answers
The questions, answered straight
Each of these is a question operators are actually asking in public, and each answer leads with the short version. Where we have a number we publish it. Where we do not, we say so.
Data and sourcing
No. Sales Navigator improves search filters and adds InMail credits, but it does not raise the invitation limit and is not required by any outreach tool. If your targeting is already tight, a normal account plus a good list will outperform Navigator plus a loose one.
Two places, and no third. Search runs through your own LinkedIn seat using your own entitlement, and you can import your own CSVs. There is no bundled contact database and no purchased data, which is a deliberate product decision rather than a gap.
Safety and restrictions
A dedicated IP removes one old technical signal and does nothing about the behavioural ones that actually drive restrictions in 2026. It is worth having and is nowhere near sufficient. Pace, targeting and account age decide the outcome.
No. LinkedIn restricts accounts for behaving like automation, not for using it. The tool is invisible to the platform; the pattern is not. Mechanical timing, around-the-clock activity, and volume that ignores falling acceptance are what get scored.
Almost nobody is banned for using a tool. Accounts get restricted for a pattern: volume on a young account, mechanical timing, identical copy at scale, falling acceptance that nobody slowed down for, and "I don't know this person" reports. Enforcement arrives as a ladder, and the first rung is survivable.
Stop all outbound immediately, work out which rung of the ladder you are on, and do not appeal with a template. Most restrictions are invitation level and clear on their own once you stop feeding the signal. Identity checks need the real document. Then fix the targeting that caused it.
Spend the first week looking like a person: profile finished, a handful of real comments, invitations only to people who will obviously accept. Then ramp. Our new seats run at 20 invitations a day and 80 a week, multiplied by 0.5x in week 0, 0.75x in week 1, and full rate from week 2.
LinkedIn publishes no invitation limit at all. Not daily, and not the 100 a week the whole category quotes. Its help pages describe restriction triggers in words and give recovery durations, never a number. So every figure you have read, including ours, is somebody's policy. Ours is 20 a day and 80 a week on a new seat, ramped and enforced.
Yes. LinkedIn's User Agreement section 8.2 prohibits bots and unauthorised automated methods, and every third-party outreach tool sits against that clause, ours included. What the clause does not say is that using one gets you banned. Enforcement is behavioural and it arrives as a ladder, not a switch.
MCP and agents
Most open-source LinkedIn MCP projects expose read-only lookups: fetch a profile, run a search, read an inbox. They cannot run outbound, because outbound is a write with consequences. The difference is not model quality, it is whether the server will send and what happens when it does.
An MCP server gives an AI assistant hands. Without one the assistant can describe what to do; with one it can do it, in your account, against real state. The value shows up only when the task is mechanical, repeated and needs live data.
Four things, roughly in the order they bite: tool discovery, the context cost of a large tool surface, auth that expires in disguise, and the idempotency of writes. A read that fails is an annoyance. A write that fails, or quietly succeeds twice, reaches a real person.
Yes, but not for the reason most builders hope. Nobody pays for the protocol. They pay for what sits behind it: state worth keeping, constraints enforced somewhere they cannot edit, and writes with consequences. A server that only reads has no floor under its price.
Add https://mcp.linkedboost.ai/mcp as a custom connector in Claude, complete the Google sign in, then tell the assistant to connect your LinkedIn account. Verify by asking what is in your workspace and expecting real numbers back. A connector showing as added is not proof that any of it works.
Search your own seat, import your own CSVs, research a person into a persistent column, run approval-gated sequences, send invitations and messages, comment and react on other people's posts, work the inbox, and report on all of it. It will not publish your posts and it does not sync anywhere.
AI SDRs
Fully autonomous AI SDRs mostly did not hold. The teams still getting value moved the agent from decision-maker to operator: it researches, drafts and paces, a human approves, and volume stayed where a human could review it. The failure was never the writing.
Because the bill arrived before the pipeline did. Contracts were signed on a promise measured in quarters, while the cost, in account standing and recipient goodwill, was spent in weeks. The deployments that renewed kept a human on the approval gate, volume small enough to review, and targeting nobody outsourced.
