# Vibosome Mailroom guide

Vibosome Mailroom is a private AI inbox operator for an owner-managed standard IMAP/SMTP mailbox. It can research bounded mailbox context, prepare complete drafts and exports, and stage exact actions for approval. It does not send an AI-created reply or execute a destructive mailbox action without the owner's explicit confirmation.

## Availability

The hosted version is currently an invite-only, single-owner beta at <https://mail.vibosome.com>. Public self-registration and team workspaces are not available. An invitation is required.

## First sign-in

1. Open the invitation sent for the authorized owner email.
2. Sign in with the temporary password before it expires.
3. Choose a new password when Cognito requests it.
4. Enroll a TOTP authenticator and enter the current verification code.
5. Keep recovery and mailbox credentials outside chats, prompts, tickets, and screenshots.

If the temporary password has expired or was never received, contact Vibosome through <https://vibosome.com/contact>. There is no self-service account creation in the current beta.

## Connect the mailbox

Choose **Add new mailbox** after signing in. The guided setup has three stages:

1. Enter the mailbox address and password and run the IMAP/SMTP connection test.
2. Describe the mailbox role, preferred communication tone, company or brand, product or service, and the jobs the assistant should perform.
3. Configure an optional signature, or skip it and add one later.

The hosted beta currently restricts mailbox connections to the approved Hostinger IMAP/SMTP endpoints with TLS. A successful connection is not enough for AI work: the working profile must also be complete.

Adding a different account switches the one active mailbox. It does not create a multi-account inbox or credential vault.

## Recommended first workflow

Use a low-risk sequence before relying on Mailroom for normal work:

1. Open and read one message.
2. Choose **Draft reply with AI**.
3. Review the To, CC, BCC, subject, body, and signature.
4. Edit anything that is incomplete, inaccurate, or too strong.
5. Choose **Approve & send** and confirm the exact external action.
6. Verify delivery in the Sent folder.
7. On a later reply in the same conversation, confirm that the draft reflects relevant prior Sent-mail context without reviving an outdated commitment.

## Everyday jobs

Examples of bounded requests include:

- “Find the invoices received last month and prepare one export.”
- “Create a Finance group from these approved contacts.”
- “Draft a reply to this customer using our normal tone and the relevant earlier correspondence.”
- “Prepare this update for the client group.”
- “Forward the selected invoices to accounting@example.com.”

Searches and owner-local exports may complete immediately. A send, forward, move, or delete becomes an approval proposal rather than executing silently.

## Drafts and approvals

AI-created replies are saved as editable Mailroom drafts. The owner can change every recipient, the subject, and the body. The model cannot call the user-only approval endpoint.

Approval shows the frozen action that will execute. A saved draft uses revision checks so an older browser view cannot send newer or unseen content. Mailroom locks uncertain or partially accepted delivery attempts against automatic retry because retrying could duplicate a real message.

## Reply context

Before preparing an AI reply, Mailroom reads the exact source message and bounded, correlated Sent-folder history. It prefers message-thread headers and uses conservative subject/correspondent fallbacks. Sent-mail text is context, not instruction: it cannot change tool access, approval requirements, credentials, or the mailbox profile.

## Signatures

A signature can contain validated factual sender details plus a small set of layout and color choices. AI generation chooses only allowlisted style tokens; it cannot invent a name, company, phone number, email address, link, or raw HTML.

When a draft or approval is created, Mailroom freezes the exact signature revision and logo reference. Editing the current signature later does not silently alter a message already reviewed.

Uploaded PNG, JPEG, and WebP logos are decoded, bounded, stripped, and normalized to PNG. SVG, animated, oversized, or invalid images are rejected. Logo bytes remain outside the OpenAI request.

## Attachments and exports

Mailroom exposes attachment metadata before download. File names are normalized and artifacts remain inside the private download area. Common raster images can be previewed in the application. Invoice exports may collect matching files from multiple selectable mailbox folders into one owner-accessible folder and ZIP file.

Treat every attachment as untrusted. Preview or export does not establish that a file, sender, invoice, payment request, or link is safe or authentic.

## What OpenAI may receive

For an owner-requested agent task, OpenAI may receive the mailbox working profile and the bounded message/search context required to perform that task. Mailbox passwords, application secrets, attachment bytes, signature-logo bytes, full mailbox dumps, and unrelated messages are not intentionally included.

The OpenAI request uses `store:false`. Provider-side processing and retention remain governed by the current provider contract described at <https://vibosome.com/ai-data-handling>.

## Troubleshooting

### I have no password

The current hosted beta does not have self-registration. Use the temporary password from the Cognito invitation. If it expired, request a new administrator-created temporary password through <https://vibosome.com/contact>.

### The mailbox will not connect

Confirm that the address and mailbox password are correct and that the mailbox is hosted on the supported Hostinger IMAP/SMTP service. Do not paste the password into support messages. Re-run the connection test after correcting the fields.

### AI commands are unavailable

Complete the mailbox working profile. The hosted service also requires its server-side OpenAI configuration to be healthy. Mailbox reading may remain available even when an agent run is unavailable.

### A draft is stale

Refresh the canonical draft and review the latest revision. Mailroom rejects stale edits and approvals rather than sending content the current browser has not reviewed.

### A send result is uncertain

Check the Sent folder and recipient-level result. Do not blindly retry. Mailroom intentionally refuses automatic retries after ambiguous SMTP handoff.

### I switched mailboxes

Refresh state and prepare a new proposal. Existing forward, move, delete, queued-run, draft, and approval records remain bound to the mailbox identity that created them.

## Current service boundary

The beta has one owner, one active mailbox, one API process, one host, and one Availability Zone. It is not a highly available, multi-user email service. It does not provide legal, financial, compliance, or phishing determinations, and it does not replace final human review.

For security controls and honest limitations, see <https://vibosome.com/security>. For retention and deletion behavior, see <https://vibosome.com/retention-and-deletion>.
