RiskMandate v1.38.0
Rule RM-R0017 · v1.0.0 · ask me first

Do you want your agent to send email as you without showing you first?

It replies on your behalf, to the wrong person, with the wrong attachment, or in a tone you would not use. Sent mail cannot be recalled.

What you get: Nothing is sent in your name until you have seen the words and the recipients.

The capability: Send a message to anyone (send.message.world). Undo: cannot be undone.

All rules: the index · This page as markdown: send-as-you.md

01 · The line

Paste this into your agent's instructions, and it should ask you first.

For Claude Code, that is CLAUDE.md in the project or in your home directory; for Claude on the web or the desktop, a project's instructions or your personal preferences. The one line is enough to try it; the paragraph tells the agent why, and what counts.

The one line
Never send an email, message or invitation on my behalf without showing me the exact text and recipients and waiting for a yes; drafts are fine.
The paragraph
Anything sent in my name is mine. Write drafts freely. Before sending any email, chat message, reply or calendar invitation, show me the recipients, the subject and the exact text, and any attachment, and wait for a yes for that message. A yes for one message is not a yes for the next.
02 · What that line is

A request to the agent, not a control.

In the vocabulary every published behaviour policy uses, a line in the agent's instructions is an expectation: a rule in prose, enforced by nobody. A rule in prose is inside the boundary the agent operates in. All four major model providers stated in their own 2026 words that an instruction at this layer can be bypassed. It changes what the agent usually does, which is worth having; it does not hold when the agent is talked out of it, confused, or reading somebody else's instructions in a web page.

If you want more than a request, these are stronger, each quoted from the vendor's own page on the date shown.

setting · a switch the agent's own account can flip

An organisation's admin can set a claude.ai connector tool to ask

Set by the organisation's admin for each connector tool; the setting also reaches Claude Code sessions.

“If your organization has set a claude.ai connector tool to ask and that setting reaches Claude Code in your session, allow rules for that tool don't take effect: Claude Code prompts on every call, even in auto and bypassPermissions modes.”

code.claude.com/docs/en/permissions · read 8 October 2026

03 · Where your agent already has it

This is a row in 3 published behaviour policies, with what stands in the way today.

Read from each vault's own grant, as published. The barrier is what was found in that deployment, before any rule.

AgentBarrierWhat the behaviour policy says
Claude's Gmail connectorsettingAnthropic: "Send, reply to, and forward emails from Gmail." and "During authentication, Google's OAuth screen mentions email sending permissions... Claude can send, reply to, and forward emails, but only does so with your explicit approval by default." The directory listing names reply and forward; Google's own reference for the same server (2026-07-21) names no tool that sends — see contradictions. The credential is the grant; the approval prompt is the barrier, and by the enforcer test it is a setting — the grant includes the ability to remove it. Measured 2026-09-16: one message sent to an address the deployer named for the purpose, after "Allow once"; Claude confirmed the send and the sending address. The message as sent carries no header naming the client: no X-Mailer, no User-Agent; the Received line says "by gmailapi.google.com with HTTPREST" from a numeric sender that is the OAuth client's Google Cloud project number, and the body is signed with the account holder's name. To the recipient it is the account holder's mail (evidence/09).
Google Workspace MCP serversboundarygmail.compose — "Manage drafts and send emails." The setup page advertises "create draft emails"; the scope it asks for also sends. Whether the server exposes a tool that sends is open, below.
Microsoft 365 connector (Claude)boundaryoutlook_send_mail — "Send an email as the user." To any address. Listed under Write tools on the same page whose read section says the connector "provides read-only access to" its sources.
04 · Before and after

Not run yet. It will be, on our own deployment.

Every rule gets one run without the line and one with it, on a deployment we are entitled to run, dated, stopped before anything irreversible. How these are run.

05 · Did it work for you?

Tell us, and the rule gets better.

Each link opens the contact form with this rule's id and version filled in. It is encrypted in your browser and read by a person. Nothing is sent until you press send.

06 · One row, and the whole agent

A rule is one row. The ABP is every row, for your agent.

If this one made sense, the Agent Behaviour Policy is the same idea for everything your agent can reach: what it can do, what you authorised, the gap, and what stands in the way of each thing.

Versions

  • v1.0.0 · 8 October 2026 · First version, written from the published rows with nothing in the way.