Agent Inbox is designed around scoped authority, approval gates, untrusted-input handling, tenant-aware access, and inspectable action records for AI agents working through email.
Email is treated as untrusted input
Incoming messages can contain spoofing, impersonation, malicious instructions, prompt injection, or unsafe requests. Agent Inbox evaluates those risks before permitting consequential actions.
Prompt-injection awareness
Suspicious-request evaluation
Policy checks before action
Authority is explicitly scoped
An agent’s role, objectives, prohibited actions, accessible data, tools, and escalation requirements define its operating boundary.
Permission-aware data access
Narrow tool scopes
Prohibited-action rules
Sensitive actions can require approval
Teams can choose draft-only, approval-gated, or autonomous operation according to the risk and reversibility of each workflow.
Configurable approval thresholds
Context supplied to reviewers
Progressive autonomy
Actions remain inspectable
Decision records preserve the context, policies, tools, and approvals associated with an action so teams can review unexpected behavior.
Decision context
Tool and approval history
Operational investigation
Data access follows authorized scope
Cross-inbox and organization-wide insight is permission-aware. Access is configured around the customer’s users, agents, and data model.
Tenant-aware authorization
Scoped conversation access
Customer-controlled integrations
Security and privacy questions
Security issues and data-handling questions can be reported directly to Agent Inbox. The public AI and Data Handling Policy contains processing and retention details.