For teams giving AI agents mailboxes · agent comms authority

Illustrative capability walk-through — it shows how KYE Protocol governs agent-driven email over any agent-mailbox provider and does not imply a partnership or commercial relationship with any provider.

An agent can have a mailbox. Whether it may send is an authority decision.

Built for a team like yours. Agent-mailbox providers now hand your AI agents their own inboxes — real addresses that receive, read, draft and dispatch at machine speed, the same speed at which one wrong send becomes a regulator letter. The KYE Agent Comms Authority Profile sits over the mailbox, not inside it: drafting stays free, but at the moment of dispatch KYE checks who authorised this agent to send this message to this recipient — and holds external, bulk and financial-legal sends for a human. Every verdict seals a receipt you can replay, cutting a "why did the agent email that" reconstruction from days to minutes.

That held send, sealed HELD · EXTERNAL_RECIPIENT_APPROVAL_REQUIRED kye:evidence:a7c3… Replay & verify →
1 · The governed action set

Eleven mailbox actions. Each one an authority decision.

Your agent's mailbox life is a fixed set of consequential actions, and the profile binds every one of them to a canonical action class with a human-oversight tier — the same HITL ladder the EU AI Act Article 14 asks you to evidence, mapped once and enforced at the action boundary.

DRAFT_MESSAGEdrafting is free — no boundary crossing until sendauto in scope
READ_INBOX · SUBSCRIBEpurpose-scoped ingress, posture-trackeddelegated
SEND_MESSAGE · REPLY · FORWARD · ATTACH_FILEroutine, in-scope, known correspondentsdelegated in scope
REGISTER_MAILBOX · BIND_MAILBOX_TO_PRINCIPALevery mailbox binds to exactly one principal in one tenantone approver
EXTERNAL_RECIPIENT_SEND · BULK_SENDirreversible once delivered · fan-out blast radiushuman approval
FINANCIAL_OR_LEGAL_CONTENTescalation condition — content that commits your organisationtwo-person + legal

One governed approval covers a thousand-recipient batch — and the batch cannot leave without it. Admit, hold or refuse, each verdict packs an Evidence Pack and a Replay-Proof verifiable from public keys alone, the audit trail ISO/IEC 42001 clause 8 expects for autonomous operation.

2 · The honest boundary

KYE is not a mailbox provider — and never will be.

This is the authority layer over the inbox, not the inbox. KYE Protocol does not host mailboxes, store your agents' mail, or deliver a single message — the provider you choose keeps that job.

The profile ships a provider-agnostic connector contract: any agent-mailbox provider that can provision tenant-keyed mailboxes, keep drafts separate from dispatch, and defer dispatch until the governing decision returns ALLOW slots in as a swappable adapter. No provider lock-in at the authority layer, no partnership implied — you bring the mailbox, KYE brings the authority decision, and the seam between them is one deferred-dispatch call. See how delegated authority reaches the agent in the first place on the Authority Governance page.

3 · See it on your own flow

Seeing is believing. Bring one agent inbox.

In a 20-minute walk-through we take one real agent-comms flow — a customer reply, an outbound follow-up, a bulk notice — and show the send admitted, held or refused against the authority your organisation actually delegated, then hand you the sealed receipt to replay yourself. No credentials to share: the proof verifies against a public key set, the same runtime enforcement KYE Protocol uses to govern its own outbound mail.