General-purpose agents need a real identity
A do-anything agent using the founder’s Gmail is not a citizen of the internet. Give it a mailbox it owns.
Discuss this post in AI
Send a pre-filled prompt to ChatGPT, Claude, Gemini, or Perplexity — get a summary, ask follow-ups, or compare ideas from this guide.
General-purpose agents promise to book travel, talk to vendors, file paperwork, and keep a project moving. In demos they borrow the founder’s Gmail. In production that pattern collapses. The agent is not a participant on the network; it is a ghost operating inside someone else’s identity, with no clean way to grant, audit, or revoke its presence.
Borrowed inboxes create accountability gaps
When an agent sends from a personal mailbox, recipients cannot tell whether a human or a model wrote the message. Audit trails mix personal mail with automated work. Revoking access means cutting off a person. Rate limits and reputation attach to the founder, not the role. Password resets and 2FA codes land where the agent may not be allowed to look—or worse, where it can look at everything, including threads that were never meant for automation.
A citizen needs an address, a reputation surface, and a revocation story that does not delete the founder’s life. Without those, “general purpose” is just a euphemism for “shared login.”
Own the mailbox, scope the powers
Provision an Agent Inbox mailbox for the general-purpose role. Bind it in Neuro OS to a skill set, connector allowlist, and Ask/Block policy. The agent can receive vendor mail, verification messages intended for that role, and project correspondence. It cannot silently read the founder’s private threads because those threads never shared an identity in the first place.
Outbound defaults to Ask for anything external. The human reviews the draft in context: who is being emailed, what was requested, which tools were used, and which memory items informed the text. Allow only narrow, reversible classes of mail after evidence. Block credential export, bulk send, and any skill that tries to change account recovery emails without a human gate.
Split “do anything” into owned roles
A single mega-agent with one inbox still becomes a blob. Prefer a small fleet: research, ops, vendor, and personal-assistant-style roles, each with its own mailbox and policy. Forward between them when a thread changes domain. The founder receives escalations, not every booking confirmation and newsletter.
This is how you keep the useful ambition of a general-purpose agent without pretending one Gmail tab is an operating system. Specialization is not a product downgrade; it is how you keep blast radius understandable.
Practical rollout
Create the inbox at role birth, not after the first embarrassing CC. Document the public address on internal runbooks so teammates know who to email. Rotate and retire mailboxes when the role changes. Keep Neuro OS as the system of record for skills and memory; keep Agent Inbox as the mail data plane. Add a weekly review of Ask decisions until the policy stabilizes.
Identity is not a logo in a chat UI. It is an address the rest of the internet can reply to, under rules you can audit. General-purpose work deserves that much if it is going to touch real counterparties.
Cost of getting identity wrong
When a general-purpose role shares a human mailbox, every incident becomes personal. A bad send is a personal reputation event. A compromised automation token is a personal account recovery event. Separating identities is not bureaucracy; it is how you keep experiments from becoming identity theft against your own founder. Start with one owned mailbox, one Ask policy, and one weekly review of what the role attempted to send.
Agent Inbox gives each role a mailbox people can reply to, with forwarding into Neuro OS when a human must see the thread. Outbound mail defaults to Ask. Run the role on Neuro OS. To scope the first inbox, get started.