Stopping an assistant from sending as you

The control is not a better prompt. It is a send path that will not deliver until you approve what the other person will see.

3 min read

The fear is specific. You said "write to Richard about the contract." You did not say "send." Something went out under your name anyway — or you worry it will. A prompt that says "never send without asking" is not a control. It is a hope, stored in a context window that the next message can overwrite.

If words will bind you, the send path has to refuse to deliver until you have seen the package.

A prompt is not a lock

Models follow instructions until they do not. A long thread, a tool result that looks like permission, a user who said "just handle it" three turns ago — any of those can look like consent to send. Human-in-the-loop that lives only in prose is theatre. The loop has to be in the server.

RelayLink's shorthand opens a draft. It does not send. The instructions say so in those words, and the tools are split the same way: compose, then confirm. Confirm is the signature. There is no silent third tool that mails the draft because the conversation felt finished.

That is why the approval step is the product, not a preference. Full-auto mail removes the owner. The person whose name is on the From never saw the words.

What you actually review

You review the package as the recipient will see it — ask, brief, options, assumptions, note — not a transcript of how the assistant got there. The unit is small enough to read. If you leave the note alone, you approved the draft. If you change it, you claimed different words. If you empty it in the portal, the send is refused. Deleting the sentence is not approval of the old one.

Letting your AI email someone still goes through that gate. So does a send to yourself. So does a send to someone with no account. The transport changes. The signature does not.

What this does not stop

It does not stop the assistant from wanting to send, or from telling you it already did. Read the draft. If there is no package waiting, nothing left. It does not stop a different mail product you connected with full mailbox scope. That is a different grant, and a different risk.

It does not stop you from confirming too fast. Rubber-stamping is a human failure. The product can force a pause. It cannot force attention. What it can do is make the pause the only road out.

If you no longer trust the session

Revoke the key that session held. Disconnect the application on your connections page. Those are owner controls, and they do not require the assistant's cooperation. A leaked key cannot issue its own replacement — issuing is not a tool.

Then treat anything that already went out as sent. You cannot unsend a briefing that arrived. You send a correction, labelled, approved, the same way as the first one.

The way you stop an assistant from sending as you is not a sterner system prompt. It is a product that will not mail until you say the words are yours.

Frequently asked questions

Can my assistant send a RelayLink briefing without me?
No. Draft opens a package. Confirm is a separate step. The shorthand that looks like a send still opens a draft.
What if I tell it to just send it?
It can draft. It cannot skip your approval. If a path ever bypassed that step, the product would have lost the one guarantee it exists to keep.
Is disconnecting the only way to stop it?
Disconnecting ends the grant. While it is connected, the send path is still draft-then-confirm. Revoking a key ends that key. Closing the account ends the address.