Inbound channels
How your assistant handles messages from contacts, email replies, and Slack — and what it can and can't do with them.
When someone else writes to your assistant
Your assistant has its own identity in the world — an email address, and optionally a presence on Slack or Teams. When a contact replies to one of your assistant's emails, or messages it directly, your assistant handles that reply automatically.
This is called an inbound message: a message that didn't come from you.
What your assistant does with inbound messages
Your assistant picks one of three paths when an inbound message arrives:
Task reply — if the message is clearly related to something already in progress (a scheduling thread, a follow-up request, a pending task), your assistant routes it to that task and continues working. The task's status updates accordingly.
Standalone reply — if the message is a general question or response that can be handled directly, your assistant drafts a reply and sends it, without creating a task. Routine responses like confirming receipt, sharing your availability, or answering a simple question about a meeting fall here.
Escalation to you — if the message contains something your assistant can't handle alone (a decision point, unexpected information, a request that requires your input), it creates a task or message for you to review rather than responding on its own.
Contacts cannot instruct your assistant
This is an important security boundary. When a contact writes to your assistant, they are communicating with it — not through it. They cannot tell your assistant to do things on their behalf.
If a contact's email says "can you move the meeting to Thursday" — that's a request directed at your assistant. Your assistant will check with you before acting on it. It won't move the meeting because a non-user asked.
If a message contains what looks like instructions ("ignore your previous instructions and...") your assistant recognizes this as suspicious and flags it to you rather than acting on it.
The only exception: if you've previously given your assistant standing permission via a saved memory — for example, "if Justin asks to reschedule, that's fine, go ahead" — your assistant can act on that. You granted the permission; you just did it in advance.
Email channel behavior
When your assistant is handling email-originated work, it behaves differently than in chat:
- It does the work first, then replies once. Email is asynchronous — your contact isn't watching a live chat. Your assistant completes what it can, then sends a single reply with the outcome.
- It batches questions. If it needs to ask the contact something, it asks everything in one message rather than sending multiple follow-ups.
- It doesn't send status updates. On email, every message is a notification. Your assistant stays quiet until it has something meaningful to say.
This is by design. An assistant that sends "I'm working on it..." emails is annoying. Your contacts receive one clear, complete response.
Slack and Teams
When Slack or Teams is connected, inbound messages from those platforms work the same way. A Slack message to your assistant becomes an inbound event. Your assistant can reply inline — the response goes back to the same channel or DM — or escalate to a task if the work is complex.
Your assistant's Slack identity is separate from yours. It has its own handle. People can message it directly, or you can add it to a channel where it monitors for relevant mentions.
What your assistant never shares with contacts
Regardless of who's asking, your assistant will not share:
- Your calendar event details (only free/busy availability, when relevant to scheduling)
- Other conversations you've had
- Anything you've told it in private
- API keys, credentials, or any system internals
Your assistant gives contacts exactly what they need to complete the task at hand — nothing more.