
FlowLeap + Gmail
Your team's inboxes stay theirs. The AI gets its own mailbox, works the correspondence from there, and earns the right to send on its own — one approved draft at a time.
Works with the tools you already use
How the connection works
The AI gets its own mailbox
Not access to yours. We set up or repurpose a mailbox on your domain as the AI's identity, the way you'd give a new junior an address. Clients see a real name on your domain, and every message it has ever sent sits in one mailbox you own and can read.
Your mailboxes connect deliberately, one at a time
Where a workflow needs context from a person's inbox, that person authorises it themselves over standard Google OAuth2 and can revoke it themselves, from their own Google account, without going through us or through IT. We don't use domain-wide delegation for this: it would grant access to every mailbox in the domain, which is more than any of these workflows need. Sensitive inboxes — usually the principal's — stay out until you decide otherwise, and plenty stay out permanently.
Sending sits behind the right person
When the AI acts on someone's behalf, that person owns the approval and the send. We don't put one person's name on mail generated from another person's work.
It learns, then earns autonomy
Everything starts in shadow mode: the AI drafts, you approve, nothing goes out unreviewed. Your approvals and corrections are the training signal, not just a safety net. Once the same kind of item has been approved unchanged around twenty times, the system asks whether it should handle that one on its own. You say when — and you can take it back.
What we don't do
- We don't connect a mailbox nobody has authorised — and the principal's inbox is usually the last one, not the first.
- We don't send anything from a workflow still in shadow mode.
- We don't grant ourselves autonomy. The system asks, you decide, and you can revoke it.
- We don't create or change filters, forwarding or vacation responders on your mailboxes.
- We don't delete mail, and we don't remove it from your mailbox.
Google Workspace domains and Gmail on a custom domain. Shared inboxes handled as Google Groups or delegated mailboxes.
What FlowLeap can do in Gmail
Read
- The AI's own mailbox
- Mailboxes and Google Group inboxes that have authorised access
- Message bodies, threads and full conversation history
- Attachments, including items nested in forwarded chains
- Sent Mail, for tone, structure and precedent
- Your existing labels and stars
Prepare
- Replies drafted on the correct thread, in the right person's voice
- Chase and follow-up sequences, tracked per client
- Documents named, classified and filed to Google Drive
- A per-client action list built from what's actually in the inbox
- File notes recording what was asked, agreed or instructed
Send and act — as itself, or on your approval
- Send from the AI's own mailbox once a workflow is trusted
- Apply labels you've defined and archive what's been dealt with
- Attach captured documents to the matching ledger transaction
- Release a drafted reply — by the person it belongs to, from Gmail, as normal
In shadow mode everything is a draft. As the AI proves a workflow, it starts sending from its own mailbox — every message visible in that mailbox, and the autonomy revocable at any point.
Core workflows
Six workflows we build first on Gmail. Each one is defined down to the parts that actually go wrong.
Document intake from the inbox
ContinuousWhat it does. Watches the AI's mailbox and any authorised Group inboxes for client documents, works out which client and period each one belongs to, names it to your convention, files it to Drive, and queues it against the right transaction in the ledger. Clients and colleagues can simply forward documents to the AI's address — for most practices that becomes the intake route.
What makes it messy
Half of it isn't even an attachment. Clients paste a Drive link instead, often not shared with your domain, so it opens an access-request dance before anyone can read it. Statements arrive as photographs taken at an angle, two slips side by side in one image, invoices three levels down a forwarded chain, several documents in one zip, a body that says “see attached” with nothing attached, the same invoice twice from two addresses, and a sender domain that doesn't match the entity the document belongs to.
What comes back. Filed and named documents matched to client and period, unreadable Drive links flagged with an access request drafted, and the “attachment missing” cases queued for a chase.
The chase loop
ContinuousWhat it does. Works out what's still outstanding against the ledger, drafts the follow-up on the existing thread rather than a fresh email, tracks who has replied and who hasn't, escalates on your schedule, and stops the moment the document actually arrives.
What makes it messy
Three to five follow-ups per client per month is normal, and the worst version is chasing something the client already sent — buried in a thread nobody reopened, or labelled by someone else. Gmail's threading helps until it doesn't: a reply on a six-month-old subject line lands in the wrong conversation entirely. Tone varies by client, and knowing when to stop emailing and phone is judgement.
