How to Give an AI Agent Access to Your Gmail (Safely)
Connect Gmail to Damon, see exactly what the agent can read and change, and put it to work triaging your inbox every morning — with every send left to you.
By Marlon Wiprud
The useful version of "an AI agent with access to my email" is not a bot that answers everything. It's an agent that reads your inbox, tells you the three things that need you, drafts replies to the rest, and never sends anything you haven't seen. This guide sets that up in Damon, with the permissions spelled out.
What the agent can do in Gmail
Damon's Gmail support is built in — a fixed set of ten actions, not a general-purpose connector — and each one is classified as reading or changing your mailbox:
| Reads (auto-approved by default) | Writes (require your approval by default) |
|---|---|
| Search emails | Send an email |
| Get an email or a whole thread | Reply to a thread |
| List labels | Create a draft |
| | Archive |
| | Mark as read |
| | Apply a label |
The split is the point. An agent can research your inbox freely; the moment it wants to send, archive or label, it stops and asks. That's the whole list: there's no bulk delete, no filter management, no settings access, because those actions don't exist for it.
Step 1: Connect Gmail
In Integrations, choose Gmail and approve Google's OAuth screen. Damon asks for the Gmail scopes those actions need and nothing else. That's it: the default agent, Damon, can use the connection straight away, and every write action is gated, so out of the box you have an agent that can summarize and draft but not send.
Step 2 (optional): A dedicated inbox agent
You don't need a separate agent for this. Create one if you want a narrower allowlist or a specific voice for inbox work. In Agents (or by asking Damon in chat):
- Name: Inbox,
@inbox - Personality: "Terse. Lead with decisions I need to make. Quote the sender's ask in one line before your recommendation."
- Goals: "Keep my inbox to the emails that need me. Draft a reply for anything that needs one. Never send without approval."
- Integrations: Gmail only.
The allowlist is explicit: this agent can't touch your calendar or CRM because you didn't grant them. If you later want it to check availability before proposing meeting times, add Google Calendar.
Step 3: Try it in chat
Open a chat (with Damon, or @inbox if you made one) and ask:
Go through my inbox from the last 24 hours. What needs me, what can wait, and what's noise? Draft replies for anything that needs one.
You'll get a sorted list with a citation back to each thread, and drafts sitting in Gmail's Drafts folder for you to send or discard. Creating a draft is a write action, so the agent asks before creating them; approve, then open Gmail and read them.
Step 4: Put it on a schedule
Ask the agent to turn that into a daily workflow: "Do this every weekday at 7:30 and message me the summary." Damon builds:
- Trigger — every day, 07:30, your timezone.
- Agent step — the triage instructions above, run in the background with the Gmail tools.
- Message step — opens a chat thread with you: the decisions first, then the waiting list, then the count of drafts waiting in Gmail.
Open Workflows to see it as a graph and adjust the wording of any step. The message step is what makes the result visible; work an agent does in a background step is only surfaced when a step explicitly messages you.
Deciding what it may do on its own
Autonomy policies map scopes to a mode. For an inbox agent the scopes that matter are email.read and email.send, and email.send covers every mutation: send, reply, draft, archive, label. There's no way to auto-approve drafting without also auto-approving sending, so our recommendation is to leave it gated. Each morning's run asks once for its batch of drafts and labels; you approve with a click, and nothing ever leaves your account unread. We run our own inboxes this way.
What you can safely loosen is elsewhere: if the agent also saves a daily summary to your drive, auto-approve file.write for that workflow. Policies layer (step → workflow → workspace default), so "this one job may write files" doesn't mean "this agent may write anything".
What a good triage prompt includes
The agent step's instructions are its brief, and specificity pays. A version that works well:
Review unread email from the last 24 hours, excluding anything already labeled "Newsletters" or "Notifications". Sort into three groups: (1) needs a decision or reply from me today, (2) can wait until Friday, (3) informational. For group 1, quote the ask in one line and draft a reply in my voice; keep drafts under 120 words. For group 3, apply the label "Triage/Read later". Do not archive anything.
Save the parts of that which are about your preferences (voice, 120 words, the label name) as a skill, and the agent will apply them to every email task, not just this workflow.
Variants
- Shared support inbox: same setup on a Google Group or delegated mailbox; add Linear or ClickUp and have the agent create a ticket for anything that's a bug report. That's the customer-support recipe.
- Calendar-aware replies: grant Google Calendar so drafts proposing meeting times reflect real availability.
- Outlook: the same pattern applies; connect the mailbox you use. Ask us if yours isn't listed yet.
Common questions
Does the agent see all my email?
It can search any mail the connected account can, but it only reads what a task calls for, and every read is logged in the run. If you want a hard boundary, connect a delegated or shared mailbox rather than your primary one.
Will it send email without me?
No. Every send, reply, draft, archive and label change pauses for approval, and we recommend keeping it that way.
Can it work with my existing labels and filters?
Yes. It can apply labels you already have and you can tell it to skip anything your filters have already sorted.
Which model reads my email?
Whichever you choose: Anthropic, OpenAI or Google models, all through zero-data-retention endpoints, so the provider doesn't keep your mail.