# What agents cannot do

> The human gates in front of sending, and the actions no credential can take. Plan around them rather than hitting them.

Source: https://rivomi.com/docs/concepts/guardrails



rivomi sends from a real person's LinkedIn account, so a few decisions belong to a human in the
browser. No tool, key or OAuth grant can make them. When a plan reaches one of these, **stop and
tell the user what to do in the app**. The error message names the place.

## The sending gate [#the-sending-gate]

Nothing reaches LinkedIn until a workspace owner or admin has accepted the LinkedIn sending terms
under **Settings › Senders**. Until then:

* `rivomi_get_workspace.sending_consent.accepted` is `false`, and `how_to_accept` says where.
* `rivomi_review_queue` approvals, `rivomi_enroll_prospects`, and `set_agent_state` with
  `start_outreach: true` fail with `consent_required` (HTTP `412`).
* A `send`-scoped key cannot be created.

Rejections, scoring, drafting and every read still work. Check `sending_consent` before planning
any outreach, and plan reads and drafts only when it is `false`.

## The approval gate [#the-approval-gate]

Every person queued for outreach needs an **approved drafted message**. `rivomi_enroll_prospects`
skips anyone without one and lists them in `skipped`. With an agent's review mode on, approval
happens through `rivomi_review_queue` or the Queue tab in the app.

## Not available to any credential [#not-available-to-any-credential]

| Action                                                                     | Where it happens instead                     |
| -------------------------------------------------------------------------- | -------------------------------------------- |
| Accept the LinkedIn sending terms                                          | Settings › Senders, by an owner or admin     |
| Connect, reconnect or repair a LinkedIn sender (involves a 2FA checkpoint) | Settings › Senders                           |
| Invite or remove members, change roles                                     | Settings › Members                           |
| Change billing, delete or export the workspace                             | The app, by an owner                         |
| Read another workspace                                                     | A separate credential made in that workspace |
| Read LinkedIn credentials, cookies or provider account ids                 | Nowhere. No tool returns them.               |

## Irreversible tools [#irreversible-tools]

Three calls act outside rivomi and cannot be undone. Confirm with the user before each one:

* `rivomi_reply` delivers the text to a real LinkedIn inbox immediately, exactly as written.
* `rivomi_set_enrollment_state` with `stopped` withdraws a pending invitation on LinkedIn.
* `rivomi_review_queue` approvals and `rivomi_enroll_prospects` put real invitations on a sender's
  queue.

Everything that spends credits is reversible in effect but not in cost. See [Credits](/reference/credits).
