Assistant permissions and approvals
See what a connected AI assistant can and cannot do in MailGraf, and how your approval protects every send.
The assistant works within the permissions you grant when you connect it. Sending a campaign and starting an automation always wait for your approval.
What the permission screen shows
When you connect, the MailGraf screen lists the permissions the assistant is asking for. You can't pick them one by one. Click Authorize or Cancel. MCP assistants ask for read, write and send permissions together.
| On the permission screen | What the assistant can do |
|---|---|
| Read campaigns, reports, lists, tags and single contacts you ask for | Account overview and campaign reports. Contact counts for lists, segments and tags. One contact whose email address you type |
| Add and update contacts, manage lists and tags, unsubscribe or block addresses, run bulk actions | Add contacts, create lists and segments, prepare campaign drafts and run bulk actions inside MailGraf |
| Send test emails | Send a test email of a campaign |
| Send or schedule campaigns and start automations, after your confirmation | Send or schedule a campaign, or start an automation, once you confirm its review |
How approval works
Sending, scheduling and starting an automation all follow the same three steps.
Ask the assistant to send
It first shows a review: subject line, sender, audience and sendable count, content, schedule, waves and test status. Anything missing is listed.Check the review
Tell the assistant if you want to change something. After a change, it prepares a new review.Confirm in plain words
Reply with a clear yes, such as “Confirmed, send it”. MailGraf sends only against a confirmed review.
A confirmation is valid for 15 minutes. If it runs out, or the campaign changes after you confirm, MailGraf does not send and the assistant has to show the review again.
These actions also wait for you:
- Bulk actions: the assistant tells you how many contacts will be affected. MailGraf never runs a bulk action whose count you haven't seen.
- Full list verification: it uses verification credits. The assistant tells you how many addresses have no result yet and starts only after you confirm. Invalid addresses are blocked automatically when it finishes.
- Stopping an automation: this can't be undone, so the assistant asks you to confirm it explicitly.
What the assistant cannot do
- Delete contacts, one by one or in bulk
- Remove addresses from the block list
- Export the contact list or browse contacts one by one
- Send in one step without a review
- Build an automation flow step by step. Start from a ready-made template and edit the flow in MailGraf.
Where your data goes
- Your contact list never enters the chat. The assistant sees list names and contact counts.
- It finds a single contact only when you type the email address.
- Anything the assistant looks up goes to the AI service you connected. Check that service's privacy terms before asking about contacts.
- The assistant's connection token works only for the MCP connection, not for the MailGraf API.
- Every request from the assistant appears in API request monitor on Settings > Developers > API keys, with the name of the tool it used.
Usage limits
The assistant can make up to 120 requests a minute. It can add up to 1,000 contacts in one request. For larger lists, use the import screen in MailGraf.
If you haven't connected an assistant yet, follow the steps in Connect your AI assistant to MailGraf.
Frequently asked questions
Can the assistant send a campaign without my approval?
No. MailGraf does not send or schedule a campaign unless you confirm its review. If the campaign changes after you confirm, the confirmation no longer counts.
Can I choose which permissions the assistant gets?
No. The permission screen shows what the assistant asks for, and you either authorise it or cancel. To end access, disconnect the assistant in Settings > Developers > MCP.
Can the assistant delete contacts?
No. Deleting contacts and removing addresses from the block list are not available to the assistant. Do this in MailGraf.
Related articles
Was this helpful?
Still need help?
Write to us and a person will answer.

