Pimp My IDE / garage dispatch
Back to garage
October 3, 2026 | agents / outbound email

Do not bolt send onto draft.

An agent that can write an email is not ready to send one. Recipient scope, sender identity, purpose, volume, approval, and the stop route belong in the control path.

Drafting turns words into a candidate. Sending turns a candidate into an external act. Put an ignition lock between them.
Outbound ignitionReview detent
Writing authority is not sending authority.The key stops at review until the recipient set, identity, purpose, limit, approval, and opt-out route are recorded.

A send API is a loaded tool.

The Gmail API makes the mechanical path short. A program creates a MIME message, encodes it, and calls messages.send. It can also create a draft and call drafts.send later.[1] That second path exposes the missing control point. Draft and send are different operations.

Agent permissions often separate reading, writing, shell commands, and network access. Claude Code documents fine-grained rules and asks for approval before many actions in manual mode.[2] Outbound email needs the same treatment. A mailbox token should not collapse composition, recipient selection, approval, and delivery into one tool call.

The send button needs its own authority, budget, and receipt.

Identity has to survive automation.

Google requires all senders to use SPF or DKIM for mail to personal Gmail accounts. Bulk senders need SPF, DKIM, and DMARC. Google also recommends sending only to people who want the messages and giving them an easy way to unsubscribe.[3]

Authentication proves that a domain authorized the message. It does not prove that the recipient expected it, that the claim is accurate, or that a person approved this batch. Keep those questions separate. Save the mailbox, authenticated domain, approving person, and exact draft with the send record.

Automation does not outsource responsibility.

The FTC says the CAN-SPAM Act covers commercial messages, including business-to-business mail. Its guidance requires accurate headers and subject lines, a valid postal address, a clear opt-out route, and prompt handling of opt-out requests. It also says a company cannot contract away responsibility when another company sends mail on its behalf.[4]

An agent is not a legal shield. It is another sender in the chain. If it finds recipients, writes claims, and sends at machine speed, the operator still owns the purpose, identity, suppression list, and response path.

Build a bounded outbound lane.

  1. Default the agent to drafts. Keep send permission absent.
  2. Define the recipient source and exclusion list before generation.
  3. Pin the sender mailbox, authenticated domain, purpose, and subject rule.
  4. Set a small batch ceiling. Review one rendered sample and the final recipient count.
  5. Require approval for each batch, not once for the lifetime of the tool.
  6. Record delivery results, replies, opt-outs, bounces, and the person who owns follow-up.

The goal is not slower email. The goal is a clear boundary between generated language and borrowed identity.

Interactive makeover / outbound ignition rack

Hold the key at review.

Traditional purpose replaced: one tool that drafts and sends. Better version: choose an authority mode, set a batch limit, close each review interlock, and copy a manifest for the person who owns the send.

Ignition controls

This page drafts a control record. It has no mailbox access and cannot send email.

Agent authority
5 recipients
1 / single review25 / hard ceiling
Review interlocks
Generated review manifest

See what is still open

The rail shows selected review sections. It does not test a list, mailbox, domain, message, or suppression system.

Outbound review bus0 of 4 sections selected
Review structure is open.Select the sections the sender must complete. Sending remains outside this page.
All four selections mean the manifest structure is ready. Required values still need evidence and approval. This control never grants sending authority.

Sources read

Source log and evidence boundary
  1. Google for Developers, "Create and send email messages", read October 3, 2026. It supports the distinction between direct messages.send and draft-based drafts.send, plus the MIME and base64URL message path.
  2. Claude Code Docs, "Configure permissions", read October 3, 2026. It supports the description of fine-grained tool permissions, manual approval, and stored allow or deny rules. The outbound manifest is our design, not a Claude Code feature.
  3. Google Gmail Help, "Email sender guidelines", read October 3, 2026. It supports the authentication requirements, opt-in guidance, and unsubscribe guidance described above.
  4. Federal Trade Commission, "CAN-SPAM Act: A Compliance Guide for Business", updated July 22, 2025 and read October 3, 2026. It supports the commercial-email requirements and the statement that businesses cannot contract away compliance responsibility. This article is an operating pattern, not legal advice.
  5. Hacker News discussion, "An AI agent emailed researchers for help. It told us why", item 49942865, read October 3, 2026. The discussion triggered this editorial angle. The linked Science page returned an access challenge during this run, so no claim here depends on its article text.

Evidence boundary. The rack teaches a review pattern. It does not connect to an email provider, check recipient consent, classify a message under a law, verify SPF, DKIM, or DMARC, process opt-outs, or retain delivery evidence.