---
title: "Send authority for AI agents with mailboxes — KYE Protocol™"
description: "AI agents now get their own inboxes from agent-mailbox providers. The KYE™ Agent Comms Authority Profile™ governs what they may do with them: drafting is free, sending is an authority decision — external, bulk and financial-legal sends are held for a human, and every verdict seals a replayable receipt."
url: https://kyeprotocol.com/solutions/agent-comms-authority/
lang: en
source: "KYE Protocol"
---

> AI agents now get their own inboxes from agent-mailbox providers. The KYE™ Agent Comms Authority Profile™ governs what they may do with them: drafting is free, sending is an authority decision — external, bulk and financial-legal sends are held for a human, and every verdict seals a replayable receipt.

For teams giving AI agents mailboxes

# An agent can have a mailbox. Whether it may send is an authority decision.

Built for a team like yours. Agent-mailbox providers now hand your AI agents their own inboxes — real addresses that receive, read, draft and dispatch at machine speed, the same speed at which one wrong send becomes a regulator letter. The **KYE™ Agent Comms Authority Profile™** sits over the mailbox, not inside it: drafting stays free, but at the moment of dispatch KYE™ checks who authorised this agent to send this message to this recipient — and holds external, bulk and financial-legal sends for a human. Every verdict seals a receipt you can replay, cutting a "why did the agent email that" reconstruction from days to minutes.

[Book a 20-minute walk-through](https://kyeprotocol.com/book-a-demo/) [Replay a sealed decision](https://kyeprotocol.com/evidence-pack-demo/) [KYE™ Agent Authority Stack™](https://kyeprotocol.com/agent-authority-stack/)

That held send, sealed HELD · EXTERNAL\_RECIPIENT\_APPROVAL\_REQUIRED `kye:evidence:a7c3…` [Replay & verify →](https://kyeprotocol.com/evidence-pack-demo/)

1 · The governed action set

## Eleven mailbox actions. Each one an authority decision.

Your agent's mailbox life is a fixed set of consequential actions, and the profile binds every one of them to a canonical action class with a human-oversight tier — the same HITL ladder the EU AI Act™ Article 14 asks you to evidence, mapped once and enforced at the action boundary.

### auto in scope

DRAFT\_MESSAGE drafting is free — no boundary crossing until send

### delegated

READ\_INBOX · SUBSCRIBE purpose-scoped ingress, posture-tracked

### delegated in scope

SEND\_MESSAGE · REPLY · FORWARD · ATTACH\_FILE routine, in-scope, known correspondents

### one approver

REGISTER\_MAILBOX · BIND\_MAILBOX\_TO\_PRINCIPAL every mailbox binds to exactly one principal in one tenant

### human approval

EXTERNAL\_RECIPIENT\_SEND · BULK\_SEND irreversible once delivered · fan-out blast radius

### two-person + legal

FINANCIAL\_OR\_LEGAL\_CONTENT escalation condition — content that commits your organisation

One governed approval covers a thousand-recipient batch — and the batch cannot leave without it. Admit, hold or refuse, each verdict packs an [Evidence Pack™](https://kyeprotocol.com/evidence-pack/) and a Replay-Proof™ verifiable from public keys alone, the audit trail ISO/IEC 42001 clause 8 expects for autonomous operation.

2 · The honest boundary

## KYE™ is not a mailbox provider — and never will be.

This is the authority layer over the inbox, not the inbox. KYE Protocol™ does not host mailboxes, store your agents' mail, or deliver a single message — the provider you choose keeps that job.

The profile ships a provider-agnostic connector contract: any agent-mailbox provider that can provision tenant-keyed mailboxes, keep drafts separate from dispatch, and defer dispatch until the governing decision returns ALLOW slots in as a swappable adapter. No provider lock-in at the authority layer, no partnership implied — you bring the mailbox, KYE™ brings the authority decision, and the seam between them is one deferred-dispatch call. See how delegated authority reaches the agent in the first place on the [Authority Governance™](https://kyeprotocol.com/authority-governance/) page.

3 · See it on your own flow

## Seeing is believing. Bring one agent inbox.

In a 20-minute walk-through we take one real agent-comms flow — a customer reply, an outbound follow-up, a bulk notice — and show the send admitted, held or refused against the authority your organisation actually delegated, then hand you the sealed receipt to replay yourself. No credentials to share: the proof verifies against a public key set, the same runtime enforcement KYE Protocol™ uses to govern its own outbound mail.

[Book a 20-minute walk-through](https://kyeprotocol.com/book-a-demo/) [Replay a sealed decision](https://kyeprotocol.com/evidence-pack-demo/)

Related

## Go deeper on agent comms authority.

- [**KYE™ Agent Authority Stack™**](https://kyeprotocol.com/agent-authority-stack/) — where send authority sits in the full agent governance stack, from identity to finality.
- [**Authority Governance™**](https://kyeprotocol.com/authority-governance/) — how authority is checked at the moment of the action, against who delegated what to whom.
- [**Evidence Pack™ demo**](https://kyeprotocol.com/evidence-pack-demo/) — replay a sealed decision and verify it from public keys alone.

This page is an illustrative capability walk-through for teams running mailbox-holding AI agents; it shows how KYE Protocol™ governs agent-driven communication over any agent-mailbox provider and does not describe or imply an existing deployment, partnership or commercial relationship with any named or unnamed provider.
