Outcome · Operations
Operations agents for LinkedIn
Keep the machine honest: pacing, approvals, an inbox that is triaged, and a record of what actually ran.
How these act
- Human approves — Drafts the action; nothing irreversible happens until a person presses send.
You bring
- An existing outreach setup worth operating — campaigns, senders, an inbox.
- A person who owns the approval queue. Approval is the rail; it needs an owner.
What it takes
The capabilities this job runs on
A capability is one thing an agent can do, and each one names what performs it: a live MCP tool, a skill, or a workflow. 13 of 14 can be performed today.
Check the remaining LinkedIn budget
Low riskHow many LinkedIn tool calls this workspace has made this month, broken down by tool, plus the rate limit in force. The call an agent makes to pace itself instead of discovering the limit by hitting it.
Runs on get_usage · Read only
Judge whether an account is safe to keep running
Low riskReads sender status, warm-up stage, daily invite and message counters and the health score, and turns them into a decision with a reason: keep going, slow down, or stop. Written down because the failure it prevents — a restricted LinkedIn account — is not reversible by changing a setting afterwards, and because the signals that precede it are visible in what these tools already return.
Performed by a skill — instructions your AI client follows. · Read only
Plan work against the limits before spending them
Low riskTurns a piece of work into an arithmetic question against three separate budgets — thirty LinkedIn calls per five minutes per workspace, the monthly allowance the usage report names, and each sender's daily caps — and says what fits, what has to be paced, and what does not fit at all. The point is to discover a limit on paper rather than by hitting it mid-run.
Performed by a skill — instructions your AI client follows. · Read only
Read campaign performance
Low riskEvery campaign in the workspace with its live funnel counters — invited, connected, replied — and the two rates already rounded to whole percentages.
Runs on list_campaigns · Read only
Read the approval queue
Low riskThe AI-written replies waiting for a person to press send. An agent can read and summarise this queue; it cannot approve anything in it, and that is deliberate — sending is the one irreversible action in the product.
Runs on list_tasks · Read only
Read the credit balance and its ledger
Low riskThe workspace balance and the entries behind it, with whether the balance can refuse anything at all reported alongside the number — because enforcement is off by default and a meter read as a spending limit is worse than no meter.
Runs on check_credits · Read only
Read the unified inbox
Low riskOne thread per lead across every sender account, with full message bodies and — once a reply has been classified — its intent. There is no since or limit argument; the whole inbox comes back.
Runs on get_inbox · Read only
Read the workspace roll-up
Low riskSenders, campaigns, leads, invited, connected and replied, counted across the whole workspace. The cheapest way to answer "how is outreach going" without walking every campaign.
Runs on get_stats · Read only
Read what this workspace has run
Low riskInstalls, purchases, the hosted seat, credits and the execution ledger over a window: what ran, what succeeded, what failed and the class of failure. The same rows the Executions page shows a person.
Runs on get_platform_usage · Read only
Read what this workspace owns
Low riskWhat has been installed, where, at which version, and what was paid for it — including removed installs when asked for the full history. The library, read back as rows rather than as a page.
Runs on list_installations · Read only
See which LinkedIn identity is available
Low riskThe accounts this workspace can act as, each with status, warm-up stage, how much of today's invite and message budget is spent, and a health score. Reads our own database, so it costs nothing against the LinkedIn rate limit and is the cheapest first call an agent can make.
Runs on list_sender_accounts · Read only
Stop a campaign from sending
Low riskThe only tool that writes anything, and it writes to our database rather than to LinkedIn: it stops outbound. There is no resume tool, because restarting a campaign is a deliberate human action in the app.
Runs on pause_campaign · Read only
The standing review that keeps the machine inside the rails
Low riskA fixed pass over the things that go wrong quietly: sender health and checkpoints, how much of each daily cap is spent, the monthly LinkedIn allowance against the calendar, the approval queue's age, the execution ledger's failures by class, and the credit balance. It ends in a written decision per account and, where the answer is stop, the one tool call that stops it.
Performed by a workflow — a sequence of steps, not a single call. · Human approves
Not built yet
These are declared in the registry so a product page can say “not yet” instead of implying it. Nothing performs them today:
- Run a product on a schedule, server-side — Not built yet. install_product records an installation and runs nothing: every workflow in this catalogue runs inside your AI client, when you run it. Nothing here wakes up on a Monday morning and does the week's research on its own, and no product page should be read as saying otherwise.
The products
1 product does this job
Each card is a real catalogue row: its price, its risk level and how it acts are the fields the product itself declares, not marketing written per page.
What it costs
Only the tiers this outcome actually uses
- Pro kit$491 product
- A skill plus MCP wiring, workflows and the files they read.
There is no payment processor connected yet. Checkout records a real order against your workspace and tells you exactly what happens next — nothing is charged, and no card is asked for. The whole ladder is on pricing.
What it risks
The part most sites leave out
Products under this heading read and report. The one class of action they may take is stopping something — pausing a campaign — because that is the only irreversible-adjacent action that is safe to hand to a model.
- Low risk
- Reads only, at human pace. No writes to LinkedIn.
LinkedIn does not endorse, certify or sanction any of this, and nobody — including us — can promise an account will not be restricted. What we can do is keep the irreversible actions behind a person, cap the pace, and tell you which side of that line a product sits on before you buy it. The mechanics are on security.
Other outcomes: Sales · Recruiting · Content · Networking · Data