Agent email
betaSet up agent mailboxes with simple incoming and outgoing address rules, blocked senders, and visible activity.
Agent email lets a persistent agent receive work and send email from a d5s address or a dedicated Gmail mailbox. Both can remain connected at the same time, with separate settings.
Default email permissions
When draft identity setup is enabled, the agent’s address can appear during its setup conversation. Enabled means the inbox exists; the draft agent cannot execute work or send replies until activation. Email received during setup is retained as blocked activity and is not automatically replayed on activation.
New automatic inboxes start with matching incoming and outgoing rules. For business email, d5s infers an organization email domain from the organization owner's verified address. For recognized personal email providers, the inbox allows only its creator's exact verified email address, including in a business organization. A member joining the organization does not change its inferred domain. Existing inboxes keep their saved settings.
These are initial communication rules, not verification that the organization owns a domain. Domain matches never grant organization or workspace access. Automatic inboxes begin with per-email approval required. Saving reviewed mailbox settings switches matching outgoing recipients to automatic delivery; the confirmation explains that change before it is applied. Open the mailbox's Email settings to edit incoming and outgoing rules separately. Accounts without a current verified email keep the manual setup flow.
Set up a mailbox
In the agent sidebar, open Channels and select d5s Email or Gmail to go directly to that provider’s mailbox settings. You can also open Manage channels → Email, then choose the d5s or Gmail tab. The Channels menu continues to show each provider’s connection status.
Where available, new agents created by a signed-in user with a verified email automatically receive a d5s address. Existing agents can use Create d5s address without signing in to another mailbox. New addresses use a short random suffix; existing addresses stay unchanged. Retired addresses are never reassigned, even after the agent or workspace is deleted.
For Gmail, choose Connect Gmail, sign in to a dedicated mailbox, and grant read/send access. Existing mail is not replayed on initial connection. The credential is reserved for this agent and does not become a workspace connector or a project tool.
Provider tabs only select which settings you edit. They do not disconnect other providers or change the default mailbox. One mailbox per provider can be connected to an agent.
Incoming and outgoing
Each mailbox has two independent controls:
- Incoming — Who can email this agent? Choose Anyone or Specific people or domains. Use an exact address or a domain such as
@example.com. Empty specific lists admit nobody through that rule. A matching choice also admits automated notifications and mailing-list messages from that sender as ordinary agent work. Where available, choosing Anyone also lets you turn on Review unknown senders first as described below. - Accept replies from people this mailbox emails is off for automatic inboxes so their initial allowlist remains exact; manually connected mailboxes start with it on. It also allows incoming mail from an address this exact mailbox successfully sent to. Drafts, pending approvals, failed or uncertain sends, and another mailbox's sent history do not qualify. This does not change outgoing permissions.
- Outgoing — Who can this agent email? Choose specific addresses/domains or Anyone. Unrestricted outgoing access has an explicit Danger confirmation. Matching sends run without per-email approval after you save the new rules.
Use My email domain to add the domain from your signed-in email address without typing it. This shortcut is hidden for common shared email providers. It is a suggestion, not proof of organization ownership: it changes only the Incoming or Outgoing list where you select it, and takes effect after Save changes. Use Add address or domain for other entries. An address already covered by a domain rule does not need to be added separately.
Automatically provisioned d5s inboxes use the defaults above. Manually created or connected mailboxes start with empty address rules. Existing policies and queued approvals keep their old behavior until explicitly updated. Changing only an advanced limit does not turn an existing off or reply-only policy into proactive sending. Converting legacy approval/copy settings requires a clear settings confirmation; it never automatically sends queued drafts.
New email uses an explicitly chosen mailbox or the designated default. Replies use the original receiving mailbox and correspondent. A blocked send never retries through another provider.
For d5s and Gmail mailboxes, under Email identity, set a Sender name when recipients should see a role such as “Engineering Ed” instead of the agent's internal name. The preview shows the resulting Name <address> identity. This changes the display name on new outgoing mail from that mailbox; it does not rename the agent or change its email address. Microsoft mailboxes continue to use the display name configured in Microsoft 365.
When an agent tries to send to a recipient outside the mailbox's Outgoing rules, its conversation shows a Recipient blocked card outside the collapsed tool activity. Choose Open Email settings to open that agent's mailbox rules directly; make the change and use Save changes before asking the agent to retry. The card does not change policy by itself, and only workspace members who can manage the channel can save new rules.
Copy people on an email
Ask the agent to send one email to a primary recipient and copy others with CC. For example: “Email the report to Michael and CC Theodore.” CC addresses are visible to everyone on the email. You can include up to 20 explicit CC recipients.
