Skip to content

Keeping confidential email out of the AI loop

A checklist for keeping sensitive email away from AI tools: identify confidential categories, separate mailboxes, control connections and set a team policy.

Koltrix Team4 min read
Brass skeleton keys
Photo by Jason D on Unsplash
On this page(9 sections)
  1. Step 1: Name your confidential categories
  2. Step 2: Route sensitive mail to separate mailboxes
  3. Step 3: Check what each AI tool can reach
  4. Step 4: Watch the personal-access loophole
  5. Step 5: Set a short team policy
  6. Step 6: Handle credentials specially
  7. Step 7: Review twice a year
  8. What not to worry about
  9. Bottom line

Most email is fine for an AI assistant to read: support questions, vendor updates, meeting logistics. Some isn't. An employee's medical leave, a draft acquisition term sheet, a customer's security incident report: these deserve a narrower circle than "whatever tools are connected to the inbox."

The goal isn't to keep AI out of email altogether. It's to make sure the sensitive minority of mail doesn't flow into AI tools by default, just because it happened to arrive in a connected mailbox. This checklist walks through how to do that for a small team.

Step 1: Name your confidential categories

You can't protect what you haven't defined. Sit down with whoever handles HR, finance and legal matters (in a small company, that may be one or two founders) and list the kinds of email that need extra care.

Common categories:

  • HR and personnel: performance issues, compensation, health or leave details, disciplinary matters, hiring decisions about specific candidates
  • Legal: disputes, contracts under negotiation, advice from lawyers, anything subject to confidentiality obligations
  • Credentials and secrets: password reset links, API keys, recovery codes, anything that grants access
  • Health information: for teams that receive it from employees or customers
  • Corporate transactions: fundraising terms, acquisition discussions, board materials
  • Security incidents: vulnerability reports, breach investigations
  • Customer-confidential data: information a customer shared under an NDA or contract clause

Write the list down. Two lines per category is plenty: what it is, and an example.

Step 2: Route sensitive mail to separate mailboxes

The most reliable control is structural. If confidential mail lands in a mailbox that AI tools aren't connected to, it never gets processed in the first place. Relying on people to remember not to ask the assistant about certain threads is much weaker.

Practical setup:

  • Create role addresses for sensitive functions, for example people@ for HR matters, legal@ for legal correspondence, security@ for vulnerability reports
  • Give access only to the people who need it
  • Don't connect AI tools or assistants to those mailboxes
  • Ask external parties (lawyers, auditors, recruiters) to use those addresses

Per-mailbox permissions make this straightforward. In Koltrix, shared mailboxes have per-mailbox permissions, so a people@ mailbox can be visible to a founder and nobody else, while support@ is open to the whole team.

Step 3: Check what each AI tool can reach

AI tools reach email in different ways. Make a list of every one in use:

Tool How it accesses email Which mailboxes Who connected it
Built-in AI in the email platform Native Depends on settings Admin
Connected AI assistant Authorized connection Whatever the user can see Individual user
Browser extension Reads the page Whatever is on screen Individual user
Chatbot used by pasting text Manual copy-paste Whatever someone pastes Individual user

The last two rows are easy to forget. A browser extension with permission to read web pages can see whatever email is open. And pasting a sensitive thread into a general chatbot sends it outside your controls entirely.

For each tool, check:

  • Does it respect mailbox permissions, seeing only what the user can see?
  • Can admins disable it for the whole workspace or for specific mailboxes?
  • Can it send or forward email, or only read and draft?
  • Is there a log of what it accessed?

Step 4: Watch the personal-access loophole

A connected AI assistant usually sees what the connecting user can see. That means if a founder with access to people@ connects an assistant, the assistant may be able to read HR mail too.

Options to close this:

  • People with access to sensitive mailboxes use a separate account for those mailboxes, without AI connections
  • Or they avoid connecting general-purpose assistants to their main account
  • Or the tool lets them exclude specific mailboxes from the connection

Pick whichever fits your tools, and make it an explicit decision rather than an accident.

Step 5: Set a short team policy

Write a policy people can remember. Five rules is enough:

AI and confidential email – team policy

1. HR, legal, security, fundraising and credential emails go to their
   dedicated mailboxes, not personal or shared ones.
2. AI tools are not connected to those mailboxes.
3. Don't paste confidential email into any chatbot or AI tool.
4. If confidential mail arrives in a general mailbox, move or forward
   it to the right dedicated mailbox and tell the sender which address
   to use next time.
5. Unsure? Treat it as confidential and ask [name].

Rule 4 matters because senders won't always use the right address. A candidate replies to the recruiter's personal email; a lawyer copies the general inbox. Moving those messages promptly limits how long they sit in a connected mailbox.

Step 6: Handle credentials specially

Password reset links and one-time codes are a category of their own. They're often short-lived but powerful, and an AI tool summarizing "everything that arrived overnight" might include them in its output.

  • Send account-recovery emails for critical services to an address without AI connections
  • Delete reset emails after use
  • Never share API keys or recovery codes over email in the first place; use a password manager

Step 7: Review twice a year

  • Is the list of confidential categories still accurate?
  • Have new AI tools been connected since the last review?
  • Do the right people, and only the right people, have access to sensitive mailboxes?
  • Has anyone left who still has access?

What not to worry about

Not everything needs this treatment. Routine customer questions, vendor notifications, newsletters and scheduling mail can generally go through AI tools without concern, assuming the tools themselves meet your privacy standards. Over-classifying everything as confidential leads to people ignoring the policy.

Bottom line

Define your confidential categories, give them dedicated mailboxes with narrow access, and keep AI tools disconnected from those mailboxes. Inventory every way AI reaches your email, including browser extensions and copy-paste, and close the loophole where a person with sensitive access connects an assistant to everything. A five-rule policy and a twice-yearly review keep it working.

Start with Koltrix

Your domain, one inbox, and an API that sends.

A team inbox where AI sorts and drafts (nothing is sent without your click), plus the transactional API and SMTP relay your product sends with. 7 days free, no card.

SharePost on XLinkedIn