The autonomy map for CRM

DecisionAutonomyWhy
Segment membershipModel decides, refreshed continuouslyReversible, low-consequence, monitored in aggregate
Send time & channelModel decidesCheap to be wrong per-instance; measurable in aggregate
Content & offer orderingModel chooses among approved optionsThe catalogue is governed; the ordering is not the risk
Offer economics & termsRules, owned by the bonus engineCost control and auditability — see bonus economics
Eligibility & suppressionHard gates, upstream of the modelConsent, RG, cooldowns and market rules are constraints, not features
Player-facing wordingGenerated within locked templates, human-reviewed at template levelCompliance wording is not creative surface

One rule engine, still

The pre-AI failure mode was eligibility logic split between the CRM tool and the platform (the double-granting problem from bonus economics). The AI era's version is worse: a model in the campaign tool optimising against a copy of the rules rather than the rules. The architecture that holds is unchanged — one rule engine, one audit log — with the model as a proposal source feeding it, so every send resolves to: gates passed, rule version, model proposal, outcome. Four fields, and the audit answers itself.

Protection as structure, not policy

Two properties have to be impossible rather than forbidden. Suppression is enforced at the single send gate (the same one-gate architecture as tracking), so no model, no campaign and no CSV export can route around it. And protection signals are physically absent from marketing feature stores — the model cannot learn from what it cannot see. Operators who implement these as review checklist items instead of architecture spend every audit proving a negative.

Measurement: the model does not grade itself

AI CRM inherits the full measurement discipline: a standing global holdout (the programme's overall incrementality), per-mechanic holdouts for material tactics, value read at honest horizons with censoring declared, and — specific to the model era — periodic challenger runs where the model's targeting is compared against simple rules on matched cohorts. The last one is regularly humbling and always worth it: the delta over good rules, not the lift over nothing, is the model's actual contribution.

The operating shape

Where this lands in practice is the daily-brief pattern: the model does the overnight work — segments refreshed, queues ranked, offers proposed within rules — and the morning surface presents decisions with their economics attached, humans working the exceptions. That is the operating model described in the AI operations brief and the VIP cockpit; the governance in this cluster is what makes that pattern defensible at scale.

Continue reading: Model risk — drift and decay in the models this page automates with. AI governance — the register these decisions live in.