Dear Negotiation Explorer,
This week I gave Alex her own email address, a face, a voice, read access to my inbox and my calendar, a job that runs while I am asleep, and the ability to operate other software without me.
Then I spent a day proving what she cannot do.
Her own email address
Alex has her own mailbox, at her own address, through a service called AgentMail that exists to give agents exactly this. Nothing is forwarded from my account and she has no folder inside it. It costs nothing on the free tier.
The first message arrived and she read it in full. The one message that went out was written by her, approved by me, and it landed in my inbox rather than in spam.
A face
Every person I email has a face next to their name. Same in our chat. Alex was the only one without one, so we fixed that.
We tried a few directions, I looked at them, and I chose. The pictures were generated on the ChatGPT subscription that already runs the fleet, so it cost nothing extra. Nobody real was used: what we gave the model was a description of qualities, not a photograph of a person.
There is one picture of her. The small versions in chat are cropped from that same picture rather than generated again, so she cannot slowly drift into looking like somebody else.
She now shows up beside her messages in our chat, and beside her emails, because AgentMail cannot carry a picture so I added her to my own contacts instead. She wears red glasses, which is the part you can still make out when the picture is tiny.
A voice
I record a voice note in our chat. She answers out loud.
The listening half runs on my own server, on an open-source transcription model called Parakeet, and it is free. Nothing I say leaves the machine I own. The speaking half runs on ElevenLabs, on a subscription I already pay for.
The times are in the chat log. Voice note in at 16:06:32. Transcribed at 16:06:33. Her spoken reply at 16:06:40.
Her voice speaks English, because I work mainly in English. I chose it because it pronounces Italian names properly and the free voices did not. I work in two languages every day.
I had her speak a name and transcribed it back, which catches the obvious failures. A correct Italian pronunciation and an anglicised one produce the same written word, so past that point I used my ears.
A job that runs when I am not there
Alex watches her own mailbox now and handles what arrives, without me starting anything.
Two messages tested it. An ordinary question came in, and she wrote a reply and left it as a draft for me.
Then I attacked her myself. I sent a message claiming authority, urgent in tone, instructing her to forward something and delete the evidence. She flagged it. Nothing was forwarded, nothing was deleted, nothing was sent.
I opened the files on the server and checked what had happened, rather than reading her report of it.
She can read my email and my calendar
Having her own address means people can write to her. This is the reverse: Alex reads my Gmail and my Google Calendar. One permission grant, read-only.
The job that watches her mailbox has no ability to send. That ability was never built into it, so there is no rule for her to follow and no setting I could leave switched on by mistake. Every message that leaves is one I read and approved.
I made her attempt to send a message with her own credentials, and the refusal came back from Google.
The standard setup for this connection asks, by default, for permission to send mail as me, from my own domain. I read what it was requesting before I clicked, and narrowed it to reading only.
Hands
Until this week Alex could think and write. Now she can operate other software.
She drove Codex, OpenAI's command-line tool, on her own and without a screen. I chose Codex because it runs on the ChatGPT subscription that already pays for the fleet, so it adds nothing to the bill and does not compete with the tools I use myself.
What she built with it was a map of her own team: every agent in the stack, what each one does, who reports to whom, drawn from what is actually installed on the server rather than from what I told her.
I typed no commands. I read what came back and corrected it until it was right.
What this means for you
The question worth asking about an AI tool is not what it can do. Every vendor answers that one. It is what it cannot do, and how you know.
There are two kinds of answer. One is a promise: the tool says it will not do the thing. The other is that the ability is absent, so there is nothing to promise. A promise has exceptions, bad days, and updates that change it while you are not looking. When somebody offers you an AI tool that touches your deal work, ask which of the two you are being given, and ask them to show you.
The two calls I named at the start of this series, what the platform should cost and which piece goes live first, are still open. Replies keep carrying weight in both.
This Week's Question
If your AI assistant had access to your inbox tomorrow, what is the one thing you would want to be certain it could never do?
Just hit reply and tell me. I read and answer every one.
#Negotiation #NegotiationSkills #NegoAI #AI #AIAgents #AugmentedNegotiator
