Being built · Drawn, not shipped
A morning, in four objects
The briefing is the product. It does not exist in code yet, so everything on this page is a design drawing and says so — but it is drawn in the product’s own grammar rather than a marketing one, and the mechanism underneath it runs today.
The shape of a briefing
You wake up. You open Keelpost. It tells you what happened overnight across every account you have connected, what actually matters, and what it proposes to do about each of those things. You approve, and it acts. On the free tier that happens every twelve hours, and you can always pull it early by hand.
What arrives is a queue of decisions, not a list of messages, and it is ordered so that the things you cannot take back come first, while your attention is freshest. Anything that needed no decision is already done and reported below, with an undo.
-
Needs you
Replies ready to send, and deletions. Every one of them is its own card with its own button, and no “approve all” can reach any of them.
-
Proposed
Reversible work offered as a set: twelve to archive, a folder to file into, a standing rule worth adopting. One click can do all twelve, because all twelve can be undone.
-
Done — undo anytime
A ledger of what was handled without asking, with an undo on each line, and three of the filed messages offered back so you can say it was wrong.
-
Everything else
One line per topic. “Five things about the Q3 renewal.” It exists to prove nothing was hidden, not to be read every day.
Between briefings, a much cheaper pass over senders and subjects can interrupt: “Nina Okafor asked for a reply within the hour — run the briefing now?” It names the specific trigger or it does not appear. A product that acts twice a day still has to notice the thing that will not wait until evening.
A send is one decision, and it looks like one
Above the rule is what the server holds. Below it is what the model wants. The two never share a block, the account it would leave from is written out in full, and the button is labelled with the thing it does — Send, never Approve.
Replyfrom you@consultco.exampleSends mail
From the server
Nina Okafor — Q3 contract: can you confirm scope by Friday?
revision 4 · re-verified
From the model
A draft that confirms the scope, flags the licensing carve-out and proposes a call on Friday.
Three rules this card obeys
The button names the irreversible thing. Not “Approve” on something that sends mail. A reversible batch may say “Approve” only when the verb and the count are in the same label — “Archive 12”.
The sending account is on the face of the card. Replying to a client from a personal address is worse than not replying, so the address is written out rather than shortened to a display name, and it is never hidden behind a hover.
Approving it sends it. No second step, no “now go to drafts”. The mail leaves after a short, visible delay with a cancel beside it, so one click stays one click while a mistake stays recoverable. Cancel is a full-size button, not a small cross, and holding a message back is never treated as a failure.
Sends and deletes never enter a multi-select and never share a button. Twelve archives can be one click; two sends are two decisions. The moment an “approve all” can send mail, the guarantee is gone no matter how good the card looked.
A batch is shown as a set, because that is safer
Nobody wants to approve twelve archives one at a time, and nobody reads the twelfth. Shown as one set with the senders visible, you can see the whole shape of what you are agreeing to and uncheck the one that does not belong.
Archive · 12 messagesfrom you@yourdomain.example
From the server
- Vercel — deploy succeeded ×4
- npm — security digest
- Stripe — payout receipt
- … 9 more
From the model
All twelve match senders you have archived unread before. Everything here can be undone.
Unchecking a line changes the button in place — Archive 11 — and the one you removed is recorded as the most valuable kind of correction there is: a case the system was confident about and got wrong.
A batch is drawn without the solid button that a send gets, because adopting it is reversible and the styling should say so before you read a word. If a batch could ever contain a send or a delete, that would be a defect rather than a setting.
A rule is a standing offer, and it is drawn dashed
This is what “ever learning” is supposed to mean in practice. Not a model quietly acquiring habits, but a written rule you were asked about, in a list you can read and delete a line from.
New rule · proposed
From the server
You have archived eleven Substack digests unopened in the last month.
From now on
from: *@substack.com
→ file to Newsletters, skip the briefing
The rule is shown as the literal predicate it will run, not a paraphrase of it, because the list you edit six months from now has to contain exactly the thing you agreed to. Each adopted rule carries the date it was adopted and the number of times it has fired, which is the whole point: when the agent does something baffling in month four there is a specific line to point at rather than a mood to argue with.
At most two rules are proposed in any one briefing. Policy churn is its own kind of fatigue.
Receipts, and the three it hands back
Below the decisions is the record of what needed none. Verb first, count, destination, undo — and a sample offered back for correction.
DoneUndo anytime
- Filed 14 → Newsletters · Review 3 · Undo all
- Archived 6 receipts → Accounts · Undo
- Marked 9 CI notifications read · Undo
- Summarised 5 about the Q3 renewal → Renewal · Undo
Review 3 is the part that matters. If forty messages are filed and nobody ever opens the folder, nothing learns it was wrong about any of them, and the system grows most confident about exactly the cases nobody checked. So it offers three back, one line each, with the rule or inference that filed them, and a single control: wrong — keep in inbox. A correction from that sample is weighted far above an ordinary one.
Undo acts immediately and asks nothing, because it is the safe direction. A send’s receipt carries no undo at all, and the absence is deliberate: it is the honest statement that sent is sent, and it teaches the difference between cancelling before and undoing after.
The best briefing has nothing in it
On a good day the sections with decisions in them are not rendered empty — they are not rendered at all. What is left is the masthead, the mark, and one sentence: nothing needs you, followed by the count of what was handled overnight and the time of the next run. The receipts stay, because the proof of a quiet day is the visible record of what was done during it.
No confetti, no mascot, no illustration of an empty inbox. That sentence is the thing the whole product exists to earn and it should be allowed to be the content.
The first briefing is the other special case. It arrives to somebody who has not yet decided to trust any of this, so it cannot be the worst one: it is built from the last ninety days of the mailbox — who gets a reply within the hour, who never does, what was archived unread, which threads you started — and it says so.
What of this runs today
The briefing does not. The boundary it depends on does, and has since before the briefing was designed — which is the order those two things should have been built in.
Runs today
The approval boundaryLive
- A server-rendered approval card on every state change, drawn from the stored message rather than from the model’s summary of it.
- The revision fence: if the message changed after the card was drawn, approval is blocked instead of applied to something else.
- An agent scoped to one mailbox, re-checked against your live grants on every turn.
- Auto-drafting on inbound mail that can only write a draft, gated by fail-closed prompt-injection scanning.
- Receiving on a domain you route in yourself, and the full mail client under it.
Not built
The briefingPlanned — not built yet
- The briefing surface itself: the queue, the cards, the sections, the counter.
- The schedule that runs it, and the cheap pass that interrupts between runs.
- The send delay and its cancel — and sending at all, which is unverified.
- Batches, standing rules, the rules list, undo and the review sample.
- Connecting a Google Workspace or Microsoft 365 account, so “every account in one place” today means the domains you route in yourself.
The roadmap, in order, including what we will not build · How the boundary is enforced
Join the waitlist
Sign-ups are closed while this gets built. Leave an address and we will write once, when they open.
We store the address you type, plus a hashed form of your IP address so the form can be rate-limited. One email when sign-ups open, and nothing after that. We do not share the list, and there is no analytics or third-party script on this site.