Docs / Use cases

Mailbox triage

Mailbox triage turns an inbox you dread into one short message you read in two minutes: your agent reads every thread, decides by rules and by judgment what needs you, archives the rest where you can always get it back, and reports the money, deadlines, security events and people that were buried in the mail. It learns from what you do with each digest, so you never teach it the same thing twice. Nothing is deleted, nothing is sent without you.

The loop at a glance

Read · every thread, headers firstJudge · rules hint, the model decidesArchive · verified, restorableDigest · four groups, one message
↓
Reply · by label: bring back A3, draft D2Cockpit · money, deadlines, security, peopleLearn · what you restore, answer, ignore

Everything runs on your own machine with your own keys (a free local skill). The model only ever judges; archiving is verified on the server per message, and every archive is restorable by its label.

Hand this page to your agent

AG2 Space 0.6.10 and newer. Send this page to your agent; no clicking through the Marketplace one tool at a time.

Copy this page's link from your browser and send it to your Sutando. It reads the page, installs every skill and activates every cloud tool listed under Requires below in one go, then follows the rest of the page with you, step by step. Before installing it shows you the plan: what it will add and what you already have. Anything that costs credits waits for your OK. Skills and cloud tools work the moment they land: your agent uses a newly activated cloud tool straight away, with no restart and no dashboard step. Only if the setup script itself reports that a restart is required does your agent ask you, once, to open Agent settings (the bot icon, bottom left), scroll to Runtime and click Restart engine.

Requires

  • Skills: email-triage-pro

Or set it up by hand

Email Triage Pro is a local skill: Install it from the Marketplace in the desktop app. It is free and runs on your Mac; your mail never leaves it except for the judging calls, which go to a model under your own API key.

Your agent restarts after the install, that's normal. The first time you say "triage my inbox" it sets itself up, asks exactly one question, and comes back with the first digest. Installed skills refresh on their own the next time you open the Marketplace; see how skills stay up to date.

Before you start

Two things need to exist, and the skill sets both up itself on the first run. You never paste a password or a key into the chat.

  • A way to read your Gmail. The first time you say "triage my inbox" your agent asks one question: read the mail through the Gmail connector you may already have (A, no setup, slow: a first run over a few hundred emails takes 15 to 25 minutes) or through a Gmail app password (B, recommended: two minutes of setup, then a 6,000-thread first sweep in about four minutes and daily runs in seconds, and better sorting because it sees the real headers).
  • A Gemini API key of your own. Every thread is judged by the model with today's date and the thread's age; that is what keeps a real person from being buried and a year-old newsletter from surviving. The key is yours, so nobody shares a quota with you, and a 6,000-thread sweep costs well under a dollar.

Pick B and this is what happens: the skill writes GMAIL_ADDRESS=, GMAIL_APP_PASSWORD= and GEMINI_API_KEY= into the .env file in your workspace, with the steps written as comments right above each line, and opens that file for you. You create the app password at Google (Account → Security → 2-Step Verification → App passwords: type a name, Create, copy the 16 characters), paste it after GMAIL_APP_PASSWORD=, put your address after GMAIL_ADDRESS=, and save. For the model key, the same file: create a free key at aistudio.google.com/apikey, paste it after GEMINI_API_KEY=, save. Your agent keeps watching the file and continues the moment the login works and the key answers one tiny test call. Nothing is read or archived until both check out.

The file lives on your own Mac and never leaves it. If you would rather not have it opened for you, say so: the skill tells you the path instead. "Switch to the connector" or "switch to imap" changes the path later, any time.

Step 1 · The first run

One question, no forms, and the whole backlog swept.

Say "triage my inbox". The first run does three things you would otherwise have configured by hand:

  • It learns who matters from your own mail. Ninety days of your Sent folder and your calendar tell it who you actually write to (VIPs), which domain is your team, which companies you meet, which senders are newsletters and which are automation. Nobody fills in a form.
  • It sweeps the entire inbox, not the last day. Six thousand threads, a year of backlog, in one digest, newest first. Everything it archives is server-verified and restorable.
  • It registers itself for two runs a business day and puts one line in your agent's memory so the setup survives updates.

Start it

Triage my inbox, including the backlog.