Every explicit CC recipient must satisfy the sending mailbox's Outgoing rules. If any recipient is disallowed, the entire email is blocked; the agent does not silently omit them or send separate copies. Policy-required oversight copies remain in place. Approvals, where required by an existing policy, preserve the exact recipients and attachments.
A successful email also lets its explicit CC recipients respond when Accept replies from people this mailbox emails is enabled. Oversight-only copies do not grant this exception. A queued, failed or uncertain send does not qualify.
Block unwanted senders
Under Advanced → Blocked senders, add exact addresses or domains. Blocking takes precedence over Anyone, allowed addresses, and the reply exception. Blocked mail cannot start agent work. Remove an entry to unblock it.
Incoming email cards also offer Block sender in their actions menu to channel managers. The action applies only to the mailbox that received the message. It does not change the other mailbox settings or automatically stop work that has already started.
Review email from unknown senders
Where available, set Incoming to Anyone and turn on Review unknown senders first to hold mail from every sender that does not match an exact address or domain under Trusted senders. That visible list is the only source of quarantine bypass trust: previous conversations and addresses the agent emailed do not bypass review by themselves. A sender trusted from the inbox is added to the list and bypasses future review; choosing Deliver once does not make that sender trusted.
Held email appears under Needs review in the mailbox activity inspector. Its sender, subject, body, links, and attachment details remain hidden from the agent. The agent receives only a notice that one or more emails are waiting and can ask the team to review the inbox; that notice cannot use tools or inspect the held content.
A channel manager can choose Deliver once, Trust sender & deliver, or Reject. Delivering starts ordinary inbound work only after the decision. Trusting admits that exact sender on later messages, while rejecting keeps the content away from the agent. Changing incoming rules, blocked senders, the review setting, or trusted-sender rules before a decision invalidates the pending review instead of applying stale rules. Disconnecting the mailbox invalidates it too.
Advanced settings
Advanced contains blocked senders, the attachment toggle, the daily sending limit, and a separate retire/disconnect action. Reconnect a Gmail mailbox through the provider if authorization expires. Disconnecting stops synchronization and new sends while retaining message history. An email already being sent may finish; accepted email cannot be recalled.
A paused agent, spent AI budget, exhausted email limit, unavailable mailbox, or denied recipient blocks sending. Every outgoing email identifies that it was sent by an AI agent. Branding follows the workspace entitlement.
Email is external input
Incoming email enters the same persistent agent conversation used by other channels. Allowed senders can invoke the capabilities configured for that agent and its bounded shared context. An address match does not prove a sender is a workspace teammate. Gmail rules use From, not Reply-To; provider headers alone are not authenticated identity evidence. Managed d5s mail also passes domain and content checks.
With Review unknown senders first enabled, an unknown sender's content does not enter that conversation until a channel manager delivers it. The agent's review notice contains no sender or message metadata and grants no email access.
Email content cannot widen address rules, override a block, or change standing permissions. Automatic replies and common bulk, list, and loop headers are filtered unless the sender's From address explicitly matches the mailbox's saved Incoming rules. A match means those messages can start ordinary agent work; the successful-send reply exception alone does not opt automated mail in. For managed d5s mail, an explicitly allowed message may have a different Reply-To, but d5s keeps From as the correspondent and reply target instead of redirecting to that header. Replies and proactive messages still require the mailbox's Outgoing rules, and actual sends require the email tool.
Every member who can open the agent can inspect its retained email activity, including after a mailbox is disconnected. Legacy approval cards retain the exact draft and can be approved or rejected by authorized members; current policy and ownership are rechecked before delivery.
If work started by an incoming email pauses on an Ask-gated connector action, the agent replies in the same email thread with an ordinary link to the relevant turn in d5s. Email replies cannot approve or deny the action, and the link contains no approval secret. An authorized workspace member must sign in and decide on the existing d5s approval card; normal workspace and agent access still apply. The run remains paused until that decision or expiry, even if someone replies with words such as “approved.”
You can ask the agent whether an earlier email is awaiting approval or has been sent. When you message an agent with retained outgoing email activity, its context includes a compact outbox overview. The agent can check a specific approval or delivery without sending another email. An earlier “queued” response describes the state at that time; approval may have completed since then. “Approved” does not itself mean sent, and “sent” means the email provider accepted it, not that it arrived in the recipient's inbox. An uncertain delivery must not be retried automatically.
