AI agents in your CRM
What runs on autopilot and what waits for you
An AI agent in a CRM should do the admin work on its own, logging, enriching and updating records, and ask for approval before anything a customer can see. That is the line that matters.
Santtu Koivumäki, co-founder· · Updated · 4 min read
Most of the debate about "autonomous CRMs" misses that line entirely, and argues instead about whether automation itself is safe. This page explains where Zero draws the line, why, and what you actually control.
The debate
AI-native CRMs promise to eliminate manual work. Skeptics answer that if no human clicks anything, no human checks anything, and autonomy is just recklessness with better branding.
The skeptics are right about one thing. An agent that emails your customers without oversight is a liability, not a productivity gain. If a vendor promises "fully autonomous selling," close the tab.
But the conclusion does not follow. The fix for risky automation is not more clicking. It is a clear boundary between work that is safe to automate and work that is not. Clicks were never the control mechanism. They were just the cost of software that could not do the work itself.
The boundary: internal work vs external actions
Here is how the work splits.
Agents handle on their own (internal, reversible):
- Logging calls, emails and meetings to the right customer record
- Enriching contacts and companies with public data
- Updating deal stages and fields based on what actually happened
- Drafting follow-ups and flagging next steps
- Deduplicating and cleaning records
You approve first (external, customer facing):
- Sending outbound email, LinkedIn connection requests or LinkedIn messages
- Adding contacts to sequences
- Anything that leaves your workspace and reaches a customer
The pattern: everything in the first list is internal and correctable. If an agent mislogs a call, you fix a record. If an agent sends a bad email to your best prospect, you cannot unsend it. That asymmetry is the entire design principle.
Why context is the real safety mechanism
An agent is only as good as the context it can see.
This is the part most "AI CRM" discussions skip. Agents bolted onto a legacy CRM see fragments: the CRM has the pipeline, the email tool has the conversations, the enrichment tool has the firmographics. An agent working from fragments makes decisions of the same quality, confidently wrong and at scale.
Zero's agents run on one complete customer record: contacts, full email history, pipeline, meetings, and enrichment from a database of more than 20 million companies. There is a full CRM underneath, and that is exactly why the agents work. When an agent drafts a follow-up, it has read the entire relationship, not the last touchpoint. Better context does not just make agents more useful. It makes them safer.
What you can see and control
Autonomy without visibility is a black box. In Zero:
- Activity log: every agent action is recorded, with what changed, when and why
- Approval queue: outbound actions wait for a yes, if you decide they should
- Reversibility: record changes can be reviewed and corrected
- Scope: you decide which agents run at all. Agents are deployed by you, not switched on by default
What this adds up to in practice: teams stop logging into their CRM to do admin, and they still open Zero constantly, to review pipeline, prep for calls and approve outreach. Sumary moved its team off HubSpot and set up agents that create a task when an account goes seven days without contact or loses a key contact, so follow-up no longer depends on someone remembering to check every account. The team opens Zero to see what needs attention, not to type into it.
That is the honest version of "zero clicks": no logging in to do admin. Not "you will never open the app."
What agents still get wrong
- Agents occasionally match an email to the wrong company when domains are ambiguous, which is why matching is reviewable
- Enrichment data is only as fresh as its sources
- Drafts are drafts. A good follow-up written by an agent still reads better with 20 seconds of founder voice on top
- If your sales motion depends on judgment calls in every message, approve everything. The time saved in the admin layer alone is worth it
Where the line sits across the market
| Approach | Admin work | Customer facing actions | Risk profile |
|---|---|---|---|
| Legacy CRM (Salesforce, HubSpot) | Manual, or partial AI on fragmented data | Manual | Low risk, high labor: the tax is your team's time |
| Legacy CRM with bolted on agents (Agentforce, Breeze) | Partial: agents see only what their silo holds | Varies by add-on | Errors from fragmented context, automated chaos |
| Full autonomy positioning | Automated | Automated, or unclear | The recklessness the critics are right about |
| Zero | Autonomous on one complete record | Approval gated | Admin automated, judgment kept human |