The only thing it asks is how to read the mail (app password or connector); the keys go into the file it opens, never into the chat. Everything else is inferred and shown to you at the top of the first digest, so you can correct any of it by replying.

A run reports its progress as it goes (threads read, how many the rules decided, how many the model judged, how many archived and verified) and then delivers the digest, with a link to the report page first.

Step 2 · The digest

Four standing groups, every line tagged with what happened to it.

A · ArchivedAutomated mail that needs no one: notifications, alerts, receipts already captured as money facts, old unanswered threads. Archived, restorable.
B · Quick confirmsThings you would glance at and close: calendar acceptances for meetings that have passed, booking confirmations, threads you already answered. Archived, restorable.
C · Newsletters & cold outreachBulk mail and pitches, identified by headers and by judgment. Archived, restorable, and forwardable to an address you name.
D · Needs youReal people waiting on you, customers and pilots, decisions, signatures, dated actions, and your upcoming meetings. Left in the inbox.

Every line carries its own label and its fate, so a reply is never ambiguous:

D2. [IN INBOX] Priya Natarajan (Northwind): asks to move Thursday's pilot review to Friday 10am PT and needs the new invite. (awaiting you since Aug 26)

B4. [ARCHIVED] You replied Aug 21: Sam Rivera proposed Monday between 1 and 5 pm.

A7. [ARCHIVED] Acme Cloud: receipt $223.46 for August (invoice 12345).

What "needs you" deliberately excludes, because these were the mistakes that made people stop trusting triage tools:

  • Threads you already answered. Every run reads your Sent folder; if your last message on a thread is newer than theirs, it can never be "needs you". For a customer it shows as "you replied Aug 21, waiting on them" on its own shelf.
  • Calendar mail about events that have passed. A proposal to move a meeting that was last Tuesday is history, whatever it asks.
  • Old unanswered asks. A human thread you have not answered in 60 days is archived with its age in the line ("unanswered for 14 months"), not carried as a to-do forever. Say "bring back" if one still matters.

And what it keeps, because the opposite mistake is worse: your upcoming meetings. A booking, an acceptance or a decline for a meeting that has not happened yet stays in the inbox until the date passes. Active customer threads stay visible for two weeks even when it is their move.

Step 3 · Reply by label

The digest is a conversation. Labels are the addressing.

Get something back

Bring back A3.

The thread returns to your inbox, verified, and the correction becomes a dated rule so the same sender is never buried again. "Undo today" restores everything the last run archived; nothing is ever deleted, so undo is always complete.

Have it draft a reply

Draft D2.

It writes in your voice, learned from your own sent mail, threads the draft on the original message and shows you the text with the recipients at the top. Drafts are create-only and never sent until you say "send the draft" after reading the final text.

Close things and ask why

Done W1. Why D3?

Done stops an item being carried in later digests. Why shows the rule or the model's reasoning behind any line, and, for money, the sentence the amount came from.

Step 4 · Twice a day

After the first sweep, runs cover the last 36 hours and take seconds. They fire at 08:30 and 16:30 on business days (say "run triage at 7 and 3" to change it; weekends and holidays are skipped) and land wherever you last spoke to your agent: the room, Slack, Telegram, the app.

Items you have not dealt with are carried in every later digest under "Still with you" with W handles (W1, W2) until you say done, so nothing silently expires. Voice works from the same run: "what's urgent" answers from the latest digest.

Step 5 · The cockpit

The mail is also a ledger. Every receipt, deadline, security event and customer thread becomes a fact with its evidence.

Triage decides where an email goes. A second pass decides what it tells you, and turns it into durable facts:

  • Money. Receipts and invoices (the amount is usually only inside the PDF, so the PDF is read), subscriptions and renewals, failed payments, spend alerts, usage limits, price changes, trials ending, refunds. The model transcribes what is printed; every total, monthly equivalent, "failed nine times" and "next expected charge" is computed in code, and any amount that does not appear verbatim in the email or the PDF is rejected.
  • Deadlines and expiry. "Your project will be deleted in 48 hours", "2FA required by June 9", "data deleted after cancellation".
  • Security events. New sign-ins, permission requests, password changes, API keys.
  • Legal, hiring, customers, investors, travel. Signature requests and equity events, candidates and interviews, per-account customer state and who is waiting on whom, reservations.

