Step 2 — Its Own Accounts
Step 2 · An Identity
A name is a decision. Accounts are the implementation, and this is the step people get wrong. Get it right and everything that follows is clean.
Three kinds of access
Section titled “Three kinds of access”Every capability the agent has falls into one of these. Classify before you connect anything.
| Kind | Meaning | Example |
|---|---|---|
| Its own account | Only the agent uses it | Its mailbox and address |
| Shared access | The household uses it too, and the agent can read or write | A shared family calendar |
| Borrowed access | The agent acting as a person | None. I do not do this |
The third row is the one to refuse. It is convenient, and it is the single most common way a household agent becomes a liability.
Do this
Section titled “Do this”- Create a new mailbox for it. A fresh account, not an alias of yours. It reads from here and writes from here.
- Create a user account for it on the computer. Its own home folder, its own permissions. Do not give it administrator rights.
- Share the family calendar with its identity — granted read and write. Share the reminder lists the same way. Share contacts as read-only.
- Issue a separate credential for each service it touches. One credential, one capability, individually revocable.
- Write the map down. Capability to credential, in one table. You will want this the first time something breaks, and the first time you want to withdraw one.
Why it gets its own mailbox and not yours
Section titled “Why it gets its own mailbox and not yours”This is the keystone decision, and it pays off in three ways.
Attribution. Everything the agent sends is traceable, because it came from its own address. Everything it receives can be handled without touching my personal inbox.
Blast radius. If the agent is ever manipulated through something it reads — and it will read hostile email — what it can reach is bounded. A mailbox of its own is a much smaller thing to lose than my whole inbox.
Simplicity. Its inbox contains only what it is meant to handle. No personal mail, no noise, no confusion about scope.
What I shared, and the asymmetry in it
Section titled “What I shared, and the asymmetry in it”The agent can write to calendars, reminders and lists, because those are surfaces where its work is visible and easy to undo. It can only read contacts, because that is a directory of my household’s relationships and it has no business editing it.
That asymmetry is deliberate. Copy it.
What it never gets
Section titled “What it never gets”- A person’s mailbox. Not read, not send. If it needs something from mine, I forward it. That one rule has prevented more trouble than any other.
- A person’s credentials. Not even for convenience.
- Anything that can spend money. It can research and compare. It cannot buy.
- Administrator rights. It runs as a normal user and cannot change the settings that govern it.
The one boundary that is absolute
Section titled “The one boundary that is absolute”The agent never holds a credential that lets it act as a member of the household.
It can read a forwarded message. It can prepare a draft ready for me to send. It can never press send on my behalf, and it never holds the credential that would let it try.
Three reasons, which is why this is a rule and not a preference:
- Attribution. Every action traces to a person or to the agent. A shared credential destroys that permanently.
- Blast radius. If the agent is manipulated, the damage is bounded by what it can reach.
- Reversibility. A draft is read before it leaves. A sent message cannot be unsent with confidence.
Checkpoint
Section titled “Checkpoint”- The agent has its own mailbox, and you can send to it and from it
- It has its own account on the computer, without administrator rights
- The calendar and lists are shared with its identity — you never handed over a password
- Each service has its own credential, and you have written down which is which
- Nothing it holds would let it act as you