What comes back. Chases threaded correctly — drafted while the workflow is in shadow mode, sent from the AI's mailbox once it's trusted — plus a live view of who owes what, and no chase sent for a document already in the building.
Repetitive client questions
ContinuousWhat it does. Recognises the questions you answer every month — where's my invoice, what do I owe, is my VAT submitted, can you resend that — pulls the answer from the ledger, and drafts the reply on the thread in the voice of whoever owns that client.
What makes it messy
The question repeats; the answer usually isn't in the email. It needs a live figure from the ledger, and someone has to notice when a routine question is the start of a problem — or a request for advice you should be charging for and shouldn't answer off the cuff.
What comes back. A reply with the figures already in it and the source shown, plus a flag when a question needs a human rather than an answer.
Remittances and payment advices
DailyWhat it does. Picks remittance advices and payment notifications out of the inbox, reads them including the PDF attachments, and proposes the allocation against open invoices.
What makes it messy
Every payer formats a remittance differently, they cover a lump sum across several invoices, they apply deductions or settlement discounts without saying so, or they never arrive at all — leaving a receipt on the bank with a reference that's just a person's name. Often the advice lands days before the money. And the same person frequently pays for more than one entity, so the payer name alone doesn't settle which client it belongs to.
What comes back. Proposed allocations with the remittance attached as evidence, and a shortlist of receipts still waiting on an advice.
Triage and the action list
DailyWhat it does. Turns the inbox into a per-client action list — what was asked, what was promised, what has a deadline — ranked with deadline-bearing items first, and drafts the diary blocks for the work only you can do.
What makes it messy
Commitments live halfway down threads nobody reopens, and a deadline mentioned in passing on Tuesday is invisible by Friday. Most practices run on search rather than filing, so the action list only exists in whichever person happened to read the thread. At small firms the principal is the bottleneck and the inbox is the real task list — anything unseen isn't done, and during provisional tax season nobody is reading anything.
What comes back. A ranked action list per client, deadlines surfaced, and drafted calendar blocks.
File notes and the correspondence trail
ContinuousWhat it does. Records what was asked, agreed and instructed by email against the client record, with the message referenced, so the decision trail exists somewhere other than one person's inbox.
What makes it messy
Client instructions arrive by email and stay there. When a query lands months later, or someone is on leave, or someone leaves the firm, the reasoning is gone — and reconstructing it means searching a mailbox that may no longer be there.
What comes back. Dated file notes against the client, each linked to the message it came from.
Enabled per mailbox, per client, per workflow — you choose what it reads, what it drafts, and what it's eventually allowed to send.
How it starts
We onboard the AI the way you'd onboard a junior: one workflow at a time, simplest first, running in shadow mode beside your team for a couple of weeks until it reliably produces the result your people would have produced. You approve, correct, and watch. When you trust it, you switch that workflow on and we start the next one.
If your team doesn't work in email
Some practices have deliberately moved off email and run everything through a practice management system. If that's you, the inbox is still where clients live even when your team isn't — documents and questions arrive there whether anyone wants them to.
FlowLeap works either way: it can work the mail and surface the results into the system your team already uses, rather than adding another place to look. If a tool doesn't appear inside the workflow people already have open, it doesn't get used. We've seen that often enough to design for it.
What this covers — and what's next
Gmail today
Everything above is Gmail on Google Workspace — the AI's own mailbox, individual mailboxes that have authorised access, Google Group inboxes and delegated mailboxes. Documents pulled out of the inbox are filed to Google Drive and attached to the ledger where the workflow calls for it. Two admin-console jobs need doing before day one: creating the AI's mailbox on your domain, and granting Group inbox access. Both are five-minute tasks, and both are worth lining up in advance — permissions are the single most common thing that delays a start, especially where IT is outsourced. Practices on a personal @gmail.com address rather than a Workspace domain can still connect a mailbox, but there's no admin console, no Vault and no domain-level control behind it, and we'll tell you plainly what you do and don't get before you start.
Calendar, Chat and the rest of Workspace
In buildThe diary side — reading your calendar, blocking time for the action list, handling meeting follow-ups — is a separate scope with its own consent, and it's being built now. Chat as a channel is on the same track. We keep them apart deliberately: mail access and calendar access are different permissions, and bundling them into one blanket authorisation is exactly what a careful admin should refuse.
Processing hundreds of client documents getting tedious?
Book a quick call with us to see how FlowLeap AI can automate your document processing to accounting tasks
Book a 30-minute call