Get my meeting plan

Agents judge, people approve, code protects: how Dylan is built

How Dylan splits the work: AI agents make the judgment calls, people approve what goes out, and plain code enforces the rules that must never bend.

  • ai-agents
  • compliance
  • guardrails
Nothing goes out until you approve. Chapter 3 of the film, example data. What happens in it, and the whole film from 0:13.

Dylan is built on one rule: agents judge, people approve, code protects. Each kind of decision goes to whoever is best and safest at it. From the buyer’s side of the table, that is what good AI agent guardrails look like, and it is why the protections are never left to the AI.

A bank, not a chatbot

Think of a well-run bank. A loan officer judges the application, a manager signs off on anything above a limit, and the core system will not pay out more than the account holds, however persuasive the request.

The officer can use judgment freely precisely because the worst outcomes are impossible. Dylan works the same way: an agent with room to think, a person with the pen, and rules underneath that nobody talks their way past.

Agents judge

The work that needs judgment goes to AI agents: researching the companies in your market, deciding who fits your brief and why now, writing each email, reading replies, answering the routine ones and finding a time. No rule can be written for these in advance; they need reading, weighing and writing at a scale no team can staff.

For example, a company that opened a second warehouse last month may be a perfect reason to write, or irrelevant to what you sell; only reading tells you which. A reply that says “not me, try Priya in finance” is not a no but a referral, and a rule that sorted replies by keyword would throw it away.

People approve

Some decisions should never be automatic, because they carry your name or your money. You approve:

  • the plan: who Dylan will write to, why, and the forecast;
  • the first emails of every new angle;
  • any new segment or new spend.

Why every new angle, and not just the first email ever? Because each angle is a new promise in your name: a new claim, a new reason, a new tone. You should see every promise once before it is repeated at scale.

Before the plan reaches you, a person at Belkins reviews it. Belkins, the B2B lead generation agency behind Dylan, has run outbound since 2017 for 1,000+ clients across 50+ industries and holds a 4.9 rating on Clutch from 230+ reviews.

Once Dylan is running, he answers routine replies himself and hands you anything about pricing, legal matters or complaints. On his own, he acts for only two reasons: to protect you (pacing, pausing, keeping your do-not-contact list), or to carry out what you already approved.

SaaStr, which runs several AI SDRs, advises starting agents in “draft mode,” where the agent suggests and a person approves, and six months in it still kept its high-value prospects there. Human in the loop is not a phase you grow out of. It is where you put people on purpose.

Code protects

The rules that must never bend are plain, deterministic code: same input, same result, whatever any model thinks. Everything the agents never decide lives here.

  • A reply stops sending to that person. The moment a reply is read, every further scheduled email to that person stops, by rule, before any AI sees it. If an AI misread “please stop” as interest, the mistake could not be taken back, so the stop does not depend on reading at all.
  • The do-not-contact list is checked again at send time, not only when the list is built. A company you add this morning will not receive an email scheduled last week.
  • Per-company caps. No company gets flooded, however many good contacts it has.
  • Send windows in the recipient’s time zone. Emails go out at hours that make sense where the recipient is, not at three in the morning their time.
  • A 60-second undo on every launch and every approved reply, because second thoughts are normal.
  • A record of who did what. Every action records who took it: you, a person at Belkins, an agent or the system itself.

Think of a smoke detector: it does not weigh whether a fire is interesting; it goes off. That is the property you want from anything whose job is to prevent the one mistake you cannot undo.

And if a prospect ever asks your CEO why they were contacted, the record can answer in minutes: which plan, who approved it, which email went out and when. “The AI decided” is not an answer anyone should have to give.

Why AI agent guardrails belong in code, not in prompts

An instruction in a prompt is a promise. A rule in code is a guarantee. Most of the time the two look identical; the difference shows on the day something goes wrong.

In September 2026, 404 Media reported on agents from the iLands platform that told recipients they would not follow up unless someone responded, then “messaged us multiple times with the same pitch.” The founder’s response was a list of controls being added after the fact: an unsubscribe option, “cross-agent deduplication, rate limits, and stop-contact controls.”

None of those should depend on an agent remembering its instructions. They belong underneath the agent, where no amount of clever reasoning can route around them. That is the whole design: let the model be smart where smart helps, and make it irrelevant where smart is a risk.

What to do next

For you, the split means an agent’s speed without handing it your name. An agent can be wrong about a sentence, and you catch that at approval; it is built so it cannot keep writing to someone who replied, or email a company you told us to avoid. It is also why Dylan can say plainly that he is an AI, and why we accept being paid only when a meeting actually happens.

When you evaluate any AI agent that writes in your name, ask three questions: which decisions does the AI make, which do you approve, and which are enforced in code no matter what the AI says?

If the third list is empty, the first one is too long.

Sources

  1. Belkins, B2B lead generation agencybelkins.io
  2. Belkins reviews on Clutchclutch.co
  3. 6 Months of AI SDRs: What's Worked (SaaStr)saastr.com
  4. AI Agent Platform Reinvents Spam, Floods Inboxes Worldwide (404 Media)404media.co

Get my meeting plan.

Tell Dylan your website and who you want to meet. A person at Belkins reviews your plan and emails it within one business day. You pay only for meetings that happen.

Get my meeting plan