How the connection works

  1. The AI gets its own mailbox

    Not access to yours. We set up or repurpose a mailbox on your domain as the AI's identity, the way you'd give a new junior an address. Clients see a real name on your domain, and every message it has ever sent sits in one mailbox you own and can read.

  2. Your mailboxes connect deliberately, one at a time

    Where a workflow needs context from a person's inbox, that person authorises it themselves over standard Google OAuth2 and can revoke it themselves, from their own Google account, without going through us or through IT. We don't use domain-wide delegation for this: it would grant access to every mailbox in the domain, which is more than any of these workflows need. Sensitive inboxes — usually the principal's — stay out until you decide otherwise, and plenty stay out permanently.

  3. Sending sits behind the right person

    When the AI acts on someone's behalf, that person owns the approval and the send. We don't put one person's name on mail generated from another person's work.

  4. It learns, then earns autonomy

    Everything starts in shadow mode: the AI drafts, you approve, nothing goes out unreviewed. Your approvals and corrections are the training signal, not just a safety net. Once the same kind of item has been approved unchanged around twenty times, the system asks whether it should handle that one on its own. You say when — and you can take it back.

What we don't do

  • We don't connect a mailbox nobody has authorised — and the principal's inbox is usually the last one, not the first.
  • We don't send anything from a workflow still in shadow mode.
  • We don't grant ourselves autonomy. The system asks, you decide, and you can revoke it.
  • We don't create or change filters, forwarding or vacation responders on your mailboxes.
  • We don't delete mail, and we don't remove it from your mailbox.

Google Workspace domains and Gmail on a custom domain. Shared inboxes handled as Google Groups or delegated mailboxes.

What FlowLeap can do in Gmail

Read

  • The AI's own mailbox
  • Mailboxes and Google Group inboxes that have authorised access
  • Message bodies, threads and full conversation history
  • Attachments, including items nested in forwarded chains
  • Sent Mail, for tone, structure and precedent
  • Your existing labels and stars

Prepare

  • Replies drafted on the correct thread, in the right person's voice
  • Chase and follow-up sequences, tracked per client
  • Documents named, classified and filed to Google Drive
  • A per-client action list built from what's actually in the inbox
  • File notes recording what was asked, agreed or instructed

Send and act — as itself, or on your approval

  • Send from the AI's own mailbox once a workflow is trusted
  • Apply labels you've defined and archive what's been dealt with
  • Attach captured documents to the matching ledger transaction
  • Release a drafted reply — by the person it belongs to, from Gmail, as normal

In shadow mode everything is a draft. As the AI proves a workflow, it starts sending from its own mailbox — every message visible in that mailbox, and the autonomy revocable at any point.

Core workflows

Six workflows we build first on Gmail. Each one is defined down to the parts that actually go wrong.

Enabled per mailbox, per client, per workflow — you choose what it reads, what it drafts, and what it's eventually allowed to send.

How it starts

We onboard the AI the way you'd onboard a junior: one workflow at a time, simplest first, running in shadow mode beside your team for a couple of weeks until it reliably produces the result your people would have produced. You approve, correct, and watch. When you trust it, you switch that workflow on and we start the next one.

If your team doesn't work in email

Some practices have deliberately moved off email and run everything through a practice management system. If that's you, the inbox is still where clients live even when your team isn't — documents and questions arrive there whether anyone wants them to.

FlowLeap works either way: it can work the mail and surface the results into the system your team already uses, rather than adding another place to look. If a tool doesn't appear inside the workflow people already have open, it doesn't get used. We've seen that often enough to design for it.

Security and control

Its own identity, its own audit trail

The AI sends from its own mailbox on your domain, so everything it has ever produced sits in one place you own and can read. Nothing goes out from a person's account without that person behind it.

Autonomy is granted, never assumed

Every workflow starts in shadow mode. Sending rights are earned per workflow, offered by the system after a run of consistent approvals, and switched on by you. Revoking them is one decision, not a migration.

Your mail stays in Google

We don't build a copy of your mailbox somewhere else. We read what a workflow needs, when it needs it, and we respect the Vault retention and data-loss rules your domain already applies. Access to a person's mailbox is per-mailbox and revocable by that person.

Your voice and your judgement stay yours

Drafts are written from your own precedent, and nothing is asserted to a client that the responsible person hasn't seen while a workflow is still proving itself. When the AI isn't sure, it says so rather than guessing confidently.

What this covers — and what's next

Gmail today

Everything above is Gmail on Google Workspace — the AI's own mailbox, individual mailboxes that have authorised access, Google Group inboxes and delegated mailboxes. Documents pulled out of the inbox are filed to Google Drive and attached to the ledger where the workflow calls for it. Two admin-console jobs need doing before day one: creating the AI's mailbox on your domain, and granting Group inbox access. Both are five-minute tasks, and both are worth lining up in advance — permissions are the single most common thing that delays a start, especially where IT is outsourced. Practices on a personal @gmail.com address rather than a Workspace domain can still connect a mailbox, but there's no admin console, no Vault and no domain-level control behind it, and we'll tell you plainly what you do and don't get before you start.

Calendar, Chat and the rest of Workspace

In build

The diary side — reading your calendar, blocking time for the action list, handling meeting follow-ups — is a separate scope with its own consent, and it's being built now. Chat as a channel is on the same track. We keep them apart deliberately: mail access and calendar access are different permissions, and bundling them into one blanket authorisation is exactly what a careful admin should refuse.

Talk to us about your inbox →

Processing hundreds of client documents getting tedious?

Book a quick call with us to see how FlowLeap AI can automate your document processing to accounting tasks

Book a 30-minute call