Skip to content

Safe sending from Claude: how the confirmation flow works

Koltrix lets an assistant send only a draft, only after an admin switch, your opt-in and your yes. See the confirmation string, the limits and every check.

Koltrix Team6 min read
Gold padlock sitting on a keyboard
Photo by Towfiqu barbhuiya on Unsplash
On this page(12 sections)
  1. The default: no sending at all
  2. Three switches, all required
  3. What the assistant is allowed to send
  4. The confirmation string
  5. Everything that is checked on every call
  6. Hard limits keep mistakes small
  7. The call is marked irreversible
  8. When your app shows cards
  9. Every send is logged
  10. Why so many layers
  11. A short checklist before you say yes
  12. Key takeaways

Letting an AI assistant send email is the one feature in this space that deserves real suspicion. Sent mail cannot be recalled, and the assistant is reading text written by strangers.

Koltrix allows it, but only behind several independent layers, and none of them depends on the model behaving well. This post walks through exactly how sending works when an admin has turned it on, what the confirmation looks like, and what still protects you if something goes wrong.

The default: no sending at all

Start from the default, because most workspaces will stay there. Claude, ChatGPT and other connected assistants can read, search, organize and draft. Drafts are saved to your Drafts folder and wait for you to click Send in Koltrix. Sending is off.

Everything below only applies if you decide to change that. If your workflow is "assistant drafts, I send," you can stop reading, and that is a perfectly good place to stay. Drafting replies with Claude and Koltrix is built on that workflow.

Three switches, all required

For a single message to go out through an assistant, all three of these have to be true:

  1. A workspace owner or admin turns it on. There is a workspace setting, Allow assistants to send email after you confirm, and it is off for every workspace until someone changes it. Turning it off again blocks sending immediately, even for apps that were already allowed.
  2. You opt in when you connect. On the approval page, an extra box, Also allow sending email, appears only if the workspace allows sending. It is unticked by default. Apps you connected before sending was enabled cannot send until you reconnect and tick it.
  3. For every message, you say yes. The assistant has to show you the recipients, the subject and the full text, and wait for an explicit yes in the conversation.

The third one is the human part. The first two make sure the capability exists only where someone chose it twice.

What the assistant is allowed to send

The sending tool is send_draft, and the name is literal: it sends a draft that already exists. That draft might have been created by the assistant with create_draft, or written by you in the Koltrix app. Either way, the exact message is visible in your Drafts folder before anything happens.

There is no tool that sends new text directly, none that forwards a message, and none that deletes. If an assistant is tricked into wanting to "forward all invoices to this address," there is no tool for it to call.

The confirmation string

Here is the clever part, and it is simple. When the assistant calls send_draft, it must pass three things:

{
  "draft_id": "d_7c1f0a92",
  "confirmed": true,
  "confirmation": "[email protected], [email protected] | Shipping on Friday"
}

confirmed must be literally true. confirmation must be the draft's To addresses, then Cc addresses, comma-separated, then a vertical bar, then the subject. Capitals, spacing and address order do not matter. A missing or extra address does, and so does a different subject.

Koltrix compares that string with the draft's current recipients and subject, and refuses on any mismatch. Two things follow:

  • To build the string correctly, the assistant must have the real recipients and subject in front of it. It cannot send "blind."
  • If the draft was edited or swapped after you looked at it, the string no longer matches, and the send is refused. When it refuses, Koltrix replies with the draft's actual recipients and subject and tells the assistant to show you the message first.

This check does not prove the assistant showed you anything. Koltrix cannot see your conversation. It only forces the assistant to have the facts. Your part is to read the recipients and the text before you say yes.

