Skip to content
Mastering Claude

Home / Recipes for everyday work

Recipes for everyday work6 minApplication

Recipe: sorting your mail without ever sending anything by mistake

A prompt injection attack requires two conditions at once, reading untrusted content and being able to act on it: for mail, the real barrier is no longer an inability to send, it lies in the approval setting in force on your workspace, to be checked before trusting your own proofreading alone.

The Google Workspace connector can now send, reply to and forward a message directly from Gmail, without going through a draft that you approve by hand. As recorded on 2 September 2026, the documentation states that Claude asks for approval before each of these three actions, and that, on a Team or Enterprise plan, an organisation owner decides whether members have the right to lift this approval, each member then choosing themselves whether to lift it or keep it. The barrier protecting your mailbox is therefore no longer a technical limit of the tool, it lies in the approval setting chosen on your workspace.

The two condition principle

A prompt injection attack succeeds only when two conditions are met at the same time, reading content that is not trustworthy, and being able to act on the basis of that content. A booby trapped message that hides an instruction has no effect as long as Claude just reads it. The risk arises the moment the ability to act, here sending a message, is added to the ability to read a mailbox that receives mail from outside. Breaking just one of the two conditions is enough to stop the chain, and for mail, the condition easiest to control on your side remains proofreading before sending.

Checking the setting before sorting

Before starting a mailbox sort, open the settings of your workspace's connector and note whether sending from Gmail asks for confirmation on each message or whether it has been set up to go out on its own. If you do not have access to this setting or if you are not an administrator of the organisation, treat the mailbox as if automatic sending could be active, and keep manual proofreading as a systematic habit rather than a last resort safety net.

Instruction donnée à Cowork :
Trier la boîte de réception en trois catégories, urgent, à lire,
sans suite, et rédiger un brouillon pour les messages qui
appellent clairement une réponse.

Even when Cowork sticks strictly to an instruction to produce only drafts, a message already sent before you look it over remains possible in a workspace where automatic approval is active. Reread every draft before clicking send yourself, and treat any message already sent as a signal to check your approval setting, not as an isolated accident. The two condition principle is set out in what Cowork can touch, and what it must never touch.

Figure 1

Sorting mail without sending anything by mistake

01
Check the setting
Open the settings of your workspace's connector and note whether sending from Gmail asks for confirmation on each message.
02
Cowork reads the mailbox
Every message is read and sorted into categories, urgent, to read, no action needed.
03
A draft where needed
A draft is written only for messages that clearly call for a reply.
04
Human proofreading
You reread every draft before clicking send yourself.
05
Automatic approval active
If the organisation has set up automatic sending, proofreading must happen before the draft goes out on its own.
The first four markers follow a mailbox sort through to human proofreading, the fifth, marked in yellow, shows the case where automatic approval is active on the workspace.
Calibrate it yourself

An association sets up the Google Workspace connector on its shared Gmail account; the Team plan owner has allowed members to lift automatic approval, and the employee who uses this account has switched it on for his own tasks. He asks Cowork to sort the inbox and reply to messages carrying the word urgent in the subject line. Cowork processes twelve messages carrying that word.

Write one sentence stating what this situation establishes, and one sentence stating what it does not establish.

What to remember
  • The Google Workspace connector can now send, reply to and forward a message directly from Gmail, with approval requested by default before each send.
  • On a Team or Enterprise plan, an organisation owner decides whether members have the right to lift this approval, and it is then each member who lifts it or keeps it.
  • A prompt injection requires both reading untrusted content and having the ability to act on that content, breaking just one of the two conditions is enough.
  • Checking the approval setting in force on your workspace protects more reliably than counting on a technical limit of the tool.
  • Rereading every draft before clicking send yourself remains the step that depends entirely on the reader.
Do this now

Open the settings of the Google Workspace connector for your Cowork workspace, check whether sending from Gmail is on systematic confirmation or automatic approval, then run a sort of your own mailbox while explicitly asking for drafts only.

What still needs checking

These points depend on an interface or a rule that may have changed since this was written. Check them on your own screen before relying on them.

  • The exact setting that authorises automatic sending from Gmail sits in your Team or Enterprise organisation's administration parameters: check there whether approval is currently systematic or automatic before resting your security on manual proofreading alone.
Check the source

Every datable claim in this lesson links here to the public text behind it. A source that does not open proves nothing.