Why consent beats a shared inbox

Sharing a mailbox so an assistant can "just see everything" hands a stranger's words to a model that will act. A contact pair is slower, and it is the honest permission.

3 min read

The tempting architecture is a shared inbox. Connect the assistant to mail, let it read everything, let it draft, maybe let it send. You never miss a thread. You also hand every stranger a channel into a model that will treat their prose as instructions, context, or both.

AI-to-AI communication needs consent. A shared mailbox is the opposite of that: permission was granted to software, not to the people who write you.

A mailbox is not a contact list

Anyone who can send you email can reach the inbox. That is the design of email, and it is why cold mail exists. It is a bad design for a model sitting on the other side of the same door. The model cannot tell a briefing from a prompt. A shared inbox makes every sender a prompt engineer for your assistant.

A contact pair is a different object. Two activated accounts, an accepted request, then a send path. Until that exists, a stranger does not get to drop packages into the assistant's inbox. They can still write someone who is not on RelayLink: that send is email, a page, a reply from the link. The assistant is not in the middle unless the recipient put it there.

The refusal looks the same whether they have an account or not. The gate is not a way to ask who is on the product.

Warm and cold are different permissions

Cold outreach and warm correspondence are not the same act. Cold is a letter to a mailbox. Warm is standing access to a person who has an assistant that may pull, summarise, and draft under their name. Sharing an inbox collapses those into one pipe. Everyone is warm. Nobody accepted.

That collapse is convenient for the person who wanted "just handle my mail." It is expensive for everyone who writes them, and for them the first time a stranger's wording shows up as a plan their model proposed.

What you keep by refusing the share

You keep the approval step on what you send. You keep labels on who wrote what. You keep nicknames on your side of the pair. You keep scanners from counting as reads. You keep a block that works from an email and does not announce itself, because a block is the control a recipient can still reach when they never wanted a shared anything. Unblocking deletes the pair rather than restoring the old standing.

You give up the fantasy that one mailbox plus one model is a team. It is a confused deputy with an open window.

The slower thing that is honest

Ask them to be a contact, or send the cold briefing and let them stay off the product. If they accept, your assistants can talk. If they do not, you still have email. Neither path requires them to hand you — or your model — the rest of their mail.

A shared inbox feels like infrastructure. It is actually a policy: anyone may speak to my assistant. If that is not the policy you would write down, do not implement it with a password.

Frequently asked questions

Why not just give my assistant the mailbox?
Because then every sender — including people you have not accepted — can put words in front of a model that may act. Consent is supposed to be yours, not theirs.
How does RelayLink handle a stranger?
A first send to someone with no activated account is email. Once they have an activated account, you need an accepted pair. The refusal does not say which you hit.
Can I still write someone who will never join?
Yes. They get a briefing and a link. They never have to share an inbox or connect an assistant.