Docs/ AI & automation

Authority modes — Manual, Copilot, Autopilot

Graduate the agent’s autonomy from suggestions to bounded action.

AI Emaily lets you choose exactly how much the agent does on your behalf. A global default applies across all threads, and agent-behaviour rules can override it per context — so high-trust senders can run on Autopilot while cold mail stays on Manual.

The three authority modes

Every thread in AI Emaily is processed under one of three authority levels. You set a global default in Settings → AI, and individual agent-behaviour rules can narrow or widen that default for specific senders, labels, or thread patterns.

The mode controls whether the agent takes action autonomously, drafts work for your approval, or stays silent until you ask.

ModeWhat the agent doesHuman touch-point
ManualAgent drafts are off; it assists on demand — summaries, search, a draft when you askYou initiate every action
CopilotTriages and drafts replies in your voice, held in the Agent drafts queue for your approvalOne click to send or dismiss; nothing leaves without you
AutopilotWithin the limits you set, drafts and sends on its own — for allow-listed senders onlyYou review the audit log and can cancel within the undo countdown

Autopilot guardrails

Autopilot is never a free agent. A set of gates determines when it sends and when it holds for you. They are all enforced at once — the first one to fail holds that draft for your review in the Agent drafts queue instead of sending it. Above them all sits a global PAUSE kill-switch that stops every autonomous send at once, plus full audit and per-send undo.

  • Sender allow-list — autonomous sends only go to the domains and addresses you have approved; everything else is held
  • Confidence floor — default 85%; any reply the agent rates below this is held rather than sent
  • Undo delay — a cancellable countdown (default 5 minutes) after the agent queues a send, giving you real-time undo
  • Escalate-if keywords — words or conditions that force human review no matter how confident the agent is
  • Working-hours-only (optional) — restrict autonomous sends to your working hours, e.g. 9–5 Mon–Fri in your timezone

Copilot never sends on its own

In Copilot, approval is mandatory: every draft waits in the Agent drafts queue and nothing leaves until you click Send now. Autopilot send is rolled out gradually and can be gated by plan. When Autopilot is enabled, the gates above are always enforced, every send is audited and reversible, and the global PAUSE kill-switch stops all autonomous sends instantly.

Adopting autonomy gradually

The recommended path is to start on Copilot, watch the agent’s drafts for a week, then promote trusted sender groups to Autopilot one rule at a time via agent-behaviour rules. This gives you a clean sense of the agent’s quality before you hand over send authority.

  1. 1

    Set global default to Copilot

    Go to Settings → AI → Authority and choose Copilot. All threads now get drafts in the Agent drafts queue with one-click send.

  2. 2

    Review drafts for one week

    Use the confidence score and one-line reason on each draft to calibrate how well the agent knows your voice.

  3. 3

    Create a behaviour rule for trusted senders

    In Rules ⚡ Brain, add a rule matching your trusted senders and set its authority to Autopilot with your desired confidence floor.

  4. 4

    Tune the gates

    Adjust the undo delay, escalate-if keywords, working hours, and standing instructions until the behaviour feels right. The audit log shows every action the agent took and why.

  5. 5

    Expand the allow-list over time

    Add more domains or addresses to Autopilot rules as confidence builds. You can always revert a rule to Copilot without losing its other settings.

Changing modes mid-thread

You can override the authority mode on any individual thread from the thread action bar. This is useful when a normally routine thread suddenly becomes sensitive — drop it to Manual with one click and the agent will not act on it autonomously until you lift the override.

Thread-level overrides take precedence over both the global default and any matching behaviour rule.

Start narrow, expand gradually

Giving the agent Autopilot on a small, well-defined sender group is far more effective than a broad Autopilot default. Narrow rules produce predictable, auditable behaviour.

Frequently asked

Feature overview

Copilot & Autopilot

Ready to try it?

Start Free Trial