Connecting an AI assistant to your inbox: a pre-flight checklist
Before you connect Claude, ChatGPT or another AI assistant to your email, run this checklist: account, permissions, sending, revocation, admin rules and logs.

On this page(12 sections)
- The checklist
- 1. Right account, right workspace
- 2. Permissions requested, and why
- 3. Can it send, forward, or delete?
- 4. Which mailboxes it can see
- 5. How to revoke it
- 6. Whether your admin allows it
- 7. What gets logged
- 8. Run a low-stakes test first
- After you connect: a monthly glance
- A printable version
- Key takeaways
Pilots run a checklist before every flight, not because they forget how to fly, but because the cost of skipping one item is too high. Connecting an AI assistant to your inbox deserves the same treatment: it takes two minutes, and the consent screen you click through grants real access to years of private conversations.
Here's a pre-flight checklist to run before you approve any AI connection to email, whether it's through MCP, a browser extension, or an app's built-in integration.
The checklist
- Right account, right workspace
- Permissions requested, and why each one
- Can it send, forward, or delete?
- Which mailboxes it can see
- How to revoke it
- Whether your admin allows it
- What gets logged
- A low-stakes test first
Each item is explained below, with what to look for and what should make you stop.
1. Right account, right workspace
Many people have several email identities: personal, work, a side project, an old job. The consent screen usually shows which account you're signed into, but it's easy to approve with the wrong one.
Check:
- The email address shown on the sign-in or consent page.
- If the service has multiple workspaces or organizations, which one you're granting access to.
Stop if: you're signed in as someone else, or you can't tell which workspace the connection applies to.
2. Permissions requested, and why
A well-built connection asks for specific permissions and shows them in plain words. Typical categories for email:
| Permission | What it allows | Reasonable for |
|---|---|---|
| Read | Search and read messages and threads | Summaries, finding things, answering questions |
| Organize | Apply labels, archive, mark read or unread | Inbox cleanup, sorting |
| Draft | Create draft replies in your Drafts folder | Writing help |
| Send | Send email as you | Rarely justified for an assistant |
| Delete | Permanently remove messages | Almost never justified |
Check: that every permission requested matches something you actually want the assistant to do.
Stop if: a summarizing tool asks to send, or the permission list is vague ("full access to your account") with no breakdown.
3. Can it send, forward, or delete?
This deserves its own line because it's the most important question. An assistant that can only read, organize and draft can make a mess at worst. An assistant that can send can email your customers, your bank, or a stranger, and it can be talked into doing so by text hidden inside an incoming email (prompt injection).
Check: the tool list or documentation for any send, forward, or permanent delete capability.
Prefer: connections where sending stays in your own email app, behind your own click. Koltrix's MCP server works this way: an assistant can read, organize, and draft, but it can't send.
4. Which mailboxes it can see
If you have access to shared mailboxes (support@, billing@, a founder's inbox you help manage), a connection might reach those too.
Check:
- Whether the assistant inherits all your mailbox access or can be limited.
- Whether it respects the same per-mailbox permissions the app enforces for you.
Stop if: you have access to sensitive mailboxes (HR, legal, finance) and you can't confirm whether the assistant will see them. Ask your admin first.
5. How to revoke it
Before you connect, know how you'll disconnect.
Check:
- Where connected apps are listed (often a settings page called something like "Connected apps" or "AI assistants").
- Whether revoking takes effect immediately.
- Whether revocation happens on the email service's side, not just inside the AI app. Removing a connector from the AI app doesn't always revoke the token on the service.
Good sign: a clear list showing each connected app, when it was connected, and when it was last used, with a revoke button next to it.
6. Whether your admin allows it
At work, connecting company email to an outside AI service may be covered by policy, even if the technology lets you do it.
Check:
- Your company's AI or acceptable use policy.
- Whether your workspace admin can turn AI connections on or off for everyone.
- Whether the AI provider's data terms fit your company's requirements.
Stop if: you're not sure. A two-line message to your admin is cheaper than an awkward conversation later.
7. What gets logged
When an assistant takes an action in your mailbox, you want a record of it.
Check:
- Whether the email service logs tool calls or API actions by connected apps.
- Whether you or your admin can see those logs.
- Whether the AI app keeps its own history of what it did.
Logs don't need to contain email content to be useful. "Applied label X to thread Y at 10:42" is enough to reconstruct what happened.
8. Run a low-stakes test first
Don't make your first request "clean up my whole inbox". Start small:
- Ask for a summary of today's unread mail and compare it with what you see.
- Ask it to find one specific thread you know exists.
- Ask it to draft a reply to a low-stakes email, then review the draft in your email app.
- Ask it to apply one label to one thread.
Watch what it does, check that the results match, and only then use it for more.
After you connect: a monthly glance
The checklist isn't only for day one. Connections outlive the reason you made them. Once a month, or whenever you change roles, take a quick look:
- Is the connection still used? If the last-used date is weeks ago, revoke it. You can always reconnect.
- Did the permissions change? Some apps request broader access after an update. Re-read the list if you're asked to approve again.
- Did your access change? If you were added to a sensitive shared mailbox since connecting, the assistant may now reach it too.
- Did anything surprising happen? A label you didn't apply or a draft you didn't ask for is worth investigating, even if it seems harmless.
A connection that you understand and still use is fine. A connection you forgot about is a door left open.
A printable version
AI inbox connection pre-flight
[ ] Correct account and workspace on the consent screen
[ ] Each permission matches a real need
[ ] No send / forward / permanent delete (or a strong reason for it)
[ ] I know which mailboxes it can reach
[ ] I know where to revoke it, on the email service side
[ ] My admin / policy allows it
[ ] Actions are logged somewhere I can see
[ ] First requests are small and reviewed
Key takeaways
- Read the consent screen: account, workspace, and each permission.
- Treat sending, forwarding, and deleting as the high-risk capabilities they are.
- Know which shared mailboxes an assistant can reach before you connect.
- Find the revoke button first, on the email service's side.
- Start with small, verifiable requests before trusting the connection with more.
Start with Koltrix
Your domain, one inbox, and an API that sends.
A team inbox where AI sorts and drafts (nothing is sent without your click), plus the transactional API and SMTP relay your product sends with. 7 days free, no card.


