Your access, no more
An assistant sees only the mailboxes you can open in Koltrix, checked on every call.
MCP security
An assistant connected to your mail should be able to help without being able to hurt. Here is exactly what each permission allows, what always needs your approval, how sending works when an admin allows it, and the limits that are enforced on our side on every call.
You see each permission in plain words on the approval page. The connection belongs to you, in one workspace.
| Permission | The assistant can | It cannot | Asked for | What needs your approval | Undo |
|---|---|---|---|---|---|
| Readmail.read | Search and read mail in the mailboxes you can open; list mailboxes and labels; summarise the inbox. | Read a mailbox you have no access to, download attachments, or change anything. | By default | You approve it once, on the approval page when you connect. | Nothing to undo: it only reads. |
| Organisemail.organize | Add and remove labels, archive, mark read or unread, and star. | Delete mail, empty the trash, or forward anything. | By default | You approve it once when you connect. Your assistant app may also ask before it runs a tool. | Yes. Every change can be reversed in Koltrix. |
| Draftmail.draft | Save a message to your Drafts folder, new or as a reply, and give you a link to it. | Send the draft. On its own this permission cannot send anything. | By default | You approve it once. Every draft waits in Drafts until you act on it. | The draft is a draft: edit it or leave it in Koltrix. |
| Sendmail.send | Send a draft that already exists, after showing you the message and getting your yes. | Send new text directly, send to more than 10 recipients, use Bcc, send attachments, or forward. | Never by default | An owner or admin turns it on, you tick Also allow sending email when you connect, and you say yes to every message. | No. A send goes out immediately, with no undo window. |
Sending is a separate, opt-in capability that is off by default. It takes three things before a single message can go, and every message needs your yes.
A workspace owner or admin turns on Allow assistants to send email after you confirm. It is off for every workspace until then.
On the approval page, tick Also allow sending email. The box is unticked by default and only appears if the workspace allows sending.
The assistant shows the recipients, the subject and the whole text. Nothing is sent until you say yes in the conversation, or press Send on the draft card.
Claude Code, and any app that does not draw cards.
The assistant saves the message with create_draft, or you wrote it in Koltrix. It is a real draft you can open.
create_draftThe assistant shows the recipients, subject and full text and waits for an explicit yes in the chat.
your yessend_draft needs confirmed set to true and a line with every To and Cc address, a bar, then the subject. A mismatch is refused.
[email protected] | Subject10 recipients at most, 20 sends a day per connection, 50 a day per workspace, no Bcc, no attachments, one send per draft.
10 / 20 / 50The message is queued at once and shows in Sent. The audit log records the tool, the app, the draft and how many recipients, never the text.
SentThe assistant has no send tool here. You press Send on the draft card, which is why an app that supports cards but did not draw one cannot send from that chat.
create_draft returns a card with From, To, Cc, Subject and the whole message. send_draft is not offered in this app.
create_draftThe click is the confirmation. The button calls a tool the app hides from the assistant, with a one-time token that belongs to that draft exactly as shown.
SendThe token works for 30 minutes and once. If the draft was edited after the card appeared, Send is refused. Every other check still runs.
30 min, onceThe card shows Sending, then Sent with a link to your Sent folder.
SentAnyone can send you an email, and an email can contain text written to fool an AI assistant. So Koltrix does not rely on the assistant behaving: the limits are enforced on every call.
An assistant sees only the mailboxes you can open in Koltrix, checked on every call.
See every connected app under Connect AI apps in the Koltrix sidebar and cut one off. It stops working immediately.
Owners and admins can turn assistants off for the whole workspace, and sending is a second switch that starts off.
There is no tool that deletes mail or forwards it. Labels, archive, read state, stars and drafts can all be undone.
At most 10 recipients a message, 20 sends a day per connection and 50 a day per workspace through assistants. No Bcc, no attachments.
Connections, revocations and tool calls are recorded in the workspace audit log with the tool name, never your mail.
Koltrix marks email content in its tool results as untrusted, third-party text, wrapped in markers with a notice, so an assistant is told not to treat it as instructions. This is a layer, not a guarantee: no assistant is immune to prompt injection today.
That is why the strongest controls do not depend on the assistant at all. With sending off, which is the default, even a fooled assistant has no way to send, forward or delete anything. With sending on, the admin switch, your opt-in, the confirmation, the recipient and daily limits and the app's own approval all still apply.
Behind the scenes this is standard OAuth 2.1, so it works with any compliant client without configuration. Apps register themselves automatically and must use PKCE.
When you ask about your mail, the parts of it the assistant reads are sent to that assistant's provider, Anthropic for Claude and OpenAI for ChatGPT, and handled under their terms. Koltrix sends only what a tool call asks for and does not receive your conversations with the assistant, only the tool calls it makes.
No. Sending is off by default. When an admin allows it and you opt in, the assistant must show you the recipients, subject and full message and get your yes first, or you press Send on the draft card yourself. It can only send a draft that already exists, to at most 10 recipients, with no Bcc and no attachments.
20 sends a day per connection and 50 a day per workspace across all assistants. The counts reset at midnight UTC and cover only sends made through assistants; sends you click in Koltrix and API sends do not count against them.
Email text is fenced and labelled as untrusted in every result. With sending off, a fooled assistant still has no way to send, forward or delete. With sending on, the confirmation, the limits and the draft you can open in Koltrix before it goes all still apply.
Yes. Owners and admins can turn assistants off for the whole workspace under Connect AI apps in the Koltrix sidebar, which cuts every connection at once. A second switch there controls sending, is off by default and blocks sending the moment it is turned off.
No. A send goes out immediately, with no undo window, and appears in the From mailbox's Sent folder. Read the recipients and the text before you say yes.
Yes. Every connection, revocation and tool call is recorded in the workspace audit log with the tool's name and none of your mail. Each send is recorded with the app, the draft, the number of recipients and their domains, not the text or full addresses.
Go deeper
Also in this guide
Related on koltrix.com
Add your domain, connect your assistant and ask what needs a reply. Every plan starts with a free trial, no card.