Your superagent needs an inbox it owns
A squad of roles, one owned mailbox each, zero-touch threads where policy allows, and Ask on every external send that matters.
Discuss this post in AI
Send a pre-filled prompt to ChatGPT, Claude, Gemini, or Perplexity — get a summary, ask follow-ups, or compare ideas from this guide.
“Superagent” usually means a coordinator that decomposes work across specialists. The demo looks like one chat that can do everything. Production looks like a squad of roles with clear ownership. Email is where that ownership becomes visible to the outside world. If the squad shares one mailbox—or worse, a founder’s—the superagent never truly owns its work; it only narrates work happening in someone else’s identity.
Squad first, mailbox per role
On Neuro OS, define the coordinator and the specialists as git-backed roles: intake, research, drafting, vendor ops, and escalation. Give each specialist an Agent Inbox mailbox when the role is created. The coordinator routes tasks; it does not impersonate every specialist’s identity on the wire. Counterparties reply to the role that should answer, which keeps context and reputation aligned with the skill that will handle the next step.
This structure supports zero-touch threads for low-risk classes of mail after you have evidence. A vendor confirming a meeting time can be handled end-to-end. A vendor changing payment details cannot. Policy encodes the difference in Allow/Ask/Block rather than in a prompt that hopes for the best.
Minutes, not hours
The operational win is latency with accountability. When a reply stays on the correct thread, the specialist role already has context, memory, and connectors. Teams typically see cycle time drop from hours to minutes once that pattern holds. The coordinator watches queues and escalations instead of pasting between tabs and guessing which specialist “owns” a CC line.
Measure touch rate: what fraction of threads required Ask, what fraction completed under Allow, and what fraction forwarded to humans. Improve skills where Ask is repetitive and correct. Tighten policy where Ask catches real mistakes. Publish those metrics next to the squad diagram so “autonomy” is a measured state, not a vibe.
Ask on external send
Default outbound to Ask until the squad earns Allow for narrow templates. Show the human the draft, the role, the thread, and the tool calls that informed it. Block mass outbound from coordinator privileges. Forward relationship-sensitive threads to a named owner rather than letting the model “sound like the CEO” from a shared identity.
Why ownership beats a shared send API
A shared transactional send API can blast messages. It cannot receive replies into the right specialist context. Two-way inboxes make the superagent a participant. Forwarding into Neuro OS keeps humans in the loop without collapsing identities when a case spans research and vendor ops.
Build the squad, provision the mailboxes at role birth, and treat email as a first-class channel beside chat. Retire mailboxes when roles retire. A superagent without owned inboxes is a router with no citizenship on the network where most external work still happens.
Failure modes to design for
Watch for three failure modes: the coordinator sending as every specialist, specialists sharing one inbound alias “for simplicity,” and Ask fatigue that pushes teams to Allow everything. Counter them with per-role mailboxes, sampled review of Allow traffic, and a hard Block list for money, legal claims, and credential changes. The squad stays fast when the exceptions remain visible and rare.
Agent Inbox gives each role a mailbox people can reply to, with forwarding into Neuro OS when a human must see the thread. Outbound mail defaults to Ask. Run the role on Neuro OS. To scope the first inbox, get started.