A [dry run](/workflows/triggers) walks one contact through a workflow on paper.
**Shadow mode** is the other half of that: the whole workflow, running for real
on your real audience, on the real clock — with every send written down instead
of sent.

Activate a workflow with `mode: shadow` and it goes **active**. Contacts enrol
through its ordinary triggers. Waits elapse. Branches evaluate. Consent is
re-checked. The only difference is the last inch: every externally visible
effect — a send, a `set attr.x`, an `add to list` — is **recorded on the run
timeline instead of performed**. Nothing leaves.


  This is the one thing to internalise before you use it. A workflow in shadow is
  **active and enrolling real contacts** — it just isn't mailing anybody. If you
  look at it and think "it's running but nothing has sent, something is wrong",
  that is shadow mode working exactly as designed. The dashboard says
  **Shadowing** across the top of the workflow for precisely this reason.


## Why rehearse

You can read a workflow and believe it. What you cannot read off the page is how
many people it actually reaches, how much mail it actually produces, and how much
of that mail your own consent rules would drop before it left.

A rehearsal answers those three questions on your real audience, and it answers
them before anybody receives anything. A welcome sequence that quietly fires four
emails in the first hour, or one whose entry filter matches ten times more people
than you expected, is a much cheaper discovery in shadow than in an inbox.

## Activating in shadow


  <Step title="Open the workflow and click Activate">
    You need the **manage workflows** permission. The workflow must be a draft or
    paused, and its definition must be valid — an invalid workflow enrols and
    steps nobody.
  </Step>

  <Step title="Choose Shadow instead of Live">
    The activate dialog offers the two modes. **Live** arms the workflow for
    real; **Shadow** arms the rehearsal.
  </Step>

  <Step title="Pick a cohort (recommended)">
    A **cohort** is a [List](/audience/lists) that bounds who may enrol into the
    rehearsal. Only its members can be enrolled; everyone else the triggers match
    is skipped, and the skip is recorded. Leave it empty and everyone the triggers
    match can enrol into the rehearsal.

    The dialog shows you both numbers — how many contacts are in the cohort list,
    and how many contacts the triggers match with no cohort at all — because
    either number on its own misleads. One hides what going live will do; the
    other hides how little your rehearsal is going to show you.
  </Step>

  <Step title="Activate">
    The workflow's status becomes **active** and the **Shadowing** banner appears.
  </Step>


Over the API this is `POST /v1/workflows/{id}/activate` with
`{"mode": "shadow", "cohort": {"list": "<list key>"}}`. `mode` defaults to `live`
when you send no body at all.


  Not a Segment. A cohort is a fixed roster of people you chose to rehearse on,
  and a Segment's membership moves underneath you while the rehearsal runs.



  A contact enrolled into a journey is in it. Pausing afterwards stops the journey
  stepping; it does not un-enrol anybody. That is true of a shadow run as much as
  a live one, which is what the cohort is for.


### The send-approval gate

Activation normally forces [send approval](/workflows/sends-and-approval) on for
any workflow that contains a send step. A shadow activation does **not** read or
write that setting: a rehearsal produces no batch of email for anybody to
approve. The gate is applied by the rule as normal when you go live.

## Reading what the rehearsal saw



The workflow detail page carries the rehearsal's numbers while it shadows, and
keeps them afterwards as its record:

- **Enrolled** — how many contacts the rehearsal actually took in.
- **Would send** — every send it recorded, across every send node, regardless of
  what consent decided about it.
- **Filtered by consent** — the subset of those recorded sends your consent rules
  would have dropped, broken down by cause: suppressed, globally unsubscribed,
  opted out of the topic, never subscribed to it, or over the frequency cap.

Those last two are separate numbers on purpose. **The mail that would actually
leave is the difference between them.** "How much mail is this?" and "how much of
my audience does this not reach?" are different questions, and one number answers
neither.

The per-node **funnel** on the canvas fills in the same way it does for a live
workflow, so you can see where the rehearsal's journeys actually got to. Each
contact's **run timeline** shows the recorded steps — including the sends that
did not happen, and the attribute writes and list adds that were noted instead of
performed.

To find out why a particular person is *not* in the rehearsal, use
[enrolment decisions](/workflows/enrolment-decisions) — contacts skipped for being
outside the cohort are recorded there with that reason.

## Going live

When the numbers look right, click **Go live** on the banner (or call
`POST /v1/workflows/{id}/go-live`). The same definition arms for real — there is
nothing to re-author and nothing to copy across.

Going live does three things in one step:

1. **Ends the shadow runs.** Every in-flight rehearsal run is cancelled. That is
   what frees each contact's single live-run slot so the same people can enrol
   for real.
2. **Switches the workflow to live** and clears the cohort.
3. **Re-runs the back-enrolment.** Any `enroll existing` backfill is registered
   again, so your back catalogue is enrolled properly this time rather than
   rehearsed.

The send-approval rule is applied exactly as it is at a live activation: a
workflow containing a send step anywhere — inside an `if`, a `split`, a `repeat`
or a `wait … timeout` — has the approval gate forced on.


  A contact the shadow observed can enrol again even under `reentry once`. The
  re-entry guards skip shadow runs entirely, which is what makes going live clean
  — nobody is excluded from the real journey for having been in the rehearsal.



  It ends journeys in flight and turns recorded sends into real email. If you need
  to stop it afterwards, **pause** the workflow. The rehearsal's record stays on
  the run timelines either way.


## What's next?

- [Triggers & enrollment](/workflows/triggers) — how contacts get in, and the enrollment scope.
- [Enrolment decisions](/workflows/enrolment-decisions) — why a particular contact was or wasn't enrolled.
- [Sends, consent & approval](/workflows/sends-and-approval) — the consent checks a rehearsal is counting.
- [Overview](/workflows/overview) — the workflow lifecycle end to end.