Discover Assess Decide Communicate Act Measure Protect
Rewards Capabilities Entities Events Organizations Individuals Trust Risks Negotiate Accept Complain Remedy Request Respond Notify Train Tasks Workflows Skills Tools Impacts Campaigns Costs Compliance Consumers Employees Stakeholders Data
 
 

Which TOOLS are your agents
ALLOWED TO USE?

Explore our Tool Registry to verify authorization, configuration, and access controls.

 

Yo-AI Agents Won't Impersonate You

(You'll know if it's me or my agent)

Consider your inbox. Do you let Microsoft Copilot or Google Gemini send emails on your behalf?
No.
Do they do it anyway? How would you know?
Have you ever granted any AI product full access to your Google Workspace, Microsoft 360, Windows File System, Mozilla Firefox browser, or devices?
Do you maintain records of all your consents? Are these events included in event logs you can access? Or were you convinced by rote promises, such as:
"They will always identify themselves as an agent and will never send messages on your behalf without your explicit consent."

Clicking the "Trust Me" button will send an email to me,
via my Solicitor-General agent, which is authorized to use the Paubox API to send and receive secure emails.
This negates the need to allow access to my live Inbox, using MY credentials.

My agents and I need to know if the Sender is Trusted or UnTrusted. That's why I have a TrustedSender program, which manages a whitelist of known and verified senders to the yo-ai.ai domain.

TrustedSenders are registered, so that every unique email address and phone number is associated with a 'Responsible Human' I can contact in case any issues arise. No guessing about which message belongs to which entity -- every message is evaluated against the sender's registration record and communication preferences.