Five checks, in this order: where the approval gate sits, whether limits are enforced or merely suggested, what happens when a cap is reached, whether the vendor publishes how it measures account health, and whose data the leads come from. A ranked list ages badly. A rubric you can run yourself does not.
It is the wrong either/or. An agent is better at reading every profile, drafting something specific for each one, and never forgetting who was already contacted. A human is better at judgment, discovery calls and relationships. The useful split is operator against decision-maker, not replacement.
Start from a signal you can name in one sentence. If you cannot say why this person and why now, no amount of rewriting saves the message. Then hold it to four lines and one idea, cut every compliment without a referent, and give every merge variable a fallback.
Agencies
One seat per client, caps enforced per seat rather than per agency, and one shared suppression layer so two clients never work the same company in the same week. The failure mode is not tooling. It is planning capacity at the agency level and discovering the ceiling is per account.
Sometimes, and rarely for the reason quoted. You are not buying software: the tooling layer runs $29 to $119 a month. You are buying targeting judgment, per-audience copy and daily inbox time. If an agency will not show you its list logic, you are paying a markup on a subscription.
The software is the cheapest line. Agency is $119 a month for up to 10 accounts, which is $11.90 per client seat at a full roster, $59 covers 3 and $29 covers 1. What costs real money is operator time on the approval queue, and capacity that is fixed per seat.
One company, one seat, one week. It is a practice rather than a setting: before enrolment the agent checks company interaction history and searches active sequences for that company, and every CSV you import turns past outreach into suppression. Nothing in the product silently blocks a second seat for you.
No. There is no white-label reporting in this build: no client portal, no branded dashboard, no logo swap, no scheduled client email, and no date we are willing to promise. What exists is per-seat observability inside the workspace, an agent activity log, and an assistant that drafts the update for you.
You do, commercially, whatever the vendor's terms say. The tool loses a seat; you lose a relationship and possibly the retainer. That asymmetry is the reason agency-side rules should be stricter than anything a vendor enforces, and the reason it belongs in the contract before the first invite.
recruiting
The tools are identical to the sales build: the same 50, the same seven categories. What changes is the motion. Candidates reply to a specific role and a real reason, requisition deadlines push volume in exactly the direction that collapses acceptance, and there is no ATS integration here to hide behind.
Five layers: an ATS as the system of record, a LinkedIn seat for sourcing, an outreach layer that sends, scheduling, and measurement. Only the outreach layer is genuinely contested in 2026. Buy the seat first, skip the bundled contact database, and expect the joins between layers to be manual.
How to
Three motions carry it: a narrow list built from a signal, warm engagement before the ask, and personal outreach that names the signal. Ads buy attention; none of these do. Our own history says the list decides the outcome: two audiences, comparable copy, 32% and 2.6% acceptance.
30 to 50% is healthy for cold outbound. We average 41% across 861 conversations over three years and five seats. Under 20% means targeting is broken, 20 to 30% means relevance is thin, 50 to 60% is a strong signal match, and over 60% usually means a warm audience.
Usually by inviting people who already know of them, or an audience one step from their own network. That is real, and it is not a cold motion you can copy. Over 60% almost always means warm or adjacent targeting. Our cold average is 41% across 861 conversations, and we would not claim more.
The ones that name a specific signal and ask for almost nothing. Four lines maximum: the signal stated plainly, why it matters to them, who you are in six words or fewer, then no ask or a micro ask. Wait one to three days after acceptance. Three follow ups over ten to fourteen days, then stop.
Partnership outreach asks for shared upside rather than a purchase, so the qualifying question is overlap, not budget. The list is tiny, the research is heavier per name, the first message names what you can send them, and none of it forecasts like a sales pipeline. Volume tactics actively hurt it.
Start with a small, relevant audience and plan a few relationship-appropriate touchpoints. Check each person's connection status and conversation before the next step, then stop on a reply, decline or request to stop. A saved sequence is a plan, not proof that an invitation or message was delivered.