What is
Shadow mode?
Shadow mode is a propose-only operating mode for autonomous software. The system runs its full decision loop and prepares every action, but executes nothing: every proposal is routed to a human who approves, edits, or rejects it. It lets an autonomous operator prove its judgment on real decisions before it is trusted with execution.
Real decisions, withheld execution.
In Shadow mode the software does everything except act. It watches the same live data, reaches the same conclusions, and prepares the same actions it would take autonomously: a budget shift, a creative refresh, a pause. Each one is queued as a proposal with the reasoning attached. The human's response is the training signal: an approval confirms the judgment, an edit refines it, a rejection corrects it.
Over time, those responses produce a number. How often the human had to change a proposal is the override rate, and the override rate is the test of trust. A falling override rate is evidence that the operator's judgment matches its principal's. That evidence is what execution authority is granted against, one campaign at a time, never all at once. In Kerdixo, Shadow is the default for every account, Full Auto is earned per campaign, and reverting to Shadow is instant.
It makes the trust dial explicit and reversible.
Autonomy over ad spend is usually offered as a leap of faith: turn it on and hope. In Shadow mode the operator works on your real accounts and real decisions from day one, but the blast radius is zero until you widen it, and you widen it based on a record you watched accumulate, not a claim you were asked to believe. And the dial turns both ways: autonomy granted can be revoked instantly, which is what makes granting it rational.
A worked example: six weeks from proposals to authority.
The numbers are illustrative. In its first week on an account, an operator in Shadow mode makes 30 proposals: budget nudges, two creative refreshes, one recommendation to hold a campaign that looks tempting to scale. The buyer approves 24, edits 3, rejects 3: an override rate of 20%. Each correction teaches the operator where its judgment diverged. By week six, the weekly override rate has fallen to 5%, concentrated in one campaign type the buyer handles differently. The buyer grants execution authority on the two campaigns where overrides hit zero, keeps everything else in Shadow, and knows the grant can be reversed with one action. The operator is the same in week six as in week one. The evidence is not.
Q. How is Shadow mode different from an AI assistant?
An assistant waits to be asked and answers questions. An operator in Shadow mode runs the entire decision loop on its own initiative: ranking, planning, monitoring, and preparing complete actions. Only the final execution step is withheld. You are supervising finished work, not prompting it for help.
Q. When does a system leave Shadow mode?
When its proposals stop needing correction. The natural measure is the override rate: the share of proposals a human rejects or edits. When that rate stays low for a given campaign, execution authority can be granted for that campaign rather than globally, while every action remains inside pre-approved guardrails.
Q. Can autonomy be revoked after Shadow mode?
In a well-designed system, yes, and instantly. Autonomy is a dial, not a door: execution authority granted per campaign can be pulled back to propose-only at any time, with no penalty and no waiting period. Reversibility is what makes granting autonomy a reasonable decision in the first place.
Media-buying guardrail · Autonomous media buying · AI media buying agent · Agentic media buying · The full glossary