4 · Cold outreach to a found contact

Use case · the want as a person would post it:

“I found a researcher whose work matters to mine. Find their email and reach out on my behalf.”

WORKS TODAY Research is ordinary agent work; the outreach is the same gated CONTACT machinery as use case 2. The gates are what make cold outreach safe to allow at all.

The walk, step by step

Deal signed
FINISH

Blocks

Gates that fire Signing freeze.

Confirm the target and the pitch angle
APPROVE

Blocks confirm_correct

Gates that fire You confirm the who and the why before any contact exists.

Research: find the address, draft the note
PROVIDE → APPROVE

Blocks review_approve

Gates that fire Agent-side work; r100 pulses every 30 min. The draft shows you the found address as part of the reviewed bytes.

Approve the exact email
CONTACT / APPROVE

Blocks review_approve

Gates that fire Per-attempt, hash-bound. REJ-07 bans bare URLs in bids; r104 bans credential asks; contact-stop is always available to you.

Send, handle the reply
CONTACT

Blocks

Gates that fire Replies ride the inbound pipeline back into the thread.

Finish line
FINISH

Blocks yes_no

Gates that fire Binary only.

Where it can stall

Volume is the risk to watch: these gates are per-deal. Nothing yet rate-limits one person running many cold-outreach deals in parallel — a policy question to settle before this is promoted hard.

HAR Reference · generated 2026-08-29 from bid_validator.py, target_walk.py, deal_step.py · staging is source of truth