The most effective safety control for an email agent isn't a better model, a longer system prompt, or a stricter eval suite. It's a draft folder.
Here's the setup. covers how API traffic and mail-client traffic share the same underlying mailbox: anything sent via the API shows up in the client's sent folder, and vice versa.
Where to draw the autonomy line
Don't make this binary. A useful split:
Auto-send: replies the classifier marks low-risk and that match a known template family. These go straight out via/messages/send.
Draft-and-approve: anything mentioning money, account changes, or escalation language. Anything where the model's confidence is low. Anything addressed to a domain you've flagged as high-value.
Human-only: legal threats, press inquiries, anything the agent shouldn't even draft.
The scoping principle from the gets you from API key to a working mailbox in under 5 minutes, and the drafts endpoints work immediately on any account you create. Start with everything routed through the draft gate, measure how often the human actually edits the model's output, and loosen from there.
What's your edit rate? If reviewers are approving 95% of drafts untouched, I'd love to hear in the comments how you decided which categories were safe to automate.
SOCIAL SHARE CARD GENERATOR