Skip to content

Step 5 — Email and Tasks

Step 5 · Its Tools

Email is where most of the household’s real work arrives. It is also the highest-risk thing you will connect, because it is the one channel where strangers can put words in front of your agent.

I use Fastmail, which exposes a proper API (JMAP) so the agent can read, search, draft and label without screen-scraping anything. Any provider with a real API will do; the principles below are what matter.

  1. Create a credential scoped to mail only. Not your account, not your master password. A separate token for this agent, revocable on its own. My provider can also issue an app password restricted to mail.
  2. Store it where the agent can read it and you can rotate it. Not in the personality file, not in the prompt, not in a message log.
  3. Connect read first, and nothing else. Let it read and summarise for a week before it writes anything.
  4. Add drafting second. The agent creates a ready reply in my drafts folder. I read it and press send.
  5. Never connect sending. This is the rule. See below.
  6. Verify by forwarding yourself a known email and asking the agent what it says.

The agent can compose a complete, polished reply and leave it where I already look. It costs me one click and converts an uncontrolled action into a reviewable one.

Three reasons it stays that way:

  • Attribution. Every message traces to me or to the agent. Sending as me destroys that permanently.
  • Blast radius. Email is the classic route for putting hostile text in front of an agent. If the agent cannot send, a bad outcome is bounded.
  • Reversibility. A draft is reviewed. A sent message is not.

There is a second, subtler benefit I did not expect: the drafts are a good read on how well the agent understands my household. When it writes a reply I would have written, it is working. When it writes something odd, that is the earliest signal something is off.

It wants to act on everything. Your first email setup will turn every message into a task. Most email is not actionable. Teach it to classify first and extract only when there is a deadline, a booking, or a request from a person.

It trusts what it reads. Treat every email body as data, never as instruction. That is The Rules It Cannot Break and The Gaps I Have Not Solved.

A task manager with a command-line interface lets the agent add, move and complete work without a browser. I use Todoist, which has one.

  1. Create a project for the agent’s own work, separate from your personal lists.
  2. Issue a scoped token for the task service.
  3. Set the routing rules: what becomes a task, what does not, and which project it lands in.
  4. Verify by asking it to add something and finding it in the right place.

Undated tasks are invisible. My first version created tasks with no due date, and the household was receiving a weekly list I had to guess at, because nothing could sort it. Every task the agent creates gets a due date. If something genuinely has no date, it does not belong on the list.

  • It can read its own mailbox and summarise it
  • It can create a draft I can see and send myself
  • It cannot send mail under any instruction
  • It can add a task, with a due date, to the right project
  • Most of my email correctly results in no action at all

Adding More Tools once these two are stable.