In short
- 1"Six jobs, two halves: find, qualify, and draft build the list; approve, send, and learn keep you in control of what happens to it"
- 2"Connected prospects reply at 12.2% vs 7.9% cold, per Belkins' 2026 benchmark across 15 million touchpoints"
- 3"LinkedIn removed Artisan from the platform in December 2025 over scraped third-party data; its own G2 reviews show a recurring complaint about bland, obviously-automated messaging at volume"
- 4"Unconditional per-account ceilings: 50 connection requests a day, 120 profile visits an hour. Base daily pacing a workspace multiplier scales: 300 visits, 70 messages"
In December 2025, LinkedIn wiped Artisan off the platform: its company page, its employees' profiles, and its executives' posts, all gone before Christmas. Artisan is the Y Combinator startup that bought "stop hiring humans" billboards across San Francisco to sell Ava, an autonomous AI agent that runs sales outreach on its own. The ban was not about spammy messages. LinkedIn objected to third-party data that had been scraped from it and to Artisan using its name on the site. Artisan cleaned both up and was reinstated about two weeks later (TechCrunch, January 2026). The episode is still the clearest public read on what "AI agent for LinkedIn outreach" quietly asks of you: whether the software drafts for you to read, or writes and sends before anyone looks.
Because the phrase hides two very different products wearing one label. One decides on its own who to message and sends without a human reading the message first. The other finds and drafts, then waits for you to say yes before anything goes out. These are not variations on the same idea. They fail in opposite ways: one drifts toward generic, obviously-automated messaging once nobody is checking it, the other catches that drift because a person reviews every draft before it moves.
This guide breaks the term into the six jobs an outreach agent can actually do, shows what each one actually delivers, and walks one honest end-to-end session so you can see exactly where the human still sits. For the wider market context first, the AI SDR hype cycle and what survived it is covered in AI agents for LinkedIn lead generation.
The six jobs of an outreach agent
Strip away the marketing and an "AI agent for LinkedIn outreach" is doing at most six distinct jobs. The useful question is not "does it have AI" but "which of these six does it do, and who has the final say on each." The single most important column is the last one: whether that decision sits with the agent or with you.
Two of the six jobs need nothing from you at all, and a third only needs the ICP you set once. That is not a rounding detail. It is the whole difference between an agent that hands you a finished, drafted queue to react to, and one that makes you do the sourcing and scoring yourself before it can write a single message.
Find
The agent's first job is sourcing. A good one does not start from a static list you upload; it starts from live signals. Who commented on a relevant post this week, who is hiring for a role your product serves, which companies just changed shape. Those are public signals: the same posts, comments, and job listings anyone can already see on the open web. You can try the raw version yourself with the LinkedIn comment scraper, and the full taxonomy of what is worth watching is in LinkedIn intent signals without Sales Navigator.
Qualify
Sourcing gives you volume. Qualifying gives you a shortlist. Say a single viral post about outbound tooling returns 400 likers. Qualify is the step that reads each public profile and keeps only the ones that match your criteria, heads of growth at Series A to C companies in your region, so you end up reviewing 25 names instead of skimming 400. Templated tools skip this and hand you the raw 400 to blast; the agent scores each prospect against your ideal customer profile and drops the misses before you ever see them. This is where an AI agent genuinely beats a human doing the same task, because it applies the same criteria to the four-hundredth profile as consistently as the first.
Draft
Templated tools lose here structurally. "Hi {name}, I noticed you work at {company}" reads as automated no matter how many merge fields you add. An agent writes from the actual context: the specific thing the person said, the specific role they are hiring for. That context is what makes a first message read less like a broadcast, and warmth moves the numbers. Belkins' 2026 LinkedIn benchmark, built on more than 15 million outreach touchpoints, found messages to already-connected prospects replying at 12.2% against 7.9% for cold connector requests (Belkins, 2026).
Approve
This is the job that separates the two product categories. An agent-with-approval shows you the drafted queue and does nothing until you act on it. You edit two, cut one, greenlight the rest. An autonomous sender skips this step entirely, which is exactly why it degrades: nobody is reading the output before prospects do.
Send
This is the sending step. The agent delivers the messages you approved, spread out under caps rather than fired all at once. BeReach's per-account pacing runs at 300 profile visits and 70 direct messages a day at base, both figures a workspace multiplier scales, on top of two unconditional ceilings that no plan lifts: 50 connection requests a day and 120 profile visits an hour. Because invitations are throttled hardest, with the market treating roughly 100 a week as the sustained pace, the connection-request lane runs well under even that unconditional daily cap. Speed on relevance, restraint on volume.
Learn
The last job is closing the loop. The agent reads replies and outcomes and adjusts, so next week's targeting and tone reflect what actually got answered. This is shared judgement: the agent proposes the adjustment, you decide whether the pattern is real.
Autonomous sender vs agent with approval
The demos blur these together on purpose. They are not the same product, and the difference shows up most in how they fail.
The market already ran this experiment, and the flagship autonomous agent is the cautionary tale. Artisan sits at around 4 out of 5 on G2, but that average hides a polarized split: mostly five-star reviews with a hard cluster of one-star ones, whose recurring complaint is bland, obviously-automated messaging that personalizes with little more than a name and a job title. Then LinkedIn removed Artisan from the platform entirely in late December 2025 over broker-scraped third-party data and use of its trademark, and reinstated it only after it cleaned up its data sources (TechCrunch, January 2026). Across the wider AI SDR market, the companies that deployed these agents as full human replacements have largely walked that back toward hybrid, human-in-the-loop setups. The lesson is not that AI outreach fails. It is that removing the human removes the thing that made the outreach worth sending.
