What the Ultra Ops agent actually does today (and doesn't)
Build-in-public update — Ultra autonomous lead-gen pipeline
We shipped a conversational layer over the Ultra pipeline called the COO agent. Here's exactly what it can and can't do, because the gap between those two things is the whole point.
What it reads
The COO agent has read access across three areas:
- Pipeline — agent run history, funnel metrics, pending approvals, outcomes
- Control Plane — run modes, app settings, listen sources, sourcing targets, the policy matrix
- Content Desk / Leads — drafted content, the leads CRM and touch history
You can ask it what the pipeline did last week, what's sitting in the approval queue, or what the current sourcing targets are. It answers from live data.
What it can write — exactly two things
- Append a note to a lead's touch history
- Submit a new content brief — which lands as a shadow draft in the same approval queue a human-submitted brief uses
That's it. Neither of these bypasses a human. The note is additive. The brief still needs a founder approval click before anything publishes.
What it cannot do
Everything else is gated. Flipping a run mode, editing app settings, adding a listen source, deciding a pending approval — the COO agent has no tool that executes any of those. The most it can do is generate a Console deep link and hand it to you.
This isn't a bug or a placeholder. It's the same logic baked into the live policy matrix.
What the policy matrix actually says (as of 2026-07-29)
- Auto (no approval needed): transactional email sends, proposal drafts, Reddit drafts
- Queue for review (founder click required before anything executes): blog publish, Facebook post, Instagram post, nurture emails, reply emails, vault promotions
- Forbidden (hard-blocked, full stop): cold email, LinkedIn posting, autonomous Reddit posting
The five scheduled pipeline agents — heartbeat, marketing, nurture-sweep, proposal-sweep, sourcing-weekly — are all running in live mode. "Live" describes their execution mode. It says nothing about what the COO agent itself can touch. Those are separate things.
Why build it this way
A conversational agent that can read everything and act on almost nothing sounds like a limitation. We think of it as a trust sequence.
The COO agent earns its place by being useful as a read layer first — surfacing what's happening, flagging what needs attention, drafting briefs for review. Every consequential action still runs through a human. That's not a temporary state we're tolerating; it's the design.
Whether the agent's write permissions ever expand is an open question for the team to decide based on how this layer performs — not something on a confirmed roadmap.
If you're building a similar approval architecture over an autonomous pipeline and want to compare notes, reply here or email me directly.
Samir Grouicha Skylab Innovations — AI systems built for revenue samir@skylabinnovations.com · skylabinnovations.com
The free 30-minute audit
Thirty minutes, your numbers, and a straight answer on where a system would pay for itself.
Book the audit → — If I can't name at least three specific things worth fixing, I'll say so in the first ten minutes and give you the rest of your time back.