Governed mail and calendar

The general model is Governance/Design; the catalogue of every concept is Governance/Catalogue. This page is the Mail module's part: which of its acts are activities, under which standard, and the rules the Executive Assistant follows.

The one idea

Today the assistant drafts and the person sends (Email:AgentSend = DraftOnly). That is already a governed activity in everything but the record: the draft is the proposal, the person's Send is the signature, the mailbox is the executor's identity. Making it one changes nothing the person does and adds the trail — who proposed, what was signed, what went out, when.

What is an activity, what is not

Act Activity? Standard Proposer → Reviewer → Signers → Executor (identity)
a draft in the person's Drafts no — inside the person's own mailbox, reversible — —
an inbound mail routed to a thread / the shared inbox no — the route's answer is a draft — (mail.route, unattended, only when the router files a reply for someone else) —
a notification to the person no — the person's own rules decide — —
reply to a mail yes mail.reply the EA (as the person) → none → the mailbox owner → SendDraft (Proposer)
mail someone outside the tenant yes mail.send-external the EA → Role.Reviewer where the tenant's policy says → owner + Manual("recipients-checked") → SendDraft (Proposer)
a mailing (one template, many recipients) yes mail.mailing the EA → none → the owner — the mailing page's Send is the signature → SendMailing (Proposer)
a quorum-approved mail (CRM: two of three partners) yes mail.quorum the author → none → Signatures(n) from the named approvers, each on the text as it stands → SendDocument (Proposer)
share a document by mail yes document.share-email the person / agent → none → the person → ExportAndSend (Proposer)
book a meeting with external attendees yes calendar.book the EA → none → owner + Manual("attendees-checked") → BookEvent (Proposer)
book an internal meeting no — reversible, inside the tenant — —
cancel a meeting yes calendar.cancel the EA → none → the owner → CancelEvent (Proposer)

The rules — what carries over unchanged

  1. The proposer is the person's assistant, acting as the person — and still cannot sign. The EA writes the proposal under the person's delegated identity; the signature must be the person's own click on the activity page (or, in DraftOnly, the Send in their mail client, which the executor recognises: see 4). An agent identity never satisfies Signature().Human().
  2. A wrong draft is amended, never re-drafted. The activity's draftId is stable; a correction is GetDraft → UpdateDraft on the same draft. The correction changes the content hash, which lapses an earlier signature — the person signs what they will send.
  3. Both writers re-read isDraft inside the write. The SendDraft executor refuses when the draft is no longer a draft; the activity ends Done with "sent by the owner".
  4. DraftOnly stays the default. In that mode the send tools are never handed to the model and SendDraft is refused on the instance; the activity's gates still run, the person still signs, and the executor records that the person sends from their client. A deployment that grants sending flips one configuration key, not the standard.
  5. One message carries every recipient (#3473) — never one mail per address. mail.mailing is the exception by design: N personal mails, each previewed, one Send.
  6. No tool attaches a file. A mail that must carry one is document.share-email with DocumentDelivery.Attachment.
  7. "Mailbox not connected" is a consent step, not a capability. The proposal is still filed; the activity waits at Gating naming the consent link; nothing is minted on the person's behalf.

The standards, as data

mail.reply, mail.send-external, calendar.book and calendar.cancel are seeded in Governance/Standards/; mail.mailing, mail.quorum, document.share-email and mail.route are defined here and seeded when the SendMailing / SendDocument executors land (slice 2, with the Proposer identity through IEaGraphAuth.GetAccessToken and SendDocumentDispatch.ExportAndSend with EmailDelivery.AsUser). The Mail package does not depend on Governance; its standards live under Governance/Standards/ until it does.