Home / Your mailbox

You connected an assistant to your mailbox. What did that give it?

Four steps, thirteen prompts, about twenty minutes. You paste them into your own session, against your own mailbox. Nothing is collected here, no account is needed, and at the end you have a written account of what your assistant can reach, what you meant to authorise, and the gap between the two.

Start here if you only do one thing. Open the assistant you have connected to your mail and paste the first prompt. It takes a minute and it changes the conversation, because almost nobody has seen the list before.

Why ask the agent rather than read a table

An assistant is unusually good at describing its own tool surface, and it is the only party in the room that can see all of it at once. It knows what it has already done in your mailbox, which no published table can. So these pages do not hand you a list to read. They hand you prompts that make your own assistant produce the list, for your deployment, and then give you something to check it against.

What comes back is a self report, and this site counts that as a claim rather than a measurement. An agent describing its own access is the cheapest evidence there is and the weakest: it stays a claim until a log held outside the agent agrees with it. That is why step one ends by asking it to mark every line it is inferring, and why the measured profile is published beside it.

The four layers this is really about

Between a mail platform and what a person meant, there are four layers. The top two are somebody else's and they only ever grow. The bottom two are yours, and they are usually unwritten.

Four layers between a mailbox and what somebody meantthe top two are the grant, the bottom two are the mandate, and the gap between them is the findingWhat the platform's scopes permitfixed, coarse, and the same for everybodyno scope can be bounded by label, correspondent, thread,topic or sensitivityWhat the connector surfacesthe tools, which grow as the product growsattached to the account rather than to this conversation,so it is the union of everything ever consentedWhat you actually wantthe job, and how your mailbox is organisedthe only layer that knows your unread set is a task list,and the only one nobody has written downWhat your organisation requiresand what the law requires of youother people's correspondence is in there, and you werenot given authority to pass it onThe gap between the top two and the bottom two is the delta, and nobody writes it: it is derivedfrom the two sides and recomputed when either of them moves.An Agent Behaviour Policy is the document that puts all four on one page for one agent in one deployment.
The top two layers are somebody else's and they only ever grow. The bottom two are yours and they are usually unwritten, which is why the gap is invisible until somebody writes them down.
LayerWho owns itWhat it does here
What the platform's scopes permitthe mail platformFixed and coarse. No scope can be bounded by label, correspondent, thread, topic or sensitivity, so every finer distinction you want has to be invented above the interface.
What the connector surfacesthe assistant's vendorThe tools you can actually reach, which is usually fewer than the scopes permit and grows as the product does. It attaches to your account rather than to one conversation, so what you consented to once applies in every session that has it attached.
What you wantyouThe job, plus the way your mailbox is organised. The only layer that knows your unread set is a task list rather than a backlog.
What your organisation requiresyour organisation, and the lawMost of a mailbox was written by other people. A grant you hold over their material is not a grant you may pass on.

What the published profile says about this shape

This site holds a measured profile for one common version of this: Claude with the Gmail connector enabled. It reaches 6 of the 23 capability primitives, through 22 tools named in the directory listing. Against a starting mandate written to be argued with, 5 of them are excess and 4 of those have nothing real in the way.

Your deployment is not that one. The point of the walkthrough is to produce yours.

Step 1: What it can already do

Ask your own assistant to enumerate its mailbox tools, what each one reaches, and which of them you could undo.

about five minutes

Step 2: What you actually asked for

Have it draft a mandate over its own tools, in three lists, and correct the draft. The correction is the whole exercise.

about five minutes

Step 3: Write the behaviour policy

Turn the gap between the two into a document you can keep, from four lines to a full Agent Behaviour Policy.

about five minutes

Step 4: What a prompt cannot do

What you have written down is an expectation rather than a control. Why it is still worth writing, and what would actually bound it.

about five minutes

What you will have at the end

Nothing on this site is an assessment, an audit, a certification or a security review of any named product. These pages describe published deployment shapes and give you prompts to run against your own. Every capability claim here carries a source, a date and whether it was measured or read.
Where the numbers on this page come from. The published profile for anthropic/gmail-connector/default, which this site did not measure: it was contributed by riskmandate.ai, read from the two vendors' own pages and measured in one session on 16 September 2026. 4 of 6 rows were seen on the thing itself and the rest were read from documentation. The evidence tier on every row is the contributor's and this site did not raise it. The rows, the profile as JSON, the contributed bytes.

The four objects an ABP is made of · The barrier · The worked examples · This shape, rendered live from a vault by riskmandate.ai