ARKONE
← All questions
Questions for the Vendor, No. 30The Directory · the approved-contact list4 minute read

Who is on the list of people it may speak to, and what happens when a stranger emails it?

A short list of named people is the difference between an agent your company uses and an address the internet can talk to.

Who is on the list of people it may speak to, and what happens when a stranger emails it?

Two answers to this exist, and one is a list. Ask for it, and either somebody opens a page with names on it, or the conversation turns to filtering, spam and domains, which answer a question you did not ask. The difference decides whether you are buying a tool your staff use or an address the outside world can reach and be answered by.

A list, and the silence around it

In ArkOne’s reference design for an executive agent, the Cabinet, the list is the Directory: one entry per real person, carrying the addresses they write from, the approvals they hold, and their working hours. It is set out in the paper on the Directory, with its settings on the Register.

The rule for anyone absent from it is short. A message from an unrecognised sender is dropped, with no reply, and the attempt goes to the ledger where every action and its reason are written and never edited. Not declined and not apologised to, because a decline confirms the address is live and attended by software.

The name typed at the bottom plays no part. Recognition is by the address a message came from, matched against the entries, which is why a note signed with your own name from an address that is not yours gets the same silence as a stranger. The protection has an honest price: a genuine new contact hears nothing at all, so the agent’s address must never be published as a route into your company.

Three descriptions of the same doorway

Suppose you ask it late in a call, once the demonstration is over and a laptop is being packed up.

What a good answer sounds like What you will be offered instead What that hides
A page of named entries you can open, with the addresses each person writes from It responds to anyone in your company Everybody on one list, with no approval rights distinguished. Ask what your newest joiner can ask it to do on their first afternoon
An unknown sender is dropped and the attempt is recorded Access is restricted to your company domain A domain, which is a boundary an address can be forged into. Ask what it does with an internal-looking message from outside
A request only counts because of where it came from, never because of the name signed at the bottom Spam and phishing are filtered before it sees anything Filtering, which grades likelihood. The question was whether a sender must be on a list before instructions are taken from them

Exhibit 1. Illustrative. Three replies about the roster, and who each of the weaker two lets into the room.

The first row is the answer most companies accept, and it is a real boundary. It is also the widest version of one: everybody on the payroll, treated identically, in a system able to write to clients. Approval rights and a roster are separate ideas and it answers for both, which is how a graduate’s request comes to carry the standing of your finance director’s.

The third row is the interesting confusion. A filter is useful and sits in front of the wrong problem. It asks how likely a message is to be malicious; a roster asks whether the sender is a person the room knows. A careful note from an unlisted address passes the first test and fails the second, and the second decides whether anything happens.

Test it yourself, twice

The follow-up is short. Send it something yourself, from a personal address, asking for something plausible, and see whether anything comes back.

That takes a minute and settles the main point. Then send a second, signed with the name of somebody senior at the vendor, still from your personal address. You want the same silence, because a system reacting differently to the second is deciding on the strength of prose rather than of an identity.

Then ask what the tests cannot cover: who reads the drops. The record fills with people the agent turned away, and among them, eventually, a real client writing to the wrong address at a bad moment. A vendor with an answer names a screen and a person. A vendor without one built the safer rule and left its cost unowned, and that cost lands on whoever your client complains to. Read it beside the line naming who it is talking to, the same mechanism from the inside.

A list of names is a modest thing to ask a supplier for and a hard thing to fake. Either it exists and can be opened, or the conversation moves to filters.

component: answer-card

Asked plainly

Can anybody who finds an AI agent's email address get a reply from it?

That depends on one design decision. Where the agent checks each sender against a list of named people and drops anything else, a stranger gets nothing. Where it answers whoever writes, or answers anyone inside the company's own domain, its address is a working channel for anybody who can guess or forge one.

What should an AI agent do with an email from someone it does not know?

Drop it without a reply, and write the attempt down so a person can see who was turned away. Replying to an unknown sender, even to decline, confirms that the address is live and answered by software. The cost of dropping is real, which is that a genuine new contact hears nothing, so the address should never be published as a way to reach the company.

Why does it matter which people are on an AI agent's list?

Because the list is what turns instructions arriving by email into instructions from a person with standing. Without it, the text of a message is the only thing deciding whether it is obeyed, and text is the one part of a message anybody can write. With it, a request only counts if it came from an identity already recorded against a named colleague.

Talk it through before you decide

A discovery call, no deck: your situation, the parts of the room it touches, and what you would need to decide first.