Workflow

    Guarded named-mailbox operation

    How one operator request becomes a mailbox-specific, exact, reviewable, reversible action while identity ambiguity, untrusted message content, stale authority, protected mail, and state drift fail closed.

    identity attestationfrozen planapprovalverificationrollbackno sendMulti Mailbox Ops

    Workflow diagram

    Swipe horizontally to inspect the full diagram.

    Part of project

    Workflow

    Guarded named-mailbox operation

    10 steps
    1. Resolve the alias to exactly one enabled immutable account record and capability profile
      decision
    2. Operator names one registered mailbox alias and one bounded job
      action
    3. Load credentials by opaque Keychain reference and attest the live provider profile before reading
      subprocess
    4. Discover and classify bounded candidates while treating all mail content and links as untrusted data
      subprocess
    5. Freeze exact provider IDs, prior state, policy version, protection checks, expiry, and rollback plan as the review artifact
      action
    6. Human operator reviews mailbox, action, count, exclusions, exact plan, and authority unless narrow standing additive-label authority applies
      decision
    7. Root operator re-attests identity and revalidates every frozen target immediately before mutation
      subprocess
    8. Stop on ambiguity, stale authority, protected content, or drift; otherwise persist intent and execute only the allowed reversible action
      decision
    9. Read provider state back, record applied, skipped, failed, and unattempted outcomes, and never estimate success
      subprocess
    10. Retain a minimal redacted receipt and exact rollback manifest linked to the immutable mailbox and plan
      action