Template · Agent · Official
GmailMicrosoft 365SlackNotion

Email triage, done before you open the inbox

An AGNT agent reads incoming mail, classifies it, drafts replies for the routine cases, and escalates the ones that genuinely need you — all under rules you write.

Get this template

Opens in AGNT and takes about a minute.

The short version

Tools it needsGmail, Microsoft 365, Slack, Notion
Setup4 steps, about ten minutes
ApprovalYours, per category — nothing is sent on your behalf unless you say so
Where it runsYour own machine. Credentials stay in a local vault.

What the agent actually does

You only see what actually needs you

The agent reads the whole thread, not just the subject line, and sorts it against categories you define — billing, bug report, sales enquiry, noise. Because it is reading rather than pattern-matching, a message that never uses the word "refund" still lands in billing when that is plainly what it is about.

Draft replies, never send blind

For the categories you mark as routine, it composes a reply grounded in your docs and previous answers, and leaves it as a draft. You skim and send. Nothing reaches a customer that a human has not seen, unless you explicitly decide a category is safe to send unattended.

Escalate with context

Anything genuinely needing you arrives with the work already done: what the customer asked, their account state, what was promised previously, and a suggested response. The escalation is a briefing rather than a notification.

The tools this job needs

Gmail

Where the work arrives. The inbox most operations still start in. The agent watches it and reads what turns up in full, rather than matching a rule against a subject line.

Microsoft 365

Context the agent pulls in before deciding. Outlook, Teams and Office — the other half of many stacks. It is read, not just referenced — which is what lets the decision account for it.

Slack

Context the agent pulls in before deciding. Team chat where operations actually surface. It is read, not just referenced — which is what lets the decision account for it.

Notion

Where the result lands. The team wiki agents can actually keep current. Nothing is written here until the agent has formed a view and, where you asked for it, you have approved it.

Set it up

  1. Connect Gmail or Microsoft 365 with one sign-in; tokens are stored encrypted on your own machine.
  2. Describe your categories and what should happen to each — in plain language, not a rules DSL.
  3. Point the agent at your docs and past replies so drafts sound like your team rather than a chatbot.
  4. Run it against the last week of mail first, read the receipts, then let it work live.

You can see exactly what it did

Nothing happens behind your back.

Every run leaves a receipt: what the agent read, which tools it called, what it decided and why, and precisely what it changed. Anything irreversible — sending, paying, publishing, deleting — waits for you to approve it. It runs on your own machine, with your own credentials, and the whole trail is yours to read afterwards. The point is not that you trust it. The point is that you never have to.

The brief it works from

This is the actual instruction set the template installs — what the agent is told to do, and what it is told never to do. Every line of it is yours to edit in AGNT after install.

Read the full brief

You triage an inbox. Your job is to make sure nothing important is missed and nothing routine reaches a human unprepared.

For every message

Read the whole thread, not the subject line. Subjects lie, get reused, and drift away from what the conversation became. Then decide two separate things: what this is, and what should happen next. Keep them separate — you are reliably good at the first and must be conservative about the second.

CLASSIFY against the categories the user has defined. If they have not defined any, propose a set from the first fifty messages you see and ask them to confirm before you rely on it. Classify on meaning, not keywords: a message that never says "refund" but describes being charged twice is a billing message.

Then act

  • Routine categories the user has approved: draft a reply and leave it as a draft. Ground it in their documentation and their previous answers to similar messages so it sounds like them, not like a chatbot.
  • Anything else: escalate. An escalation is a briefing, not a notification. Include what the sender asked, the relevant history, what was promised previously, and a suggested response.
  • Obvious noise: label it and archive it. Never delete anything.

Hard boundaries

Never send an email unless the user has explicitly marked that category as send-unattended. Draft-and-review is the default and you should expect it to stay that way for anything customer-facing. Never make a commitment on the user's behalf — no dates, no prices, no promises of a fix. If a reply would need one, escalate instead of inventing it.

When you are unsure

Say so, and say why. Flagging a message as uncertain costs the user five seconds. Guessing confidently and being wrong costs them a customer. "I could not tell whether this is a sales enquiry or a support request" is a useful sentence and you should use it.

Report what you did in plain language: how many messages, how they were classified, what you drafted, what needs them. If a category is consistently reaching them that you could have handled, say so — that is how your remit widens.

Shown exactly as it ships. The agent inherits whichever model you already use.

Why rules alone never finished the job

Every inbox eventually accumulates a stack of filters, and every stack has the same problem: it matches on surface features. A rule keyed to "invoice" misses the customer who writes about "the charge on my card", and catches the newsletter that mentions invoicing software. An agent classifies on meaning, which is why it handles the long tail that filters were never going to reach.

The judgment you keep

Triage is not one decision but two: what is this, and what should happen next. Agents are reliably good at the first and should be trusted with the second only where you have said so. The practical shape is an agent that classifies everything, drafts for most things, sends for a narrow set you have explicitly approved, and escalates anything it is unsure about — with uncertainty flagged rather than hidden behind a confident guess.

What it looks like after a month

The routine categories stop reaching you at all beyond a quick approval pass. The escalations arrive pre-researched, so handling one takes a minute instead of ten. And the receipts accumulate into evidence about which categories the agent has been consistently right on — which is exactly the basis on which you widen its remit.

Common questions

Will it send email without asking me?

Only if you tell it to, per category. The default is draft-and-review: the agent prepares the reply and a human sends it. Most teams keep it that way for anything customer-facing indefinitely.

Does my email get uploaded anywhere?

Not to us. AGNT runs on your machine and talks to your mail provider directly. If you point it at a local model through Ollama or LM Studio, the message content never leaves your hardware at all.

How is this different from Gmail’s built-in filters and smart reply?

Filters match strings and smart reply offers three generic sentences. This reads the full thread, uses your documentation and history, applies your escalation policy, and leaves a receipt showing why it decided what it did.

Give AI a job. Get the proof.