operator who approved it, with a record of whenThroughput is bounded by review time, so approval has to be fast or the queue becomes the bottleneck

These are architectural models rather than a ranking of named products. Tools move between the middle row and the bottom row depending on configuration, which is precisely why the question to ask a vendor is whether approval can be disabled, not whether it exists.

What should you verify before choosing a tool with an approval workflow?

Approval is easy to claim and hard to implement completely, so check the edges rather than the headline. Confirm that approval covers every outbound message type, not just the first touch, because follow-ups and replies are where autonomous behavior usually hides. Confirm there is no automatic fallback that sends an unapproved draft after a timeout. Confirm the reviewer is shown the complete message that will send rather than a preview of the opener or a truncated summary, because approving a fragment is not the same as approving the send. Confirm you can edit and regenerate rather than only accept or reject. Confirm there is a per-message record of who approved what and when, which is what makes the workflow auditable rather than merely claimed.

Approval covers every message type

Connection requests, first messages, follow-ups, and replies. Follow-ups are where optional approval usually leaks, because the first touch gets reviewed and the rest of the sequence runs on its own once the prospect is enrolled.

No automatic fallback

Ask what happens to a draft nobody approves for a week. Sending the unapproved draft anyway after a timeout makes approval a delay rather than a gate. Falling back to a template the operator wrote is a different and defensible answer, but you should know which one you are buying, and it should be your choice rather than a default you discover later.

Full context beside the draft

The reviewer should see the prospect's profile signals and the conversation so far next to the message. Approving a message in isolation is rubber-stamping, and a rubber stamp produces the same outcomes as no stamp at all.

Edit and regenerate, not just accept

A binary accept or reject pushes reviewers toward accepting, because rejecting means losing the work. Being able to fix one clause or ask for another draft is what keeps the human genuinely in the loop rather than nominally in it.

A per-message approval record

Who approved this, and when. Without that record you cannot audit what went out under your company's name, and in a team or agency setting you cannot tell whether the review step was actually used.

Caps that apply to approved messages too

Human approval is not a licence to exceed LinkedIn's activity limits. An approved message and an autonomous one look identical to LinkedIn, so per-account daily caps still have to be enforced underneath the review queue.

Does requiring human approval slow outreach down?

It bounds throughput, and that is the honest trade. But the bound is far looser than people expect, because reviewing a draft is not the same work as writing one. Reading an opener that is already researched and drafted takes a few seconds, and most of them are approved unchanged. In practice the constraint that limits LinkedIn outreach is not review time, it is the daily send cap: an account that can safely send fifteen to twenty connection requests a day does not generate a review queue that takes meaningful time to clear. Approval only becomes the bottleneck if you were planning to send at volumes that would get the account restricted anyway.

The arithmetic is worth doing once. At a safe pace of roughly fifteen to twenty connection requests per day per account, a single operator reviewing a few seconds per draft clears a day of outreach in a couple of minutes. The review step only starts to hurt at volumes the account could not survive.

Is a human-approved AI SDR the same as an AI SDR?

No, and the difference is the whole point. An AI SDR is sold on removing the person: it researches, writes, sends, and handles replies with no human in the path, and its value proposition is headcount you no longer need. A human-approved AI SDR keeps the person as the decision maker and uses AI to remove the drudgery instead, which is the research and the first draft. The output volume is lower and the quality floor is much higher, because nothing goes out that a person would not have sent. Which one is right depends on whether your prospects are worth annoying at scale.

Sources: LinkedIn Help: prohibited software and extensions·LinkedIn User Agreement

How approval works in Quillreach

Quillreach defaults to the bottom row of the table above. AI message blocks draft every opener from real profile signals, and each draft lands in an operator review queue where a person approves, edits, or rejects it. Human review is the default on every AI step, and a draft nobody approves does not send.

To be straight about it, the code does contain an autonomous path, and we would rather describe it than claim an absolute. Reaching it takes two independent opt-ins: the individual step has to be set to autonomous, and a separate server-side gate has to be open. Neither alone is enough, which is the point. Autonomous sending is the highest ban-risk action in the product, so one setting being wrong should never be enough to start it.

The reviewer sees the complete send-ready message rather than an opener fragment or a summary of one, alongside who it is going to and which campaign it belongs to, so approving is a judgment about the actual text that ships. Edits are made in place, and under human review a draft that is not approved simply never sends.

Approval sits on top of the safety constraints rather than replacing them. Every account still runs against hard per-account daily caps, an automatic warm-up ladder for new accounts, randomized human-paced timing inside working hours, and stop-on-reply, so an approved message is still subject to the same limits an unapproved one would have been.

Common questions

AI does the research and the writing. You make the call.

Quillreach drafts every opener from real profile signals and holds it for a human to approve. Human review is the default on every AI step. $59 per seat per month, with a 14-day free trial and no credit card to start.