Two sales meetings, a day apart. Two businesses in unrelated industries, different sizes, different problems, no connection to each other.
Both owners asked the same thing first. Not what it costs. Not what it can do.
One asked whether we could set it up so that exactly one named person — and nobody else — could trigger an email to a client. The other, whose work is confidential by nature, asked whether there was any chance of messages going out to a list.
One of them asked it midway through a full walkthrough of the software, with the whole feature list running in front of them. It was still the first thing they wanted to know.
The question underneath both, and it is the real one: will this thing do something on its own?
That is not a question about AI. It is a question about who holds the keys.
Once you have heard it twice in a day from people with nothing in common, it stops looking like caution and starts looking like the actual buying decision. Every other question — cost, features, how long setup takes — is downstream of it. An owner who thinks the software might email a client unbidden is not evaluating your feature list. They are calculating what it costs them the first time it happens.
The honest answer is not that it’s safe, don’t worry. Safe is a promise, and a promise is exactly the thing the owner has no way to check.
Three questions worth putting to any vendor, including us
Does it read, or does it also write? An assistant that reads your inbox and one that can send from your address are different products with the same demo. The distinction rarely survives a sales conversation intact, so make someone say it out loud. Wherever email is involved at all, our standing recommendation to customers is the read-only side of that line: let it read, don’t give it your outbox.
When something does go out, whose words are they? There is a large difference between a message the model composed in the moment and a message you wrote in advance that the system sent on cue. The second you can review before it exists. The first you can only review afterward — which is to say, after the customer already read it.
Who decided what this person can reach — you, or the model? This is the one that gets skipped. In our case: what each person can reach is enforced on our side, not chosen by the AI. Access is set per person, by you, and the model does not get a vote in it. If a vendor cannot tell you where that boundary is enforced, that is your answer.
None of that is a claim about how clever the AI is. It is a claim about where the walls are, and walls are the kind of thing you can go look at.
Why we can afford to keep the AI in a small box
There is a structural reason many tools cannot give you that answer, and it has nothing to do with their engineering.
You bring your own model to our product. Your Claude account, your ChatGPT account, whatever you already trust. We do not resell it, and we do not take a margin on what you spend with them.
Now look at the alternative. When a vendor bundles the model into the subscription, their cost is the model call and their revenue is the seat. Margin lives in the gap. That is a perfectly legal business, and it produces one predictable pressure: a product whose economics improve when more of your work routes through the model has no reason to route less of it. Nobody has to be cynical for that to shape a roadmap.
We do not have that gap, so we do not have that pressure. When the right answer is that the AI should stay out of a workflow entirely, we can just say so and lose nothing. That is not virtue. It is what the incentive happens to be, which is sturdier than virtue.
Which is also why you should not take our word for any of it. How a vendor makes money predicts more about how their product behaves in a year than any feature list they show you.
Trust is a configuration, not a promise
A promise is something a vendor makes and you hope holds. A configuration is something you can open, read, change, and check again next month after someone new joins.
So when you are across the table from any vendor, us included, two last questions do the rest. Who profits when the AI touches more of my business? And then: show me the setting, not the policy.
The first tells you which way the product drifts when nobody is watching. The second is the one that ends the conversation early, because a policy can be written the night before your meeting and a setting cannot. If the answer is a paragraph instead of a screen, you have learned something.
Both owners were asking for exactly that, a day apart, without knowing the other existed. They just phrased it as a question about email.