Agent questions

How do I make an AI agent ask before it sends email?

Give the agent its own mailbox token with a send limit, and approve its drafts yourself. In Envelope a new agent can write drafts and can't send them. Each draft is saved to your Drafts folder and shows up on the dashboard's Review page, where you read it and decide.

Setup

Run these in your own terminal, so your password and the agent's token never pass through the agent.

# Install on macOS or Linux
curl -fsSL https://u1f4e7.com/install.sh | bash

# Add your mailbox and create a token for the agent
envelope accounts add --email you@example.com
envelope agent create claude-code

# Print the MCP config to paste into your agent
envelope mcp --config

# Open the dashboard at http://localhost:3141; drafts wait on the Review page
envelope serve

Claude Code, Codex and Cursor can install Envelope as a plugin instead of a pasted config. The README has the plugin commands.

The four send modes

Each agent has a send-mode ceiling that only you can change, with envelope agent policy set <name> --send-mode-ceiling <mode>.

  • draft-only is where every new agent starts. The agent saves drafts, and you send them.
  • confirm-send lets the agent send after you approve. Its send and reply calls save a draft and tell it to wait for you. Once you approve on the dashboard, its send_draft call goes through. If the draft changes after you approve it, it needs a new approval.
  • allowlisted-send lets the agent send without asking, only to the addresses and domains in its policy, such as --allow-recipients 'ops@example.com,@example.com'.
  • autonomous-send lets the agent send on its own. I'd keep it for mail you would already let a cron job send.

Under confirm-send, the agent's reply call comes back like this (trimmed), so a well-behaved agent tells you there is a draft to approve:

{"status": "drafted",
 "confirmation": {"required": "human_approval", "surface": "dashboard"}}

Where approval can be bypassed

An unauthenticated dashboard. On 127.0.0.1 with no auth configured, any program on your machine can call the dashboard, and that includes the agent. If agents run on the same machine, give the dashboard a token: envelope config set dashboard.auth_token "$(openssl rand -hex 32)".

An agent with your shell. It can run envelope without its token, which makes it you. Connect agents over MCP with their token where you can, and avoid handing them a terminal that has your Envelope access.

Tool parameters. MCP send tools take confirm_send and allow_recipient inputs. With an agent token those inputs only state what the agent intends; the recipient list comes from the agent's policy and the confirmation comes from your approval. Before 1.3.16 an agent could pass them itself, so update if you're on an older version.