Bot autonomy modes and human approval (HITL)

Conversa Labs

Conversa Labs

Last updated on Aug 18, 2026

Overview

Autonomy defines how much the Bot (Maestro acting inside the conversation) does on its own versus when it asks a person to confirm. You pick the level of trust, and it governs how the Bot behaves in support.

There are three modes:

  • Autopilot β€” the Bot executes on its own, without waiting for approval.
  • Copilot β€” the Bot proposes cards (a message draft or a module action); you review and send. Nothing goes out on its own.
  • Hybrid (Require approval / HITL) β€” the Bot acts on its own in day-to-day work, except for sensitive actions, which are held, waiting for your approval.

The safety principle is simple: in Hybrid, nothing sensitive or final happens without approval; in Copilot, nothing is sent without you. You decide how much to trust.

This concept has analogs elsewhere in the platform: the Brain's departments have their own autonomy level (including an "Ask first" tier), and Follow-ups have AI-draft approval. Both are linked under "See also".

Prerequisites

  • Maestro enabled and a Bot/agent configured on the inbox.
  • Administrator permission to set the autonomy mode.
  • An owner (the conversation's assignee or a team) to receive the approval notifications.
  • The per-module tools you want proposed/parked must be enabled β€” see the tools article.

Step by step

  1. In the Bot configuration, choose the autonomy mode: Autopilot, Copilot or Hybrid (Require approval).
  2. To change only one conversation, open the Maestro side panel, click the Autonomy mode card and choose another mode. The card says Set for this conversation; use Use Bot default to remove the exception. Only administrators can make this change.
  3. In Copilot: the Bot proposes cards (a draft or a module action); you review and send/confirm β€” nothing goes out on its own (details in the generative copilot article).
  4. In Hybrid: for day-to-day actions the Bot acts; when a sensitive action comes up, it is parked β€” the Bot posts a private note that @mentions the owner (firing the native notification) and creates an approval card with an action id.
  5. The owner taps/clicks the Maestro indicator in the conversation header to open the panel; the adjacent shortcuts Pause, Resume, or Take over the service. Pending approvals stay visible in the numbered shield. In the panel, choose Approve or Reject. On Approve, the exact action that was held is re-executed; the note records who approved it.
  6. In Autopilot: the Bot executes on its own (sensitive actions are still recorded in the audit trail).
  7. Track the result on the card and in the conversation's activity line.

Settings & options

The three autonomy modes

Mode Behavior
Autopilot Runs on its own; no approval wait.
Copilot Proposes; the person reviews and sends. Nothing is sent without you.
Hybrid (Require approval / HITL) Runs on its own, except sensitive actions, which are parked for approval.

What counts as a sensitive action in Hybrid (gets parked)

  • Assign to a team, run a macro, mark the conversation as resolved.
  • Writes to CRM, Tasks, Calendar (create/edit/reschedule/cancel an appointment) and Payments.
  • Commerce recovery (a recovery card sent to the customer), cancel a follow-up cadence, enroll into a distribution group and trigger a collaboration round.
  • Database writes, generate video, contracts (create/send/remind) and delegating to a sub-agent when that delegation is marked as sensitive.

What the Bot does freely (even in Hybrid)

  • Reply to the contact, add labels, internal notes, reactions, generate an image, knowledge-base searches and other read-only lookups.

Human-only action

  • Approving an AI Follow-up draft is always human β€” the Bot never approves its own draft. This holds in any mode (see the Follow-ups article).

The approval card and note

  • The private note @mentions the owner (or the team) and references the action id, to trigger the platform's native notification.
  • The approval card sits in the conversation's Maestro panel, with Approve and Reject.
  • The decision is recorded with who approved β€” and on approval, the exact parked action is re-executed.

Handoff to a human: status, priority and summary

When handing a conversation off to a human team, the Bot sets the conversation's status (open, pending, snoozed or resolved) and priority (none, low, medium, high or urgent). Each one can be a fixed value or "Maestro decides": in that mode the Bot itself picks the most suitable value per conversation, at the moment of handoff β€” a fixed value always prevails over the Bot's choice. The handoff note sent to the agent includes the reason and a conversation summary (generated on the spot when there is no accumulated summary yet), so the person can take over with context.

Taken over by a human (the bot stands down, then comes back)

When a person replies in the conversation (from the dashboard or the mobile app) or pauses the bot, it stands down on that conversation β€” it stops replying so it does not talk over the human. This applies to that conversation only; the bot keeps working everywhere else.

Two options control the comeback:

Option What it does Default
Resume automatically after a while The bot takes the conversation back once the window below passes with no new human reply. On
Resume after The idle window before it returns: 1 hour, 4 hours, 12 hours, 24 hours, 48 hours, 1 week, or Custom (you type the hours). 24 hours
  • With auto-resume off, the bot stays paused on that conversation until a person hands it back β€” there is no time-based return.
  • The clock runs from the last human message: if the person replies again, the window restarts.
  • The minimum accepted window is 1 minute; anything shorter is raised to that floor.
  • The setting is per bot (it applies to every inbox the bot answers on).

Where the mode applies, and the per-department analog

  • The mode configured on the Bot is the default for every inbox it serves. A conversation may keep a persistent exception; precedence is conversation β†’ Bot. The change starts on the next turn, does not interrupt an in-progress reply, and neither executes nor discards existing approvals.
  • The Brain's departments have their own autonomy level (including "Ask first") β€” a separate setting, detailed in the departments article.

Use cases

  • A team new to AI: start on Copilot and review everything before sending.
  • A trusted operation with guardrails: Hybrid β€” routine replies on their own, money/data moves waiting for approval.
  • High volume, low risk: Autopilot for simple touches, or Hybrid for most cases.
  • Sensitive sub-agent delegation kept under approval in Hybrid.

Tips, limits & best practices

  • Grow trust gradually: Copilot β†’ Hybrid β†’ Autopilot.
  • Make sure there is an owner (assignee or team) so approval requests don't slip by.
  • Review pending items often so the flow doesn't pile up.
  • Approving re-executes the exact parked action β€” check the data before approving; if something changed, reject and ask again.
  • Only enabled tools are proposed; keep the more powerful ones starting with approval.

Troubleshooting

  • "The action didn't run": in Hybrid, a sensitive action is held β€” approve it in the Maestro panel.
  • "Nobody saw the approval request": check the owner (assignee/team) and the account's notifications.
  • "The Bot acted on its own on something I wanted to review": it's not on the sensitive list, or the mode is Autopilot β€” switch to Hybrid.
  • "I can't approve an AI Follow-up draft through the Bot": draft approval is human by design β€” see the Follow-ups article.

See also