An agent that reads mail written by strangers and can send mail as you is, by construction, a way for a stranger to send mail as you. Every prompt-injection paper is a variation on that sentence. So before Sodaroad's agents could send anything, we built the rails.
Seven permissions, one enforcement point
Read messages, draft replies, send without approval, archive and label, access attachments, call external tools, contact new recipients. Each is a switch on the agent. The effective capability is the agent's permissions intersected with the channel's scope, computed in one place so there is exactly one answer to 'can this agent do this here'.
Approval is on the row
There is no separate queue to check. When an agent drafts a reply that needs you, the draft sits on the message row with Approve and Edit. When it archives something, the row says so. A filter shows you everything that came from an agent.
Budgets, and what happens at the limit
Each agent has a monthly budget and a per-task ceiling, and an explicit on-limit behaviour: pause, or notify. Cost shows live in the activity tray while a run is happening, in dollars, not tokens.
None of this is exciting. That is the point. The exciting part is what people do with an agent they can trust.
By Cameron