AI EMAIL AGENT SECURITY REVIEW: QUESTIONS TO ASK A VENDOR DuoInbox — duoinbox.com/resources/ai-email-agent-security-questions/ Nine questions to take into a vendor call before letting any AI agent touch a team inbox. Write the answers down. 1. SCOPE GRANULARITY Can permissions be set per workflow, or only per integration as a whole? 2. WHAT TRIGGERS A RUN What event starts a run, and how precisely can that trigger be scoped — a specific sender, domain, subject pattern, or label? 3. WHAT ONE RUN CAN READ When a run starts, does it see the single matched message and thread, or does it get open-ended access to search or read the rest of the mailbox? 4. WHO AUTHORIZES A SEND Can a workflow be configured to send only after a person approves it, and does that apply to every outbound message from that workflow or only some? 5. HOW RECIPIENTS ARE RESTRICTED Can the system restrict or flag who a reply can go to, and is an added or changed recipient checked as its own event rather than read as incidental text inside the reply? 6. WHAT RATE LIMITS APPLY Is there a ceiling on how many actions a workflow can take in a given period, and what happens when it is reached? 7. WHAT AN OPERATOR CAN RECONSTRUCT FROM THE AUDIT LOG From the log alone, can you tell why a run started, which rule it matched, what it was permitted to do, who approved it, and whether a repeated action is a retry of the same event or a new one? 8. HOW FAST ACCESS CAN BE REVOKED Is there an immediate control to stop new runs, and does it act at the workflow level or only by disconnecting the whole integration? 9. WHO OWNS THE AGENT Who inside your organization is accountable for the rules, exceptions, and pause decisions, and do they have direct visibility into the queue and the runtime? A vendor who cannot answer one of these with specifics, rather than a general assurance, is telling you something. Weigh a vague answer the same way you would weigh a vague answer to any other security question. Related reading: https://duoinbox.com/guides/ai-email-agent/ https://duoinbox.com/guides/gmail-mcp-for-ai-agents/ https://duoinbox.com/controls/ https://duoinbox.com/security/