Governed mail and calendar
The general model is Governance/Design; the catalogue of every concept is Governance/Catalogue. This page is the Mail module's part: which of its acts are activities, under which standard, and the rules the Executive Assistant follows.
The one idea
Today the assistant drafts and the person sends (Email:AgentSend = DraftOnly). That is
already a governed activity in everything but the record: the draft is the proposal, the person's
Send is the signature, the mailbox is the executor's identity. Making it one changes nothing the
person does and adds the trail — who proposed, what was signed, what went out, when.
What is an activity, what is not
| Act | Activity? | Standard | Proposer → Reviewer → Signers → Executor (identity) |
|---|---|---|---|
| a draft in the person's Drafts | no — inside the person's own mailbox, reversible | — | — |
| an inbound mail routed to a thread / the shared inbox | no — the route's answer is a draft | — (mail.route, unattended, only when the router files a reply for someone else) |
— |
| a notification to the person | no — the person's own rules decide | — | — |
| reply to a mail | yes | mail.reply |
the EA (as the person) → none → the mailbox owner → SendDraft (Proposer) |
| mail someone outside the tenant | yes | mail.send-external |
the EA → Role.Reviewer where the tenant's policy says → owner + Manual("recipients-checked") → SendDraft (Proposer) |
| a mailing (one template, many recipients) | yes | mail.mailing |
the EA → none → the owner — the mailing page's Send is the signature → SendMailing (Proposer) |
| a quorum-approved mail (CRM: two of three partners) | yes | mail.quorum |
the author → none → Signatures(n) from the named approvers, each on the text as it stands → SendDocument (Proposer) |
| share a document by mail | yes | document.share-email |
the person / agent → none → the person → ExportAndSend (Proposer) |
| book a meeting with external attendees | yes | calendar.book |
the EA → none → owner + Manual("attendees-checked") → BookEvent (Proposer) |
| book an internal meeting | no — reversible, inside the tenant | — | — |
| cancel a meeting | yes | calendar.cancel |
the EA → none → the owner → CancelEvent (Proposer) |
The rules — what carries over unchanged
- The proposer is the person's assistant, acting as the person — and still cannot sign. The
EA writes the proposal under the person's delegated identity; the signature must be the person's
own click on the activity page (or, in
DraftOnly, the Send in their mail client, which the executor recognises: see 4). An agent identity never satisfiesSignature().Human(). - A wrong draft is amended, never re-drafted. The activity's
draftIdis stable; a correction isGetDraft→UpdateDrafton the same draft. The correction changes the content hash, which lapses an earlier signature — the person signs what they will send. - Both writers re-read
isDraftinside the write. TheSendDraftexecutor refuses when the draft is no longer a draft; the activity endsDonewith "sent by the owner". DraftOnlystays the default. In that mode the send tools are never handed to the model andSendDraftis refused on the instance; the activity's gates still run, the person still signs, and the executor records that the person sends from their client. A deployment that grants sending flips one configuration key, not the standard.- One message carries every recipient (#3473) — never one mail per address.
mail.mailingis the exception by design: N personal mails, each previewed, one Send. - No tool attaches a file. A mail that must carry one is
document.share-emailwithDocumentDelivery.Attachment. - "Mailbox not connected" is a consent step, not a capability. The proposal is still filed;
the activity waits at
Gatingnaming the consent link; nothing is minted on the person's behalf.
The standards, as data
mail.reply, mail.send-external, calendar.book and calendar.cancel are seeded in
Governance/Standards/; mail.mailing, mail.quorum, document.share-email and mail.route are
defined here and seeded when the SendMailing / SendDocument executors land (slice 2, with the
Proposer identity through IEaGraphAuth.GetAccessToken and
SendDocumentDispatch.ExportAndSend with EmailDelivery.AsUser). The Mail package does not depend
on Governance; its standards live under Governance/Standards/ until it does.
Related
Mail/Skill/governed-mail— the assistant's operating rules under this page.get Doc/AI/ExecutiveAssistant,get Skill/share-email,get Skill/email— the seams.- Governance/Catalogue — the CRM quorum mail and the social post beside these.