I wanted my OpenClaw agent to handle email — read it, triage it, draft replies. The obvious path is to hand it a Gmail OAuth token and let it call the API directly. I didn't do that.
Not because I don't trust the agent, but because that framing is wrong. The question isn't do I trust the agent — it's what rules should govern what it's allowed to do? Reading my inbox? Fine, always. Sending an email to an investor on my behalf? That needs my explicit sign-off. Permanently deleting messages? Never, under any circumstances.