Being built · Drawn, not shipped

A morning, in four objects

The briefing is the product. It does not exist in code yet, so everything on this page is a design drawing and says so — but it is drawn in the product’s own grammar rather than a marketing one, and the mechanism underneath it runs today.

The shape of a briefing

You wake up. You open Keelpost. It tells you what happened overnight across every account you have connected, what actually matters, and what it proposes to do about each of those things. You approve, and it acts. On the free tier that happens every twelve hours, and you can always pull it early by hand.

What arrives is a queue of decisions, not a list of messages, and it is ordered so that the things you cannot take back come first, while your attention is freshest. Anything that needed no decision is already done and reported below, with an undo.

  1. Needs you

    Replies ready to send, and deletions. Every one of them is its own card with its own button, and no “approve all” can reach any of them.

  2. Proposed

    Reversible work offered as a set: twelve to archive, a folder to file into, a standing rule worth adopting. One click can do all twelve, because all twelve can be undone.

  3. Done — undo anytime

    A ledger of what was handled without asking, with an undo on each line, and three of the filed messages offered back so you can say it was wrong.

  4. Everything else

    One line per topic. “Five things about the Q3 renewal.” It exists to prove nothing was hidden, not to be read every day.

Between briefings, a much cheaper pass over senders and subjects can interrupt: “Nina Okafor asked for a reply within the hour — run the briefing now?” It names the specific trigger or it does not appear. A product that acts twice a day still has to notice the thing that will not wait until evening.

A send is one decision, and it looks like one

Above the rule is what the server holds. Below it is what the model wants. The two never share a block, the account it would leave from is written out in full, and the button is labelled with the thing it does — Send, never Approve.

A design drawing, not a screenshot and not software yet. The two-block split, the revision fence and the words on the captions are taken from the approval card that already ships.

Three rules this card obeys

The button names the irreversible thing. Not “Approve” on something that sends mail. A reversible batch may say “Approve” only when the verb and the count are in the same label — “Archive 12”.

The sending account is on the face of the card. Replying to a client from a personal address is worse than not replying, so the address is written out rather than shortened to a display name, and it is never hidden behind a hover.

Approving it sends it. No second step, no “now go to drafts”. The mail leaves after a short, visible delay with a cancel beside it, so one click stays one click while a mistake stays recoverable. Cancel is a full-size button, not a small cross, and holding a message back is never treated as a failure.

Sends and deletes never enter a multi-select and never share a button. Twelve archives can be one click; two sends are two decisions. The moment an “approve all” can send mail, the guarantee is gone no matter how good the card looked.

A batch is shown as a set, because that is safer

Nobody wants to approve twelve archives one at a time, and nobody reads the twelfth. Shown as one set with the senders visible, you can see the whole shape of what you are agreeing to and uncheck the one that does not belong.

A design drawing, not a screenshot and not software yet. The senders and counts are fabricated sample data.

Unchecking a line changes the button in place — Archive 11 — and the one you removed is recorded as the most valuable kind of correction there is: a case the system was confident about and got wrong.

A batch is drawn without the solid button that a send gets, because adopting it is reversible and the styling should say so before you read a word. If a batch could ever contain a send or a delete, that would be a defect rather than a setting.

A rule is a standing offer, and it is drawn dashed

This is what “ever learning” is supposed to mean in practice. Not a model quietly acquiring habits, but a written rule you were asked about, in a list you can read and delete a line from.

A design drawing, not a screenshot and not software yet. Dashed is this site’s existing word for “not yet standing” — the same border the planned chips on the roadmap carry.

The rule is shown as the literal predicate it will run, not a paraphrase of it, because the list you edit six months from now has to contain exactly the thing you agreed to. Each adopted rule carries the date it was adopted and the number of times it has fired, which is the whole point: when the agent does something baffling in month four there is a specific line to point at rather than a mood to argue with.

At most two rules are proposed in any one briefing. Policy churn is its own kind of fatigue.

Receipts, and the three it hands back

Below the decisions is the record of what needed none. Verb first, count, destination, undo — and a sample offered back for correction.

A design drawing, not a screenshot and not software yet.

Review 3 is the part that matters. If forty messages are filed and nobody ever opens the folder, nothing learns it was wrong about any of them, and the system grows most confident about exactly the cases nobody checked. So it offers three back, one line each, with the rule or inference that filed them, and a single control: wrong — keep in inbox. A correction from that sample is weighted far above an ordinary one.

Undo acts immediately and asks nothing, because it is the safe direction. A send’s receipt carries no undo at all, and the absence is deliberate: it is the honest statement that sent is sent, and it teaches the difference between cancelling before and undoing after.

The best briefing has nothing in it

On a good day the sections with decisions in them are not rendered empty — they are not rendered at all. What is left is the masthead, the mark, and one sentence: nothing needs you, followed by the count of what was handled overnight and the time of the next run. The receipts stay, because the proof of a quiet day is the visible record of what was done during it.

No confetti, no mascot, no illustration of an empty inbox. That sentence is the thing the whole product exists to earn and it should be allowed to be the content.

The first briefing is the other special case. It arrives to somebody who has not yet decided to trust any of this, so it cannot be the worst one: it is built from the last ninety days of the mailbox — who gets a reply within the hour, who never does, what was archived unread, which threads you started — and it says so.

What of this runs today

The briefing does not. The boundary it depends on does, and has since before the briefing was designed — which is the order those two things should have been built in.

Runs today

The approval boundaryLive

  • A server-rendered approval card on every state change, drawn from the stored message rather than from the model’s summary of it.
  • The revision fence: if the message changed after the card was drawn, approval is blocked instead of applied to something else.
  • An agent scoped to one mailbox, re-checked against your live grants on every turn.
  • Auto-drafting on inbound mail that can only write a draft, gated by fail-closed prompt-injection scanning.
  • Receiving on a domain you route in yourself, and the full mail client under it.

Not built

The briefingPlanned — not built yet

  • The briefing surface itself: the queue, the cards, the sections, the counter.
  • The schedule that runs it, and the cheap pass that interrupts between runs.
  • The send delay and its cancel — and sending at all, which is unverified.
  • Batches, standing rules, the rules list, undo and the review sample.
  • Connecting a Google Workspace or Microsoft 365 account, so “every account in one place” today means the domains you route in yourself.

The roadmap, in order, including what we will not build · How the boundary is enforced

Join the waitlist

Sign-ups are closed while this gets built. Leave an address and we will write once, when they open.

We store the address you type, plus a hashed form of your IP address so the form can be rate-limited. One email when sign-ups open, and nothing after that. We do not share the list, and there is no analytics or third-party script on this site.