That is also the real read on productivity. The Prospecting 2025 report from Outreach found that 100% of AI-powered SDR users reported time savings, with nearly 40% saving four to seven hours a week (Outreach, 2025). The saved hours come from the find, qualify, and draft jobs, not from taking the human off the approve and send jobs.
Most of the work is the list, not the send
Here is the part almost no outreach tool is built to admit: finding, qualifying, and drafting are the bulk of the job, and all of it runs on public data, post signals, company data, each prospect's own profile. None of it needs more from you than the ICP you set once. Review is the step that decides whether any of it goes anywhere.
BeReach is built around exactly that: it does the finding, the qualifying, and the drafting, then stops and hands you a queue of finished messages to read. The agent proposes, you decide, and nothing goes out that you have not seen. That is the part most tools skip, because approving work is harder to demo than automating it.
That framing matters more than it sounds. The fastest way to burn a good prospect is not sending too many messages, it is sending one nobody reviewed. Keep a human on the approve step and the only thing left to automate is delivery, paced, after you have said yes.
One honest session, start to finish
Here is a real end-to-end shape, not a highlight reel. The agent runs inside Claude through BeReach's MCP connector, so the whole thing is one conversation.
You: Find people who commented on that post about outbound tooling,
qualify them against my ICP, and draft a first message for the
best fits.
Agent: Pulled 41 commenters from public data. Scored them against your
ICP (Series A to C, heads of growth or demand gen). 12 clear
fits, 29 dropped. Drafting 12 openers now, one per person, from
what each actually wrote in their comment.
You: Show me the queue.
Agent: 12 drafts ready for your approval. Nothing has been sent, and
nothing goes out until you say so.
You: [approve 9, edit 2, cut 1]
Agent: 11 approved. Sending is paced under your daily caps, not fired
all at once. Want me to schedule the 11 or send now?
Notice what did not happen. The agent did not decide the messages were good enough to send on its own. It stopped at the queue and waited for you. The one out of twelve you cut is the one an autonomous sender would have delivered without you ever seeing it.
If you want to reproduce this exact flow, the connector setup and the tool surface are documented in the LinkedIn MCP server for Claude, and the step-by-step is in run BeReach from Claude.
Why the transcript is reproducible, and why that matters
A demo you cannot reproduce is a promise. A transcript you can run yourself is a product. BeReach's outreach agent is exposed as a 27-tool MCP connector at mcp.bereach.ai that runs inside Claude and Claude Cowork, across 114 API operations behind a single key. Because it is a standard connector, the session above is not a canned marketing script; it is a set of tool calls anyone can issue and watch happen turn by turn.
That reproducibility is the real answer to "can I trust an AI agent with my outreach." You do not have to trust the marketing. You watch it find, watch it qualify, watch it draft, and approve before anything moves. The agent proposes; you dispose. There is one included model, BeReach 2.0 Flash, so there is no key to bring and no model picker to misconfigure, which keeps the reproducible part actually reproducible across accounts.
What it costs and where to start
You can start for free: eight free finders cover the sourcing signals, and the agent itself has a free tier with a monthly credit allowance. Paid plans open the send step and more connected accounts, starting at EUR 99 per month on Pro with a short trial. Rather than quote every tier here, the current breakdown lives on the pricing page.
The summary is the one the market arrived at the hard way. An AI agent is a force multiplier for the find, qualify, and draft jobs, and a liability the moment it takes the human off the approve and send jobs. Pick the one that keeps you on the gate.
Every viral post is 100+ warm conversations waiting.
Tell your agent who you want to reach. It finds them, says which ones are worth your time, writes the first line, and follows up.
What does an AI agent for LinkedIn outreach actually do?
A capable one does six jobs: find prospects from public signals, qualify them against your ICP, draft a specific first message per person, present the queue for approval, send the approved messages under daily caps, and learn from replies. Finding, qualifying, and drafting build the list; approving is where you decide what actually goes out.
What happens if one of the agent's drafts misses the mark?
You catch it in the queue. Every draft sits there until you edit it, cut it, or approve it, so nothing reaches a prospect before you have seen it. That is the same kind of miss an autonomous sender would have delivered without anyone noticing.
Can an AI agent write LinkedIn messages that do not feel templated?
Yes, because it writes from real context rather than merge fields. Instead of inserting a name into a fixed sentence, it references the specific thing a prospect said or the role they are hiring for. Warmth moves reply rates: Belkins found already-connected LinkedIn outreach replying at 12.2% versus 7.9% for cold connector requests across more than 15 million touchpoints (Belkins, 2026).
How is a Claude-connected outreach agent different from a normal tool?
It runs as an MCP connector inside Claude, so the whole workflow is one conversation you can watch and reproduce turn by turn, rather than a dashboard doing things out of sight. BeReach exposes 27 tools across 114 operations this way. You see it find, qualify, and draft, then approve before anything sends, which is what makes the agent auditable instead of a black box.
Reading this in an AI assistant? Hand it the page and let it summarize, so you can ask follow-up questions against the whole argument rather than the part you have read so far.