Attachments are fetched only when needed
Incoming messages can include TXT, Markdown, CSV, JSON, PDF, DOCX, XLSX, PNG, and JPEG files. The email card shows retained file metadata and whether each retained file is available, read, skipped, or failed. Archives, executables, macro-enabled Office files, unknown types, and unsafe or malformed files are skipped with a visible reason. Inline message resources are ignored rather than presented as files.
d5s retains a reference first and downloads a supported attachment only when the agent needs it. The agent can use retained attachments on later runs while the connected mailbox and current attachment permissions still allow access. For d5s addresses, unread attachment references expire when the original message is removed after its 30-day retention period. Supported files already downloaded remain available under the agent's retained file controls. Email content remains untrusted and cannot change permissions or reply routing.
PDF and image downloads make the original file available without automatically extracting its contents. The agent chooses how to inspect it; visual inspection requires a supported vision model. For scanned or mixed PDFs, ask it to inspect relevant pages as well as any extracted text. Downloading a file does not mean every page has been read.
File count, size, expansion, page, image-dimension, and extracted-text limits apply. A supported file the agent reads remains available for later work. Extracted text is untrusted evidence.
The agent can attach files it created to a new email or an explicit reply. Ask it to attach the file so recipients can open it. A missing, oversized, or unreadable requested file blocks the email instead of silently sending only the text. When approval is required, it preserves the exact attachment bytes and metadata alongside the recipient, subject, and body; later file changes cannot alter what the reviewer approves.
Follow activity
The agent conversation records inbound processing and outgoing states such as received, processing, processed, sending, sent, blocked, rejected, failed, and uncertain. Full email activity remains available to everyone who retains access to the agent, including after the mailbox is disconnected.
For a mailbox-focused view, open Email in the agent's secondary Channels section. The activity inspector groups retained messages into threads, pins pending approvals and unknown-sender reviews, supports subject or address search, and lets you open the related conversation turn. It is an audit and triage view, not a separate agent conversation: delivered email and approval cards continue to appear inline in the main timeline.
Incoming-mail limits apply. Contact support if expected allowed mail is missing.
“Sent” means the mailbox provider accepted the send request; d5s does not claim recipient delivery. If the provider's final response is ambiguous, the message remains uncertain instead of being retried blindly and risking a duplicate.
Mailbox options
A d5s address is available where Create d5s address appears in setup. Connecting a dedicated Gmail mailbox is also supported. You do not need to change its domain or mail delivery settings.
Generic IMAP and SMTP mailboxes are not supported in this beta.
Hidden copies (BCC)
Ask the agent to BCC the exact email addresses you provide. BCC recipients receive the email without appearing in the visible To or CC fields. The agent does not infer hidden recipients from an earlier message.
When Accept replies from people this mailbox emails is enabled, a successfully sent BCC copy also permits that recipient to reply, subject to blocked-sender rules.
BCC follows the sending mailbox’s outgoing rules and approval requirements. One disallowed recipient blocks the whole send. A BCC address that also appears in To, CC, or a configured oversight copy must be resolved before sending, so a hidden recipient is never silently made visible. People authorized to inspect the agent’s email activity can see BCC recipients and review them before approving a send.
Open a managed email in d5s
Emails from a d5s-managed address use a compact AI-assistant signature with the agent’s avatar. Where branding is enabled, the footer offers two choices: Work with the agent’s team? Request access and Want d5s for your own team? Get started. Reply directly by email without registering whenever the mailbox’s incoming rules allow it; the first-contact guidance appears only when replies are permitted.
Sign in with the verified address that received the email. If your existing session has no recorded email verification, sign in again. A forwarded link does not give another account access. The recipient view includes only emails sent to your address, including explicit CC or BCC copies, and never exposes hidden recipients or the agent’s private activity.
- Already a member with access to the agent: choose Open … in d5s to enter the correct workspace.
- Invited to that workspace: accept the invitation to join, then open the agent. Invitation expiry, email matching, and seat requirements still apply.
- Colleague, not invited: choose Request access. The request page names the workspace and its organization, so you can confirm which team you are asking to join. Request workspace access when available. Workspace invitation managers review requests in Settings → Members and use the normal invitation flow. A request alone grants no access.
- External collaborator: choose Get started to register and follow normal onboarding for your own use of d5s. This does not request access to the sender’s workspace. You can keep replying by email without registering when the mailbox permits it.
Requests target one workspace. An existing organization member still needs access to that workspace; a newcomer joins through the normal organization invitation and seat checks. Other workspaces and private projects require separate access. Your email address or company domain does not automatically join you to the sender’s team.
Personal workspaces cannot be joined through an access request. If you already belong to a workspace but cannot open the agent’s private project, ask its administrator to share the project with you.