LinkedIn automation that asks before it sends

Short answer: the pattern you want is called human-in-the-loop. The tool drafts everything and sends nothing. You read a queue, edit what is close, skip what is wrong, and approve the rest. The test of whether a tool really works this way is simple. Ask if approval can be turned off.

Why this is the setting that matters

LinkedIn outreach has one failure mode that costs more than all the others combined. A tool sends something you would not have sent, to someone whose opinion of you matters, under your name.

It happens through ordinary bugs. A profile is misread and the note references the wrong company. A thread is misclassified and a warm intro gets a sales pitch. A template fires with the placeholder still in it. None of these are exotic. All of them are caught in about two seconds by a person reading the draft.

The account risk works the same way. LinkedIn restricts accounts for volume and for repetition. A person approving each message notices when thirty drafts are near-identical. Software running unattended does not.

Which actions need approval

ActionApprovalWhy
Search for peopleNoNothing leaves your account
Read a profile or postNoNothing leaves your account
Connection request with a noteYesA person reads it and it is attributed to you
Direct message or replyYesOne-to-one, and mistakes are visible
Comment on a postYesPublic, and it stays public
Publish a postYesPublic, and it is your byline

The line is whether another person will read it. Everything above that line waits for you.

What a real review queue does

  • Shows the exact text. Not a summary of the message. The message.
  • Shows what it was drafted from. The profile and the post it referenced, so you can see whether the reference is right.
  • Gives you four choices. Approve, edit and approve, ask for a rewrite, or skip.
  • Filters itself. Drafts scored as robotic are dropped before you see them. A queue full of things you would never send teaches you to stop reading.
  • Lets you schedule. Approving now and sending at nine tomorrow is one action.

Where limits have to live

A daily cap written into a prompt is a suggestion. Models can be argued out of suggestions, including by their own reasoning about being helpful.

A cap enforced in the server is a rule. The model calls the send tool, the server counts, and the call fails. Nothing in the conversation can change that number because the number is not in the conversation.

This is worth asking any vendor directly. Where is the daily limit enforced. If the answer is the system prompt, the limit is decoration.

Questions people ask next

Does approving everything defeat the point of automation?

No, because the expensive part was never the clicking. Writing thirty personalized notes takes an afternoon. Reading thirty drafts takes a few minutes, because reading is much faster than writing. You keep the hours and give up almost nothing.

Which tools have an auto-approve mode?

Most of them, and several advertise it as a feature. That is the thing to check before you connect an account. A tool with auto-approve is a fire-and-forget tool with an optional pause, and the pause tends to come off during a busy week.

Will approving each message keep my account safe?

It removes the largest cause of trouble, which is unattended volume. It does not make automated outreach risk-free. LinkedIn's terms restrict automated access, and you remain responsible for how you use any tool. Keep numbers low, vary what you send, and read your own log.

What if I want a draft changed rather than skipped?

A good queue lets you edit the text directly or ask for a rewrite with a note about what was wrong. Skipping a near-miss and starting over is the slowest option and it is the one most queues leave you with.

How do I verify what was actually sent?

Through an activity log, and it should record the exact text rather than a description. Failures belong in it too, with their reasons. Without a log you are trusting a report of what happened instead of the record of it.

How Iridium does it

Iridium has no auto-approve mode. Every connection request, message, reply, comment, and post is a draft. Approving is a separate explicit action and it is the only thing that sends.

Daily and weekly limits are enforced on the server, so they hold whether you are working in the web app or asking Claude through the MCP server. Each draft is scored for how robotic it reads and the weak ones are filtered before they reach your queue. Every attempt, including the failures, is written to an append-only log you can read in the app or ask your agent to read back.

Automation that waits for you

7-day free trial. No credit card. Cancel anytime.

Start free → Compare with doing it by hand