Off until you turn it on: how much rope Autopilot gets
The interesting question about software that acts is not what it can do. It is what stops it.
Most writing about software that acts is a list of what it can do. That list is easy to write and tells you almost nothing, because the capability was never the risky part. The risky part is what runs on a Tuesday night while nobody watches, and the only useful question is where it stops.
Autopilot is a tab in the Sell workspace and it is off by default. A workspace that never opens that tab has an autopilot that does nothing, costs nothing and sends nothing. Everything below is what happens after you turn it on, which is a decision you make on purpose. Turned on, it does one round a night, and what it produces is drafts. It writes them, you press Send.
Off is the shipping position
Off is not idling politely. The job is skipped where it stands: nothing read, nothing written, no credit spent. That is where every job sits if you never open the tab.
Turning Autopilot on is one decision. Letting it send is a second, and the second is really two, because choosing to send leaves the daily limit at zero, and zero still sends nothing. The capability matrix puts it in one line against the plans that carry it: ships off, drafting only, with a daily send limit of zero.
What the first decision buys is a morning. The clients who have gone quiet and the tasks that are overdue are read overnight, and the writing is waiting when you open the workspace.
Off, ask me, or just do it, and you set it per job
There is no one autonomy dial. Every job on the list carries its own setting, because reading your overdue tasks and writing to your clients are not the same decision and should not share a switch. The three words are the product's own.
Ask me is the approval queue, and the job that uses it is the one that writes to your clients. The round files what it would have sent, why, and roughly what it would cost, then stops. What runs on approval is the same checked path the copilot uses when you ask it yourself, and there is deliberately no second way to act.
Just do it lets a job go ahead inside the ceilings you set. For the job that can reach a person outside your workspace that is still not enough on its own: the sending gate is a separate lock, asked again before every single message.
The ranking underneath the three levels is not the obvious one: jobs are ranked by the worst thing they could do rather than the usual thing they do. A job that only reads your workspace and writes back into it can be undone inside it, so it gets on with the reading. A job that could reach a stranger is held behind approval and behind the sending gate. A job that could commit money is built to ask first whatever else you have set, which is why nothing in Autopilot today touches your money at all.
The shape of a round
One paragraph on the shape, because the job-by-job walk is its own essay. A round runs six jobs in the same order every time. The two reads that cost nothing come first, and only two of the six put any work through a model. The money job files what it would ask for and waits for you whatever else you have set. The one job that can reach somebody outside your workspace runs last.
Six locks, and where each one sits
Software that acts while you are asleep is only worth having if you can say exactly what it cannot do. The first lock is the one above: it ships off, and sending ships off separately.
The second is the ceiling. A daily one, and a monthly one if you want it, asked between every step, so a round that reaches it stops there. What a ceiling promises is that the round stops, not that it stops to the exact credit, because a step is billed once it has run.
The third is that the sending gate is asked per message, not once at the top of the round. The twelfth message is exactly the one that has to be refused, so the question is put again before each, answered fresh from your settings and from how much has gone out today.
The fourth is precedence. If you have never allowed AI to email your clients at all, Autopilot's own sending setting cannot overrule that. The narrower, later question does not get to win over the one you were actually shown.
The fifth is what a refusal does. Anything the gate cannot establish is a no, and a refused send is written down rather than thrown away, because an unsent message in your workspace is a cheaper mistake than one that has left it.
The sixth is the bill. The round bills under its own key, so Autopilot is a row in your account rather than part of one undifferentiated total. Not every credit lands on that row: work it hands to another part of the product, a task analysis for instance, is billed to that part's line. The tab shows which models did the work and what each cost.
The briefing, and the refusals
Each morning the tab carries a briefing: what it did, what it did not do and why, and the credits it spent under your cap. The middle one matters most, because a ceiling reached is named as the reason a job stopped rather than left for you to read as nothing to do. One is written every day, including the days nothing happened, because a quiet night reported as a quiet night is information and silence is indistinguishable from a broken job.
On timing, the screen's own words are ready by: once a day by default, ready by an hour you pick, which means at that hour or after it and not to the minute. If you would rather it worked through the day, switch it to an interval between two hours you set, with the passes no closer together than half an hour.
The refusals say more than a feature list does: a refusal is checkable and a feature is a promise. It never ticks a task off. It never answers an email in your inbox. It never runs a web search of its own. It never writes to a client without two settings you chose and a gate asked per message. It never acts on a suggestion you did not approve, or on one more than a week old. It never pushes on through an empty balance.
Read that back and the honest headline is a small one: Sell drafts overnight and leaves a briefing, under ceilings you set, in a tab that is off until you open it. Signing up builds the workspace, switches the copilot on and puts credits in it. Autopilot stays where it shipped until you decide otherwise.
Questions this raises
Is Autopilot on when I sign up?
No. It ships off, and off means the round does not run, reads nothing and spends nothing. Signing up builds the workspace and switches the copilot on. Autopilot is a separate tab and a separate decision, and it stays off until you open it and turn it on.
Can it email my clients without me?
Only after two switches you set on purpose, and then only through a gate asked before every single message. Choosing to send leaves the daily limit at zero, so the second switch is a number you have to put there yourself.
Does it ever raise an invoice or move money on its own?
No, and not as a setting you could change. Nothing in Autopilot today touches your money. The job that reads invoices past their due date writes the reminder, with the amount and the date in it, and then waits for you whatever your other settings say. The job that spots work a client accepted and never invoiced tells you about the gap and leaves the raising to you. Card collection is still being switched on in this deployment.