Skip to main content

Warranty Policy - Outbound Email Agent

This policy governs an agent that drafts and sends outreach email through a provider API (Resend, SendGrid, Gmail API) and reads prospect data from a CRM. Outreach recipients are unknown in advance, so this policy does not use a recipient allowlist. Its controls are the ones the evaluator enforces fail-closed: every send is held for human approval, every send intent must carry a recipient, listed internal broadcast addresses are denied, every intent must declare an approved job type and a campaign, and per-campaign daily volume is capped. Suppression lists, unsubscribe handling, and CAN-SPAM/GDPR mechanics live in your email provider; this policy does not replace them. job_type and campaign are declared by the agent unless your deployment submits intents through a trusted shim. Replace the example hosts and addresses, then copy the policy body into Sigil Warrant and sign it.