Guarded named-mailbox operation
How one operator request becomes a mailbox-specific, exact, reviewable, reversible action while identity ambiguity, untrusted message content, stale authority, protected mail, and state drift fail closed.
Workflow diagram
Swipe horizontally to inspect the full diagram.
Part of project
Multi Mailbox OpsParent project
Guarded named-mailbox operationThis workflow
Workflow diagramRendered with the workflowWorkflow
Guarded named-mailbox operation
- Resolve the alias to exactly one enabled immutable account record and capability profiledecision
- Operator names one registered mailbox alias and one bounded jobaction
- Load credentials by opaque Keychain reference and attest the live provider profile before readingsubprocess
- Discover and classify bounded candidates while treating all mail content and links as untrusted datasubprocess
- Freeze exact provider IDs, prior state, policy version, protection checks, expiry, and rollback plan as the review artifactaction
- Human operator reviews mailbox, action, count, exclusions, exact plan, and authority unless narrow standing additive-label authority appliesdecision
- Root operator re-attests identity and revalidates every frozen target immediately before mutationsubprocess
- Stop on ambiguity, stale authority, protected content, or drift; otherwise persist intent and execute only the allowed reversible actiondecision
- Read provider state back, record applied, skipped, failed, and unattempted outcomes, and never estimate successsubprocess
- Retain a minimal redacted receipt and exact rollback manifest linked to the immutable mailbox and planaction