The digest carries the new and critical ones as a short Heads-up block (E1 deadline, S1 security, L1 legal, H1 hiring) and one Money line; the rest is on demand.

Ask the ledger

What am I paying for? Any failed payments? What did I spend on OpenAI? What's expiring? Who's waiting on me? Any security alerts I haven't acknowledged? Where are we with Northwind?

Each answer comes from the ledger in under a second and prints its inputs, so a figure in a digest can be checked against the receipts by eye. "Money summary" gives the paragraph: subscriptions, monthly equivalent, business versus personal, unresolved failures.

The cockpit surfaces and proposes; it never touches the world on its own. "Remind me about E1" prints a calendar event for your yes; "add them to my people" prints a dossier for your yes. Nothing is written to your calendar or contacts without you saying so.

The report page

Every run also renders the digest as one self-contained page and publishes it, so the first line of what you receive is a link. The page has fixed sections with a sticky navigation: Overview, Needs you grouped into shelves (customers and pilots, people who matter, team, support, actions and deadlines, upcoming meetings, waiting on them, older asks), Heads-up, Expenses (window total with its inputs, month-to-date, subscriptions and their monthly equivalent, business versus personal, a six-month chart, spend by vendor, failed payments and alerts, receipts in a collapsed table), the Cockpit, the Archived groups collapsed with a filter, and the reply chips. Same layout every time, so you learn where to look once.

What it learns, and how

You never re-teach it. Every decision is a ledger row, and every run starts by reading what you did with the last digests on the server: what you restored, what you answered, what you trashed, what you ignored. Consistent signals become sender-table entries silently (one silent change per sender, ever); anything less certain becomes one yes/no question at the end of a digest, never a guess.

A correction becomes a rule

Always put mail from Northwind in D. Never bury Docusign. Forward newsletters to reading@acme.example.

Each of these applies at once and is filed as a dated rule in your own words. "Adopt 1" accepts a rule the digest proposed; "no" declines it and it is never proposed again.

Rules you can set by saying so

  • Schedule and delivery: "run triage at 7 and 3", "D first", "shorter".
  • People and accounts: "treat sam@northwind.example as a VIP", "we are waiting on Acme for the contract".
  • Groups: "always … in D", "never archive …", "forward newsletters to …".
  • Mail access: "switch to imap" or "switch to the connector" any time.
  • Money scope: vendors are tagged business or personal; tell it which is which and it remembers.

Where your data lives

Everything this skill produces is a file on your own machine, in the workspace folder you can open: the sender table, your dated rules, the decision ledger, the money and facts ledgers, the report pages, the attachment cache. Your mail is read over IMAP from your Mac; nothing is uploaded to AG2 Space. The one thing that leaves the machine is the judging call to the model, under the Gemini key you own, on Google's terms with you (the paid tier does not train on your data; use one). The digest your agent posts into a room is stored like any chat message; the mail behind it is not.

  • Nothing is sent, signed or bought on your behalf. Drafts are create-only and wait for your final text; forwards only go to addresses you allowed; the agent never completes a transaction or accepts an agreement for you.
  • Verification codes and secrets stay put. One-time codes are recognised as such and archived after they expire; the skill never uses them.
  • Senders are judged by domain before subject, because subjects are attacker-controlled, and every outbound step passes an approval gate.
  • Leaving is complete. Delete the app and the workspace folder and there is nothing left to delete anywhere else: no retained copies, no licence, no training.

Guardrails

  • Nothing is deleted. Archiving is a label change, verified on the server per message, and every archive is restorable by label or all at once.
  • Nothing is sent without you. Drafts are create-only and never auto-sent; forwards only go to addresses you allowed.
  • Threads are addressed by Message-ID, never by subject search, and senders are classified by domain before subject, because subjects are attacker-controlled.
  • Your keys stay on your machine. The app password and the model key live in your own .env; the cloud never sees your mail.
  • Corrections are dated rules in your words. The agent proposes; you decide.

Speed & cost

Measured on a real 6,000-thread, 7,800-message inbox on the app-password path: the whole first sweep, from reading to a verified archive and a delivered digest, in about four minutes; daily runs in 15 to 30 seconds. The skill is free; the only cost is your own Gemini usage, a few cents a day.