Skip to content
Koltrix

MCP security

How Koltrix keeps an AI assistant on a short leash.

An assistant connected to your mail should be able to help without being able to hurt. Here is exactly what each permission allows, what always needs your approval, how sending works when an admin allows it, and the limits that are enforced on our side on every call.

What each permission allows

You see each permission in plain words on the approval page. The connection belongs to you, in one workspace.

What each Koltrix MCP permission allows an AI assistant to do
PermissionThe assistant canIt cannotAsked forWhat needs your approvalUndo
Readmail.readSearch and read mail in the mailboxes you can open; list mailboxes and labels; summarise the inbox.Read a mailbox you have no access to, download attachments, or change anything.By defaultYou approve it once, on the approval page when you connect.Nothing to undo: it only reads.
Organisemail.organizeAdd and remove labels, archive, mark read or unread, and star.Delete mail, empty the trash, or forward anything.By defaultYou approve it once when you connect. Your assistant app may also ask before it runs a tool.Yes. Every change can be reversed in Koltrix.
Draftmail.draftSave a message to your Drafts folder, new or as a reply, and give you a link to it.Send the draft. On its own this permission cannot send anything.By defaultYou approve it once. Every draft waits in Drafts until you act on it.The draft is a draft: edit it or leave it in Koltrix.
Sendmail.sendSend a draft that already exists, after showing you the message and getting your yes.Send new text directly, send to more than 10 recipients, use Bcc, send attachments, or forward.Never by defaultAn owner or admin turns it on, you tick Also allow sending email when you connect, and you say yes to every message.No. A send goes out immediately, with no undo window.

No permission unlocks these

  • Forward a message
  • Delete mail or empty the trash
  • Send text that is not in a draft you could open first
  • Send with Bcc recipients or attachments
  • Read a mailbox you cannot open yourself
  • See your conversation with the assistant

How safe sending works

Sending is a separate, opt-in capability that is off by default. It takes three things before a single message can go, and every message needs your yes.

  1. An admin allows it

    A workspace owner or admin turns on Allow assistants to send email after you confirm. It is off for every workspace until then.

  2. You opt in when you connect

    On the approval page, tick Also allow sending email. The box is unticked by default and only appears if the workspace allows sending.

  3. You say yes to each message

    The assistant shows the recipients, the subject and the whole text. Nothing is sent until you say yes in the conversation, or press Send on the draft card.

In an app that shows text results

Claude Code, and any app that does not draw cards.

  1. A draft exists

    The assistant saves the message with create_draft, or you wrote it in Koltrix. It is a real draft you can open.

    create_draft
  2. You read it and say yes

    The assistant shows the recipients, subject and full text and waits for an explicit yes in the chat.

    your yes
  3. The confirmation line must match

    send_draft needs confirmed set to true and a line with every To and Cc address, a bar, then the subject. A mismatch is refused.

    [email protected] | Subject
  4. The limits are checked

    10 recipients at most, 20 sends a day per connection, 50 a day per workspace, no Bcc, no attachments, one send per draft.

    10 / 20 / 50
  5. It goes, and is logged

    The message is queued at once and shows in Sent. The audit log records the tool, the app, the draft and how many recipients, never the text.

    Sent

In an app that shows cards

The assistant has no send tool here. You press Send on the draft card, which is why an app that supports cards but did not draw one cannot send from that chat.

  1. The draft card appears

    create_draft returns a card with From, To, Cc, Subject and the whole message. send_draft is not offered in this app.

    create_draft
  2. You press Send

    The click is the confirmation. The button calls a tool the app hides from the assistant, with a one-time token that belongs to that draft exactly as shown.

    Send
  3. The same limits apply

    The token works for 30 minutes and once. If the draft was edited after the card appeared, Send is refused. Every other check still runs.

    30 min, once
  4. It goes, and is logged

    The card shows Sending, then Sent with a link to your Sent folder.

