Admin guide: turning AI assistants and sending on or off
What the two workspace switches do, when to keep sending off, what happens when you turn one off, how to review connections and answer your team's questions.

On this page(11 sections)
If you are an owner or admin of a Koltrix workspace, you decide whether AI assistants can connect to your team's mail at all, and whether any of them may send. Two switches, a short list of connections, and an audit log are the whole control surface.
This guide is for the person holding those switches. It covers what each setting does, the order to turn things on, what happens when you turn something off, and how to answer the questions your team will ask.
What you control
| Control | Default | What it does |
|---|---|---|
| Assistants on or off for the workspace | On | Off means every connection stops working at once and no new ones can be made |
| Allow assistants to send email after you confirm | Off | Lets people opt in to sending when they connect. Turning it off blocks sending immediately |
| Connected apps list | Each person's connections | Shows who connected what, and lets connections be revoked |
| Audit log | Always recording | Connections, renewals, revocations, tool calls and sends, with tool names and counts, never mail content |
The settings live under Settings, then AI assistants in Koltrix. Labels in the app can change, and the docs carry the current names.
What an assistant is, to Koltrix
Before deciding, it helps to know exactly what you are permitting. An assistant such as Claude, ChatGPT or Cursor connects to Koltrix on behalf of one person, in one workspace, after that person approves it on a Koltrix page. It has that person's access to mailboxes and nothing beyond it, checked on every call. By default it can:
- Read: search and read mail, list mailboxes and labels.
- Organise: add and remove labels, archive, mark read or unread, star. All reversible.
- Draft: save drafts to the person's Drafts folder.
It cannot delete mail or forward it, because those tools do not exist. It does not download attachments. Least privilege for AI email agents explains why that shape is the safe one.
Koltrix's own AI, which sorts, summarizes and suggests replies in the app, is a separate thing. It never sends without a person clicking Send, and these switches do not govern it.
Decision 1: should assistants be on
For most teams, yes, with sending off. The benefits are real: faster triage, faster first drafts, easier searching. The risks are bounded by the tool set. Even so, there are good reasons for a workspace to keep assistants off:
- A regulated mailbox. If mail contains material you are obliged to keep out of third-party AI providers, off is the simple answer. The parts of mail an assistant reads are sent to its provider and handled under that provider's terms.
- A rollout that is not ready. You may want a pilot first.
- Contractual limits. Some customer agreements restrict where their messages go.
Turning assistants off is easy to reverse and takes effect straight away.
Decision 2: should sending be on
This is the weightier one. Start with the default, off. Turn it on only if someone has a concrete need and you have thought about who.
What turning it on does and does not do:
- It does not let anyone send by itself. Each person still has to opt in when they connect, with an unticked box, Also allow sending email, that only appears when you have enabled sending.
- It does not let an assistant send arbitrary text. The only sending tool sends a draft that already exists, and the server refuses unless the assistant names the real recipients and subject.
- It does not remove limits: at most 10 recipients per message, 20 sends a day per connection and 50 a day for the whole workspace through assistants, no Bcc and no attachments.
- It does not change what existing connections can do. Connections made before you turned it on cannot send until the person reconnects and ticks the box.
What it does is make it possible for an assistant to send a draft after showing the person the message and getting their explicit yes in the conversation. In apps that show interactive cards, the person presses a Send button on a draft card instead. Safe sending from Claude goes through all the gates, and MCP Apps cards covers the card version.
A reasonable policy for a small team:
| Role | Sending |
|---|---|
| Admin/owner | Opt in only if they want to, after using drafts for a while |
| Support agents | Off. Replies are commitments |
| Founders | Their choice, with the checklist below |
| Everyone else | Off |
Remember that sending is opt-in per person, so even with the workspace switch on, nobody is forced.
The order to turn things on
- Confirm assistants are on (they are by default) and sending is off.
- Let one or two people connect and use read, organize and draft for a week.
- Collect what worked, and the prompts that did it.
- Roll out to the team.
- Decide about sending separately, later, with evidence from your own use.
Treat sending as a second project, not part of the first.
What happens when you turn things off
| You turn off | Effect |
|---|---|
| Assistants for the workspace | Every connection stops working at once. New ones cannot be made until you turn it back on |
| Sending | The very next send is blocked, even for apps already allowed. Turn it back on and those apps can send again |
| One person's connection (revoke) | That connection stops working immediately. Others are unaffected |
| A person (removed or suspended) | Their connections stop working immediately |
Nothing is cached. Each call checks the state at the moment it happens, which is why changes take effect straight away. Existing drafts remain in Drafts; mail already sent stays sent.
Reviewing connections
Check the connected apps list on a schedule. Monthly is plenty. Look for:
- Apps you do not recognize.
- People who have left (they should be gone, since removal ends their access).
- Connections that can send. The list shows whether each one can, which tells you where your sending exposure is.
- Connections nobody uses. Unused ones lapse after 30 days of inactivity anyway.
Reviewing and revoking AI app connections has a fuller routine.
Using the audit log
The workspace audit log records each connection, token renewal, revocation and tool call, with the tool's name and none of your mail. Each send through an assistant is recorded as mcp.send, with the tool, the app, who sent it, the draft id, the number of recipients and their domains. The message text and full addresses are not logged, so the log is safe to share more widely than the mail itself.
Use it to answer three questions: who connected what and when, what did a given connection do, and how many assistant sends happened. Auditing what an AI assistant did in your mailbox walks through reading it.
Answers for your team
"Can it read the CEO's mailbox?" Only if the person who connected it can. An assistant has its owner's access and no more.
"Can it delete things?" No. There is no delete tool, and no forward tool.
"Can it email customers on its own?" Not by default. If you enable sending, it can send a draft only after showing the message and getting an explicit yes, and only for people who opted in.
"Where does our mail go?" The parts an assistant reads go to its provider, such as Anthropic for Claude or OpenAI for ChatGPT, under that provider's terms. Koltrix does not receive the person's conversation with the assistant, only the tool calls it makes. What your AI provider sees is a good handout.
"What if an email tries to trick it?" Koltrix marks email content in tool results as untrusted, third-party text and tells the assistant to treat it as data. With sending off, the default, a fooled assistant can still only label, archive, mark and draft, all of which can be undone.
A one-page policy you can adapt
- Assistants are on. Sending is off.
- Each person connects their own account and reviews drafts before sending.
- Never connect an assistant to a mailbox containing material our contracts keep away from third parties.
- Ask an admin before enabling sending.
- Connections are reviewed monthly, and anything unused is revoked.
Key takeaways
- Admins hold two switches: assistants on or off for the workspace, and a separate sending switch that starts off.
- Turning sending on enables per-person opt-in and layered checks; it does not let anything send by itself.
- Changes take effect immediately because Koltrix checks on every call. Revoke connections one by one or switch everything off.
- Review connections monthly and use the audit log, which records tool names and counts rather than mail.
- For the overview, see koltrix.com/mcp.
Start with Koltrix
Your domain, one inbox, and an API that sends.
A team inbox where AI sorts and drafts (nothing is sent without your click), plus the transactional API and SMTP relay your product sends with. 7 days free, no card.


