Inbox SPEC

Designed, not built, and deliberately last.

There is no inbox in CustomerLedger today. This page exists because the reason it is last is the most useful thing we can tell you about how the rest was built.

Mail is the weakest identity signal in the system.

The intended shape is a unified inbox organised around the person rather than the thread, one email front end over the addresses your businesses already use. It is the hardest of the three remaining surfaces, and it goes last for three reasons that are worth being explicit about.

01

An address is not a person

A phone number is dialled by whoever holds the handset. An address is typed, forwarded, shared by a household and reused by a business. Resolving mail onto the right human is a harder problem than resolving a call.

02

Mail is permanent and forwardable

A call ends. An email is a durable artifact the recipient can forward anywhere, which means an audience mistake in mail is not recoverable in the way a spoken mistake sometimes is.

03

Sending is the dangerous half

Reading mail into the record is tractable. Sending on your behalf crosses into the same territory as the send gate, and it should sit behind the same single decision rather than beside it.

What exists today, stated exactly

Drafting and reading tools exist inside the After Hours AI product against individually connected mailboxes. They do not write to CustomerLedger and they are not this feature. Nothing on this page describes running code in this product.

measured 2026-09-02 | state SPEC | reproduce with ledgerctl.py shipstate