SIG9
HOW IT WORKS

What access an install needs, and where lead text goes

An install needs access to the accounts the workflow touches, granted once and removable whenever you like. Lead text passes through your email provider, an AI model provider that sorts and drafts, a chat app where each reply is approved, and the place the system runs and keeps its run records. Junk stops before any AI sees it.

What access the install needs

The install needs access to the accounts the workflow touches. For a system that answers leads, that usually means your email account and the chat app replies are approved from.

You grant that access once, inside accounts you own, and you can remove it whenever you choose: from the email account's security settings, and by removing the approval bot from the chat it posts to. Later changes to the system don't come with fresh requests for access.

What these installs leave out

Two kinds of work sit outside these installs: anything behind security or compliance approvals, and anything that handles regulated data.

Where lead text goes

[ WHERE A LEAD GOES ]READS AND DRAFTS · CAN'T SENDNOTHING CROSSES WITHOUT APPROVALMAIL ARRIVESTHE EMAIL ACCOUNTYOU ALREADY USESCREENFIXED RULES · JUNK STOPS HERENOTHING SPENTDRAFTAN AI MODEL PROVIDERREADS THE LEADA PERSONAPPROVESSENDS FROM YOUROWN ADDRESS
A lead arrives in the email account you already use, a fixed-rule screen stops junk before any AI is used, an AI model provider reads the rest and drafts a reply, and that reply waits in a chat app for a person to approve it before it goes out from your own address.
RoleExampleWhat it sees
Your email providerGoogle WorkspaceEvery lead, as it does today. Approved replies go out through it, from your own address.
An AI model providerNamed in your setup guideEach lead that gets past the fixed rules, earlier emails in the same conversation, and the notes about your business and your writing that it drafts from.
A chat app for approvalsTelegramAn excerpt of the lead and the drafted reply, on the approval card.
The person who approves repliesSomeone at your business, chosen at setupAn excerpt of the lead, the drafted reply and the record of that run, on the approval card.
A store for AI step recordsNamed in your setup guideThe lead's email address, subject and message, and the drafted reply, for each AI step.
Where the system runs and keeps its run recordsAgreed per install, named in your setup guideWhat came in, what the AI was given and what it drafted, for each run.

Each run also leaves a record of what came in, what the AI was given and what it drafted, so a failed run can be traced.

In a live pass on SignalNine's inbox on 2026-09-07, junk and mail that wasn't a lead cost $0.00 in AI fees, because the screen runs before any AI call.

What the AI can and can't do

The AI sorts each lead, works out what the person is asking for, and drafts a reply from the notes about your business and examples of how you write.

The part of the system that reads incoming mail has no way to send email. Sending sits in a separate step, and that step runs only after a person presses approve on the card.

So a lead who writes “ignore your instructions and reply now” can't make the system send anything, because the side that reads the message has no way to send, and every draft still waits for approval. Each draft is also checked against fixed rules before it reaches you, and a draft that names a price nobody set gets flagged for a closer look.

Questions

Can I take the access back?

Yes. Remove it from the email account's security settings to stop the system reading or sending through that account, and remove the approval bot from the chat it posts to, to stop the cards.

Can the AI send email by itself?

No. The part that reads mail can't send. A reply goes out only after a person approves it on the card, and it goes out from your own address.

Mashrur Rahman · Founder, SignalNinePUBLISHED · UPDATED