    Sent
  • 10recipients at most on a message, To and Cc together
  • 20sends a day per connection, resetting at midnight UTC
  • 50sends a day per workspace, across every assistant
  • NoBcc recipients or attachments: such drafts are sent from Koltrix, not by an assistant

Controls enforced on our side

Anyone can send you an email, and an email can contain text written to fool an AI assistant. So Koltrix does not rely on the assistant behaving: the limits are enforced on every call.

Your access, no more

An assistant sees only the mailboxes you can open in Koltrix, checked on every call.

You approve, you revoke

See every connected app under Connect AI apps in the Koltrix sidebar and cut one off. It stops working immediately.

Admins hold the switch

Owners and admins can turn assistants off for the whole workspace, and sending is a second switch that starts off.

Nothing deleted, nothing forwarded

There is no tool that deletes mail or forwards it. Labels, archive, read state, stars and drafts can all be undone.

Hard limits on sending

At most 10 recipients a message, 20 sends a day per connection and 50 a day per workspace through assistants. No Bcc, no attachments.

Everything is logged

Connections, revocations and tool calls are recorded in the workspace audit log with the tool name, never your mail.

Email is untrusted text

Koltrix marks email content in its tool results as untrusted, third-party text, wrapped in markers with a notice, so an assistant is told not to treat it as instructions. This is a layer, not a guarantee: no assistant is immune to prompt injection today.

That is why the strongest controls do not depend on the assistant at all. With sending off, which is the default, even a fooled assistant has no way to send, forward or delete anything. With sending on, the admin switch, your opt-in, the confirmation, the recipient and daily limits and the app's own approval all still apply.

Sign-in, tokens and the audit log

Behind the scenes this is standard OAuth 2.1, so it works with any compliant client without configuration. Apps register themselves automatically and must use PKCE.

  • An access token lasts an hour and renews itself with a refresh token for up to 30 days of inactivity.
  • Tokens are tied to you, the workspace, the app and the permissions you approved. Koltrix stores only hashes of them.
  • Each connection, token renewal, revocation and tool call is recorded in the workspace audit log with the tool's name and none of your mail.
  • Each connection has its own request limit, so a runaway assistant cannot overload your account.

What leaves Koltrix

When you ask about your mail, the parts of it the assistant reads are sent to that assistant's provider, Anthropic for Claude and OpenAI for ChatGPT, and handled under their terms. Koltrix sends only what a tool call asks for and does not receive your conversations with the assistant, only the tool calls it makes.

Questions about security and sending

Can an AI assistant send email from my Koltrix account without asking me?

No. Sending is off by default. When an admin allows it and you opt in, the assistant must show you the recipients, subject and full message and get your yes first, or you press Send on the draft card yourself. It can only send a draft that already exists, to at most 10 recipients, with no Bcc and no attachments.

What are the daily sending limits?

20 sends a day per connection and 50 a day per workspace across all assistants. The counts reset at midnight UTC and cover only sends made through assistants; sends you click in Koltrix and API sends do not count against them.

What happens if an email tries to trick the assistant?

Email text is fenced and labelled as untrusted in every result. With sending off, a fooled assistant still has no way to send, forward or delete. With sending on, the confirmation, the limits and the draft you can open in Koltrix before it goes all still apply.

Can an admin turn all of this off?

Yes. Owners and admins can turn assistants off for the whole workspace under Connect AI apps in the Koltrix sidebar, which cuts every connection at once. A second switch there controls sending, is off by default and blocks sending the moment it is turned off.

Is the send action reversible?

No. A send goes out immediately, with no undo window, and appears in the From mailbox's Sent folder. Read the recipients and the text before you say yes.

Does Koltrix log what an assistant does?

Yes. Every connection, revocation and tool call is recorded in the workspace audit log with the tool's name and none of your mail. Each send is recorded with the app, the draft, the number of recipients and their domains, not the text or full addresses.

Go deeper

Guides from the blog

Also in this guide

Related on koltrix.com

Try it on your own mail.

Add your domain, connect your assistant and ask what needs a reply. Every plan starts with a free trial, no card.