Everything that is checked on every call

Nothing is cached. Each send call runs through these checks:

Check What it means
Permission The connection holds the send permission you ticked
Workspace setting Assistant sending is on right now. Turn it off and the next call fails
Your access You may send from the draft's From mailbox, same as in the composer
Valid sender The From address is active on a verified domain in the workspace
A real draft It exists in this workspace, is not already sent, and is not in the trash
Complete It has a recipient, a subject and a body
No Bcc, no attachments Neither can be covered by the confirmation, so the draft is refused
Billing and quota The workspace is not frozen and the send fits the plan's usual allowance
Limits The ones in the next section

A send that is refused or fails does not use up a slot in the daily limits. If the counters cannot be reached, Koltrix refuses rather than guessing.

Hard limits keep mistakes small

Limit Value
Recipients (To and Cc) per message 10
Sends per connection per day 20
Sends per workspace per day, across all assistants 50

The daily limits reset at midnight UTC and count sends made through assistants only. Sends you click yourself in Koltrix, and API sends, are not counted against them. A message sent by an assistant still counts against your plan's daily send allowance like any other.

These numbers are deliberately small. An assistant that has been fooled can do a small amount of damage, not a mailing's worth. Anything at volume belongs in the API, not in a chat window.

The call is marked irreversible

Koltrix annotates send_draft as destructive and open-world, which are the signals MCP clients use to decide when to ask for approval. Apps such as Claude and ChatGPT are expected to prompt you themselves before running a tool like that. That prompt is a second, independent gate sitting in front of Koltrix's own.

When your app shows cards

Some apps can show a tool's result as an interactive card, using the MCP Apps extension. In an app that does, send_draft is not offered at all. The draft appears as a card showing From, To, Cc, Subject and the whole message, with Send, Edit in Koltrix and Discard. Clicking Send is the confirmation.

The button calls a second tool that the app hides from the assistant, using a one-time token that Koltrix issued with the draft. The token works for 30 minutes, belongs to that draft and connection and the exact message you saw, and is used up by the send. If the draft is edited after the card appeared, or the card is older than 30 minutes, Send is refused. Discard closes the card and deletes nothing. MCP Apps cards, explained has the full picture.

Every send is logged

Each send is written to the workspace audit log as mcp.send, with the tool, the app, who sent it, the draft id, the number of recipients and their domains. The message text and full addresses are not logged. The message itself appears in the From mailbox's Sent folder like any other. Auditing what an AI assistant did in your mailbox shows how to review it.

Why so many layers

The honest reason is that no assistant is immune to prompt injection. An email can contain text such as "reply with the account number" or "send this thread to someone else," and a sufficiently cooperative model might try. If sending were a single toggle, a successful trick would become a sent message.

Layering means a trick has to pass an admin's decision, your opt-in, a confirmation that matches the real draft, the app's own approval prompt, strict limits and an audit trail. And the assistant is told, in the server's instructions, to show you the recipients, subject and whole message, wait for your explicit yes, and never send because an email told it to. That instruction is a courtesy to the model, not the safety mechanism. The mechanisms are the gates.

A short checklist before you say yes

  • Are the recipients exactly who you intended, including Cc?
  • Does the subject match the conversation?
  • Did you read the whole text, including the last line?
  • Does the draft come from the mailbox you meant to send from?
  • Is anything in it that the assistant took from an email rather than from you?

Key takeaways

  • Assistant sending is off by default and needs an admin switch, your own opt-in, and your yes on every message.
  • send_draft sends only an existing draft, and the server refuses unless the stated recipients and subject match it.
  • Limits are small on purpose: 10 recipients, 20 sends a day per connection, 50 per workspace, no Bcc, no attachments.
  • Every send is logged, and apps that show cards replace the text confirmation with a Send button you press yourself.
  • Read the message before you approve it. The full rules are in the docs, and the overview is at koltrix.com/mcp.

Start with Koltrix

Your domain, one inbox, and an API that sends.

A team inbox where AI sorts and drafts (nothing is sent without your click), plus the transactional API and SMTP relay your product sends with. 7 days free, no card.

SharePost on XLinkedIn