A send API is a loaded tool.
The Gmail API makes the mechanical path short. A program creates a MIME message, encodes it, and calls messages.send. It can also create a draft and call drafts.send later.[1] That second path exposes the missing control point. Draft and send are different operations.
Agent permissions often separate reading, writing, shell commands, and network access. Claude Code documents fine-grained rules and asks for approval before many actions in manual mode.[2] Outbound email needs the same treatment. A mailbox token should not collapse composition, recipient selection, approval, and delivery into one tool call.
The send button needs its own authority, budget, and receipt.
Identity has to survive automation.
Google requires all senders to use SPF or DKIM for mail to personal Gmail accounts. Bulk senders need SPF, DKIM, and DMARC. Google also recommends sending only to people who want the messages and giving them an easy way to unsubscribe.[3]
Authentication proves that a domain authorized the message. It does not prove that the recipient expected it, that the claim is accurate, or that a person approved this batch. Keep those questions separate. Save the mailbox, authenticated domain, approving person, and exact draft with the send record.
Automation does not outsource responsibility.
The FTC says the CAN-SPAM Act covers commercial messages, including business-to-business mail. Its guidance requires accurate headers and subject lines, a valid postal address, a clear opt-out route, and prompt handling of opt-out requests. It also says a company cannot contract away responsibility when another company sends mail on its behalf.[4]
An agent is not a legal shield. It is another sender in the chain. If it finds recipients, writes claims, and sends at machine speed, the operator still owns the purpose, identity, suppression list, and response path.
Build a bounded outbound lane.
- Default the agent to drafts. Keep send permission absent.
- Define the recipient source and exclusion list before generation.
- Pin the sender mailbox, authenticated domain, purpose, and subject rule.
- Set a small batch ceiling. Review one rendered sample and the final recipient count.
- Require approval for each batch, not once for the lifetime of the tool.
- Record delivery results, replies, opt-outs, bounces, and the person who owns follow-up.
The goal is not slower email. The goal is a clear boundary between generated language and borrowed identity.