The problem: you want an agent to handle email, but you don’t want it deleting everything. You want it to write code, but not commit to main. You want it to be proactive, but not reckless.
Most systems give you two choices: full access or none. That’s not how human trust works.
The All-or-Nothing Trap#
“Give the agent access to my email.”
Now it can:
- Read your inbox
- Send messages on your behalf
- Delete conversations
- Forward sensitive threads
You wanted it to filter spam. But the permission model doesn’t understand nuance.