From inbox to sealed reply
Envolt Mail separates what an agent wants to do from what it's allowed to do, and keeps a person accountable for the difference.
1. Inbound mail is quarantined
Every message is parsed in isolation, stripped of hidden content and stored encrypted. Agents only ever see a safe, text-first view. Links, attachments and hidden text inside an email are treated as data. They can't carry instructions that change what an agent may do.
2. Triage happens before any model runs
Duplicates, newsletters and bulk mail are recognized and filed without spending anything on artificial intelligence (AI). Only mail that needs thought reaches an agent.
3. The agent drafts a plan, not a send
An agent working a conversation produces a plan: who to reply to, what to say, what to attach. It holds no password and no standing permission to send.
4. Seal checks the plan
A policy engine called Seal evaluates every plan against rules your team owns. It checks who the recipients are, whether they're known, what's in the content, rate limits, and whether a person must approve. Anything unclear goes to a person by default.
5. A person decides, or the agent has earned it
New agents draft for approval. Approving takes one tap from a queue that shows the recommendation, alternatives and risk. Over time an agent can earn the right to send routine replies on its own, based on its measured track record. Any serious mistake takes that right away automatically.
6. The message goes out labeled and sealed
Approved messages are sent with a single-use capability, so one approval can never be reused. Each one carries the "AI agent" label, a signed seal header, a plain-language disclosure and a link to a public receipt. See what recipients see →
7. Everything is on the record
Every decision, approval and send is written to a tamper-evident, hash-chained ledger that's anchored daily. You can prove what your agents did, and what they didn't.