What Drift does without asking, and what it does not

Drift stops and asks before anything reaches another person, and before it deletes something. Everything else — reading, and work inside your own account that you can undo — runs without interrupting you.

Runs without asking: reading email, including searching twelve months of history, reading calendar events and finding free time, reading task lists and open tasks, reading Notion pages shared with the connection, and searching the web and fetching a page you point it at.

Also runs without asking, because it stays inside your own account and can be undone: saving an email draft in your own mailbox, creating, editing, or deleting a calendar event, creating or completing a task, and creating or editing a Notion page.

Always stops for a confirmation card: sending, replying to, or forwarding an email, deleting an email, deleting a task, sending a Slack message, or posting a comment anywhere, and anything that runs a query, deploys, force-pushes, or moves money.

A confirmation card states the exact external effect before you approve it. For a message that means every recipient and the body text, not just the subject line — approving a subject is not consent to words you have never read. An unanswered card expires, and nothing happens.

Declining is a decision, not an error. Drift is told a person chose not to allow the action, so it acknowledges the choice and moves on rather than retrying. Decline the same action twice and it will not be proposed again in that conversation.

The one exception. Calendar writes are the one exception, and they include deletes. They run inline, with no confirmation card. An earlier build did ask, by pausing the turn and resuming it after approval — and because each resume was a fresh model turn, the same event was created over and over until the turn hit its tool limit. Running calendar writes in the same turn as the reads is what stopped that. It is the one place the rule bends, and it is a deliberate trade, not an oversight.

Why this design exists. An agent with unsupervised write access to your inbox is a category of risk most of this market is quiet about, and the reason is that confirmation is friction and friction does not demo well. The argument for asking anyway is that the costs are not symmetrical: reading a thread wrongly costs you nothing, and sending one wrongly can cost you a relationship. So the line is drawn at the point where an action stops being recoverable — where someone else can see it, or where the thing it changed is gone. Everywhere else, asking would be theatre, and a product that asks about everything teaches you to approve without reading, which is worse than not asking at all.

Permissions Drift requests. Drift requests access to the Google surfaces you choose to connect, through Google’s own consent screen, which lists the specific permissions before you agree. Gmail access is what lets it read and search your mail and draft replies; Calendar access lets it read your schedule and book what you ask for; Tasks access lets it read and update your lists. Connections are authorised through Composio, Drift’s connected-account provider, and the access tokens are held there rather than in Drift’s database. Revoke any connection from Settings and the access ends with it.

Can Drift send an email without asking me?

No. Sending, replying to, and forwarding are classified as actions that reach another person, and every one of them stops on a confirmation card first. There is no setting that turns this off, because the rule is enforced in the runtime rather than configured per account.

What does the confirmation card show me?

A confirmation card states the exact external effect before you approve it. For a message that means every recipient and the body text, not just the subject line — approving a subject is not consent to words you have never read. An unanswered card expires, and nothing happens.

What happens if I decline?

Declining is a decision, not an error. Drift is told a person chose not to allow the action, so it acknowledges the choice and moves on rather than retrying. Decline the same action twice and it will not be proposed again in that conversation.

Why do calendar events not ask?

Calendar writes are the one exception, and they include deletes. They run inline, with no confirmation card. An earlier build did ask, by pausing the turn and resuming it after approval — and because each resume was a fresh model turn, the same event was created over and over until the turn hit its tool limit. Running calendar writes in the same turn as the reads is what stopped that. It is the one place the rule bends, and it is a deliberate trade, not an oversight.

What permissions does Drift request from Google?

Drift asks for access to the Google surfaces you choose to connect — Gmail, Google Calendar, and Google Tasks — through Google’s own consent screen, which lists the specific permissions before you agree to them. Read access is what makes Drift useful at all; write access is what lets it draft, book and add on your behalf, under the approval rule on this page. Connections are authorised through Composio, and you can revoke any of them from Settings at any time.