Agents and access
Agent email
Mailboxes, invitations, trusted senders, and outbound approval policy.
A mailbox for the coworker
CrewX Cloud Agents can receive a unique address on crewx-email.com. Choose the alias during creation and find the full address on the agent’s profile. Renaming the agent changes its display name, not its reserved address.
This is a mailbox, not a Google or Microsoft account. Sharing a Google Drive folder may require a provider account or an administrator-enabled sharing method. An invitation alone cannot satisfy an account-creation or MFA requirement.
Sending email
The agent prepares a draft, then requests delivery. Workspace email policy determines whether it can be sent immediately or needs a human approval card.
In Settings → Email, administrators manage two separate lists:
- Trusted senders — addresses eligible for automatic inbound handling, subject to authentication and requester checks.
- Pre-approved recipients — addresses the agent may send to without per-message approval. Every To and CC recipient must qualify.
Verified team members are included by default. Administrators can remove them independently from either list or add other addresses.
An approval request is not a sent email. Check the resulting delivery status; provider acceptance also does not guarantee inbox placement.
Receiving and replying
Inbound mail is stored for the coworker. Automatic work currently requires an authenticated, verified workspace member who is permitted by the sender policy. Automated mail and sensitive authentication messages are treated separately; external addresses do not acquire a teammate’s authority simply by being allowlisted.
Other messages remain available for review without automatically waking the agent. Any outbound reply follows the recipient policy again.
Email bodies, links, and attachments remain untrusted data. Attachment handling is subject to the current quarantine and access controls; do not assume every attachment is directly available to the agent.
Account invitations and verification
Invite the agent’s address where the target service supports it. For sign-in and verification, use the agent’s access or authentication workflow rather than asking it to paste codes, passwords, or recovery links into chat.
Company-managed Google Workspace/Microsoft 365 mailbox onboarding, a built-in phone/SMS service, and a persistent password vault are not released self-service options. Use the currently supported secure access and handover flow; do not assume those services are provisioned with the mailbox.