Guides · Tag
permissions
9 guides tagged permissions.
Controls · Sep 21, 2026
Scoped Credentials for Agent Email: Read, Draft, Send
Give an agent the smallest useful email permission: project and inbox scoping, one-time secrets, draft-only grants, rotation, and revocation you can verify.
Inboxes · Sep 21, 2026
AI Agent Inbox vs Connecting Gmail: How to Choose
Giving an agent its own inbox versus wiring it into an existing Gmail or Microsoft 365 mailbox: identity, blast radius, OAuth scope and revocation.
Email for Agents · Sep 21, 2026
Email for AI Agents: How Agent Inboxes Actually Work
What an email inbox for an AI agent is, how mail arrives and leaves, which permissions matter, and when an agent needs its own address instead of yours.
Inboxes · Sep 21, 2026
Signup and Verification Codes in an Agent's Inbox
Agents that create accounts need a real mailbox for verification email. How to provision one, read the code safely, and where this becomes unacceptable use.
Integrations · Sep 21, 2026
How to Give an AI Agent Its Own Email Address
Create a dedicated inbox, choose read, draft or send permission, connect over MCP or a scoped key, and prove a real round trip before granting send access.
Controls · Sep 21, 2026
Human Approval Before an AI Agent Sends Email
When to require review, why approval binds to one exact draft version, how recipient rules and daily caps work, and what editing a draft does to its approval.
Integrations · Sep 21, 2026
MCP Email Server: Give Your Agent Client a Real Inbox
How a remote MCP email server works, what the consent screen must show, how to scope a grant to one inbox, and how to verify it before allowing sends.
Controls · Sep 21, 2026
Prompt Injection by Email: What Actually Helps
Any stranger can email your agent. What an email-borne injection looks like, why message text must never grant permission, and the controls that limit damage.
Integrations · Sep 20, 2026
MCP or API Key for Agent Email? How to Choose
Remote MCP over OAuth or a project-scoped REST key: what each can and cannot do, who authorises it, how revocation differs, and why teams use both.