cadohq
Start free trial
Governance layer

The AI governance layer for RevOps.

Your team already reviews AI-written code before it ships to production. Outbound is the last place where AI output goes straight to the outside world, to prospects, under your brand, from your domain, with no review layer at all. cadohq is that layer: policy is authored and versioned, a gate enforces it in the send path, overrides are logged, and leadership sees the posture of the whole program.

One principle underneath all of it: the system that generates the message can never be the system that clears it. Sequencers are paid on volume sent. A governance layer is paid on judgment, so it has to stand outside the send path it governs.

Shipping in stages. Live today: the versioned ruleset, the gate (block rules force hold, revise rules cap the verdict), per-score policy checks, and the append-only audit log. Illustrative below: exceptions and approvals, posture, and coverage, which arrive with multi-user workspaces.
Why now

Three forces converged. Generation became free, so outbound volume multiplied. The mailbox providers turned deliverability into a machine-enforced compliance regime with a two-tenths-of-a-percent margin for error. And the teams deploying AI are scaling something they say they do not trust. Each number below is sourced and named, because a governance product should govern its own claims first.

0.30%
spam-complaint ceiling enforced by Gmail, with 0.10% the recommended line. Since November 2025, enforcement includes permanent rejections.
Google sender guidelines
0.45%
average cold email reply rate across 7.5M sends in 2025, down 20% within the year.
Belkins, 2025 campaign data
356%
more closed deals from AI used to filter audiences. The highest-impact use of AI in prospecting was not writing copy.
Sopro, State of Prospecting 2026
<10%
of 300+ surveyed RevOps leaders report ROI from AI, while roughly 45% plan to expand AI usage anyway.
Default, State of AI in RevOps

The asymmetry that makes this a governance problem: AI generates per message, but the punishment lands per domain. One cadence past the complaint ceiling degrades inbox placement for every sequence the company runs. Microsoft matched the regime for Outlook in May 2025. The governable unit is the sending program, not the single message.

Where sequencers do ship governance controls, they govern access, not content: admin toggles that switch AI features on or off, and usage logs written after the send. Access control and monitoring are necessary. Neither one reviews what the AI wrote before a prospect reads it. Pre-deployment review of the content itself is the unowned layer, and it is the layer regulators and risk frameworks keep converging on: NIST AI RMF, ISO 42001, and the EU AI Act all require documented human oversight of AI output, and the AI Act's transparency obligations take effect August 2, 2026 with fines up to 15 million euros or 3 percent of worldwide turnover.

Sources: Google email sender guidelines · Microsoft high-volume sender requirements, April 2025 · Belkins cold email response rates, 2025 · Sopro State of Prospecting 2026 · Default, The State of AI in RevOps, 300+ teams · EU AI Act, Article 50. Vendor-published figures are attributed to their vendor and are their measurements, not ours.

The control loop
Policy
Versioned rules, owned by RevOps.
Evaluate
Hard rules plus the six-dimension score.
Gate
Deploy, revise, or hold, in the send path.
Exception
A different role clears it, logged.
Send
Only a current pass ships.
Audit
Append-only: who, what, when, why.
Posture
Are we governed, across the program.
Coverage
Every send routes through the gate.
Policy catalog
ruleset v2026.06

Rules are machine-readable, individually owned, and versioned. Compliance rules are deterministic pass or fail. Quality rules carry the model score. Each rule has an enforcement level: block cannot be overridden in product, revise needs an approved exception, advisory annotates and ships.

R-01Working unsubscribe present
ComplianceBlockEnforcingv2026.06
R-02Sending domain authenticated (SPF, DKIM, DMARC)
ComplianceBlockEnforcingv2026.06
R-03Physical postal address in footer
ComplianceBlockEnforcingv2026.06
R-04EU and UK lawful basis attached
ComplianceBlockDry-runv2026.06
R-05Projected daily volume under the bulk line
DeliverabilityAdvisoryEnforcingv2026.06
R-06Named proof point for any VP-level touch
QualityReviseEnforcingv2026.05
R-07No guaranteed-outcome or regulated claims
ComplianceReviseEnforcingv2026.06
R-08Each step adds new value, no repeat-ask
QualityAdvisoryDry-runv2026.06
R-09Composite score at or above workspace threshold
QualityReviseEnforcingv2026.06
The gate

The gate fails closed. A cadence ships only with a current passing verdict tied to its exact version. Not yet scored counts as hold. Any failed block rule forces hold regardless of score.

Auto-deploy
Score at or above 85 and every block rule passes.
Revise
Score 70 to 84, or a revise rule failed. Ships with an approved exception.
Hold
Score under 70, or a block rule failed. No in-product override.
Exceptions and approvals

The author is never the approver. A held or revise cadence ships only when a different role clears it, with a written reason. Every override is a logged, time-boxed event, not a global off switch. This is what keeps the control on instead of routed around.

EX-118Awaiting approval
Dana K. requests to ship cadence-9241, held on R-06.

Reason given: "Verbal proof point came up on the discovery call, adding the named reference next week."

Author: Dana K. (rep)Approver: a manager or ops, not DanaExpires: this send only
Audit log

Append-only and tamper-evident. Every score, gate decision, override, and rule change is recorded with who, what, when, why, and the ruleset version in force. This is the record that answers, months later, why a sequence shipped, and the evidence a security review asks for.

2026-06-19 15:10
cadence-9128 · Evaluated, verdict Auto-deploy
scorer · score 85 · ruleset v2026.06
2026-06-19 14:48
cadence-9241 · Exception requested
Dana K. (rep) · reason: verbal proof point from discovery, adding next week
2026-06-19 14:32
cadence-9241 · Evaluated, verdict Revise
scorer · score 72 · failed R-06 · ruleset v2026.06
2026-06-18 09:05
ruleset · R-04 set to dry-run
Priya M. (RevOps admin) · reason: measuring impact before enforcing
2026-06-17 16:20
cadence-9090 · Held, no override
gate · failed R-02 · DMARC record missing · ruleset v2026.05
Posture

The "are we governed?" view for leadership, distinct from per-rep coaching. Pass rate against the threshold, exception rate, coverage, and prevented sends, trended over time.

78%
of cadences cleared the gate this month
up from 71% in May
6%
exception rate
14 of 233 held cadences overridden, all logged
92%
of sends routed through cadohq
8% shadow sends flagged for coverage
31
compliance blocks this month
sends prevented before they shipped
Coverage

Governance only holds if nothing escapes it. A send that never reached cadohq is ungoverned, so coverage is tracked as a first-class number and shadow sends are flagged. Deliverability makes this concrete: one rep past the 0.3 percent complaint line degrades inbox placement for every cadence the org runs, so the governable unit is the sending program, not the single message.