XavierFok
← all posts

I let an AI triage my messages, with one rule that never moves

2026-08-15 · by Xavier Fok

# I let an AI triage my messages, with one rule that never moves

I used to open my messages each morning with a small, familiar dread. No single message was the problem. The problem was volume, spread across email and a couple of chat apps, with two or three items buried in the pile that genuinely needed me that day and no fast way to find them.

A few months ago I did the thing that sounds reckless when said out loud: I let an AI read my incoming messages and draft replies. It saves me real time daily. It stays safe because of one rule I set on the first day, and everything below is really an explanation of that rule.

Two jobs, and only two

The assistant has exactly two capabilities. It reads incoming messages across my email and chat apps, and it writes draft replies that sit in a holding area waiting for me.

The load bearing word is draft. It cannot send. It cannot delete. It cannot forward. Nothing it produces can reach another human being through any path that skips me. Every draft waits until I have read the exact words and pressed send myself. That boundary is the reason the rest of this setup exists at all, and I will come back to why it never gets relaxed.

The sorting was always the hard part

The capability that returns the most time surprised me, because it is the least glamorous: plain triage. Each morning the assistant looks at everything that arrived overnight and tells me, in ordinary language, which few messages actually need me today, which handful can wait for the weekend, and which pile is newsletters, receipts, and notifications I can ignore outright.

That sounds minor and is not. The heavy part of a full inbox was never the replying. It was the deciding, the low constant hum of wondering whether something important was sitting unread in the noise. Handing that first pass to something that never gets tired removed a weight I had stopped noticing I carried.

Twenty messages, one honest sentence

The second capability is thread summarizing. Everyone knows the thread: two weeks old, twenty messages deep, three people added midway, and you get pulled in at message nineteen with no idea what was decided.

I point the assistant at the whole mess and ask what the current state is and whether anyone is waiting on me. It reads the history and answers in a sentence or two. Imperfect, to be clear. It sometimes misses tone, and it has flattened a joke into something that read as serious. So I treat the summary as a map. It tells me which small slice of the thread deserves a close read, and for anything that matters I go read that slice myself. Ten seconds of orientation instead of ten minutes of scrolling, with my own eyes still on the part that counts.

The draft kills the cold start

The third capability gets the most attention, so it deserves the most care. The assistant writes a first draft of a reply, in roughly my tone, for the messages that are pure friction. A reschedule request. A quick yes or no. A short answer to a clear question.

Half the time I send the draft with a small tweak. The other half I rewrite it, because the tone landed slightly wrong, or it agreed to something I did not want to agree to, or it lacked a piece of context that lived only in my head. Both halves are fine. A draft I edit still beats a blank reply box by minutes, every single time. The value is the removed cold start.

Why sending stays behind my yes

Now the rule. The assistant can read everything I have connected and draft anything it likes, and it can never act on the outside world without my explicit yes. Not for an easy message. Not when it is almost certainly right. Not once.

Reading is a low stakes act. The worst case of reading is that it sees something and tells me. Sending belongs to a different category entirely, because a sent message cannot be unsent. There is no undo on an email sitting in someone else's inbox.

The temptation arrives after the hundredth good draft: why stay in the loop for the easy ones. Run the numbers on that trade. Letting it send saves roughly two seconds per message, the glance and the click. In exchange, a system that misjudges tone some fraction of the time gains the ability to speak to real people as me, with no chance for me to catch it first. One confidently wrong message, sent in my name to the wrong person, unseen by me, outweighs months of saved clicks. The rare miss costs too much for the tiny saving to ever cover.

The quieter reason

There is a second reason the rule holds, and it took me longer to articulate. The moment something sends on your behalf, you stop reading. That is simply how people work. Once the machine handles the easy messages, you stop opening the easy messages, and you slowly lose track of what is going out under your name. The easy messages are exactly where a subtle mistake hides longest, because nobody is looking at them.

So the two seconds I spend on each draft buys more than error catching. It keeps me connected to my own conversations. I always know what I have agreed to, because I read every word that leaves.

What never gets connected

The send rule is the first layer. The second layer is about access, and it is a shorter conversation: some things never touch the assistant at all.

It has no connection to banking. It sees nothing financial. It has no access to passwords or to any account that holds or moves money. On the messaging side, the genuinely private conversations, the personal ones, the legal and medical ones, are walled off entirely and the assistant does not know they exist.

The test I use is blunt. If the wrong eyes reading a message, or a wrong reply going out, could cost real money or trust I cannot rebuild, that conversation stays with me. Convenience never wins that comparison.

Ask where the words travel

One more question matters more than how smart any of this is: where do the messages physically go. To read your inbox, a system has to process your words somewhere, and there are two basic answers. Everything stays on your own machine, processed locally, leaving nothing. Or your messages travel to a company's servers, get processed there, and the results come back.

Both can be reasonable. They are very different promises. For the most private material, local processing is the only arrangement I accept, because words that never leave the machine cannot leak from someone else's breach. For lower stakes triage, a reputable cloud service can be acceptable, provided you actually find out what happens to your data. Do they keep the messages, and for how long. Do they train models on them. Can you delete everything when you leave. Vague or buried answers are themselves an answer. The real mistake is pointing an AI at your entire private inbox without ever asking the question.

Start small, or wait

Who should build this. Anyone comfortable with a little setup who genuinely understands the difference between letting a system read and letting it act. The returned time is real and it compounds.

Who should wait. Anyone who suspects they would let it send the easy ones after a good week. And anyone who had never considered where their messages travel until this paragraph. The people who get burned wire everything in on day one, grant send, and point it at their most sensitive account because a video made it look simple.

Start with read only triage on the inbox you care about least. Keep every send behind your own yes. Extend trust one deliberate step at a time. The drafting will keep getting better, which makes the rule matter more each month, because better drafts make checking feel less necessary right up until the day it was.

More honest write ups of setups like this live at [xavierfok.com](/).

Get new guides and videos first — join the Telegram channel.