The autonomy map for CRM
| Decision | Autonomy | Why |
|---|---|---|
| Segment membership | Model decides, refreshed continuously | Reversible, low-consequence, monitored in aggregate |
| Send time & channel | Model decides | Cheap to be wrong per-instance; measurable in aggregate |
| Content & offer ordering | Model chooses among approved options | The catalogue is governed; the ordering is not the risk |
| Offer economics & terms | Rules, owned by the bonus engine | Cost control and auditability — see bonus economics |
| Eligibility & suppression | Hard gates, upstream of the model | Consent, RG, cooldowns and market rules are constraints, not features |
| Player-facing wording | Generated within locked templates, human-reviewed at template level | Compliance wording is not creative surface |
One rule engine, still
The pre-AI failure mode was eligibility logic split between the CRM tool and the platform (the double-granting problem from bonus economics). The AI era's version is worse: a model in the campaign tool optimising against a copy of the rules rather than the rules. The architecture that holds is unchanged — one rule engine, one audit log — with the model as a proposal source feeding it, so every send resolves to: gates passed, rule version, model proposal, outcome. Four fields, and the audit answers itself.
Protection as structure, not policy
Two properties have to be impossible rather than forbidden. Suppression is enforced at the single send gate (the same one-gate architecture as tracking), so no model, no campaign and no CSV export can route around it. And protection signals are physically absent from marketing feature stores — the model cannot learn from what it cannot see. Operators who implement these as review checklist items instead of architecture spend every audit proving a negative.
Measurement: the model does not grade itself
AI CRM inherits the full measurement discipline: a standing global holdout (the programme's overall incrementality), per-mechanic holdouts for material tactics, value read at honest horizons with censoring declared, and — specific to the model era — periodic challenger runs where the model's targeting is compared against simple rules on matched cohorts. The last one is regularly humbling and always worth it: the delta over good rules, not the lift over nothing, is the model's actual contribution.
The operating shape
Where this lands in practice is the daily-brief pattern: the model does the overnight work — segments refreshed, queues ranked, offers proposed within rules — and the morning surface presents decisions with their economics attached, humans working the exceptions. That is the operating model described in the AI operations brief and the VIP cockpit; the governance in this cluster is what makes that pattern defensible at scale.
Continue reading: Model risk — drift and decay in the models this page automates with. AI governance — the register these decisions live in.