🏠 All tools

← Working With AIEspaΓ±ol

Worked Example: Letting an AI Run Your Inbox

One ordinary delegation, done two ways β€” and why only the setup changed the outcome.

Here's a delegation millions of people are starting to make: handing a week of email to an AI assistant. It's a perfect small case, because the very same task β€” done one way β€” is a quiet disaster, and done another way is pure leverage. Nothing about the AI changes between the two. Only the setup does.

The naive version

The setup: Going on vacation, you connect an AI assistant to your whole email account and tell it: "Keep my inbox under control and reply to anything routine while I'm away." Then you close the laptop.

It demos beautifully for the first day. Then, on the cases a quick test never shows:

It sent a confident, wrong reply to an important client

A client emailed a question it judged "routine." It wrote a fluent, professional answer β€” and agreed to a deadline you'd never have accepted. It sounded completely sure.

The missing piece: fluency isn't correctness, and sending to other people should have needed your yes. It optimized "reply to routine," not what you'd actually want said.

It "tidied up" threads you needed

To keep the inbox "under control," it archived and deleted long threads β€” including one with attachments you were relying on for a project.

The missing piece: it acted on your literal words, not your intent β€” and on things that weren't easy to undo.

It confirmed a paid renewal

A "confirm to continue your subscription" email looked routine, so it replied "yes" β€” committing you to a charge you'd meant to cancel.

The missing piece: money and commitments are exactly what to gate, never auto-handle.

You didn't find out for four days

It all looked handled, so nobody checked. The wrong promises and deletions sat there compounding.

The missing piece: convenience lulled the check away β€” there was no review and no log being read.

The same week, set up wisely

Same assistant, same inbox, same goal. The only changes are in how it was handed the task β€” drawn straight from the three habits.

Narrow access, not the whole account

You connect it read-only, or scoped to a single "scheduling" label β€” and let it draft, not send. (Before You Give an AI the Keys.) Now the worst it can do is propose.

The intent and the limits, said out loud

Not "handle routine," but: "Draft replies only to meeting-scheduling emails. Never agree to a deadline, never spend or confirm anything, never delete, never reply to clients β€” flag those for me." The gap it can fall through shrinks to almost nothing.

A gate on anything that leaves or can't be undone

Nothing sends, deletes, or confirms without your explicit yes. (When You Let an AI Do It For You.) It prepares; you decide.

Small, supervised, and actually checked

You skim its drafts once a day β€” five minutes β€” before anything goes out. It earns a little more slack only on the harmless stuff.

The result: you come back to an inbox that's triaged, scheduling replies drafted and waiting, the tricky ones flagged β€” and not one wrong promise, deletion, or charge was possible. Same leverage. None of the disaster.

If something slips anyway

Even set up well, an agent can surprise you. That's not failure β€” it's why the recovery steps exist: stop it, see what it did, undo what's reversible, contain the rest, tell anyone affected, and tighten the gap.

The takeaway

Read the two versions back to back and the lesson is hard to miss: the AI was identical. What made one a mess and the other a genuine help was entirely how it was set up and gated β€” narrow access, a clear intent, a gate on the irreversible, and a daily look. That's the whole skill of working with AI that acts. The leverage is real; you just keep your hand on the wheel.

Free and public domain (CC0) β€” copy it, translate it, share it. No accounts, no tracking; it runs entirely in your browser. A worked illustration, not technical or legal advice.

Last reviewed: June 2026. This is general information that can age β€” verify time-sensitive specifics (laws, numbers, programs, app menus) against current official sources.