Control

How Control works

Updated 4 October 2026

Reading the mailbox

Control reads the Inbox through Microsoft Graph with the permissions of the account that connected it, so it can read exactly what that account can read. Every few minutes it asks for what changed since the last time (a delta query), so a message is seen once, soon after it arrives. On the first run it looks back 24 hours. Messages are read as text; attachments up to 3 MB are fetched, at most five per message.

Mail from your own domains and automatic mail (out-of-office, bounces, no-reply senders) is recorded as left alone and never assessed.

Preparing a message

Before any model sees a word, code prepares the text:

  • Own words only. Quoted history (On … wrote:, … kirjoitti:, forwarded headers) and the signature block are dropped. The text is capped at 6,000 characters.
  • Identifiers replaced. Finnish personal identity codes (checked by their control character), IBANs (checked by their checksum) and payment card numbers (checked by the Luhn algorithm) are replaced by placeholders, in the body, the subject and every attachment. Counts are kept, values are not.
  • Attachments as text. PDF and Word documents are read (up to 20 pages, 4,000 characters each), text and CSV files decoded, images and other files only named.
  • The sender stays behind. The sender's address never leaves Control; its domain does.

The proposal

A generative model hosted in the EU reads the prepared message and answers through one fixed schema: intent, urgency, language, summary (one or two sentences, no names or identifiers), action, reasons, draft_reply (only with a reply, complete and in the message's language, no placeholders), needs_person. An answer that does not fit the schema is a failure, recorded as not assessed, never a guess. The model is told your mailbox policy: what your company does with a sales inquiry, a support request, an invoice, a complaint, a newsletter.

The rules the model cannot change

Found in the message Control does
A personal identifier (replaced by the redactor) to a person, no draft
The words of a legal matter or a complaint, in Finnish, Swedish, English or Bulgarian to a person, no draft
Nothing the policy covers, or the model is unsure to a person

These run before the model and win over it. The model may add to the list in its own answer; it cannot shorten it.

Asking Gate

Control sends the proposal to Gate as a structured request: the action type (reply_email, forward_email, archive_email, categorise_email, escalate, leave), the message as the target, the summary, and as context the facts (time, sender's domain, subject, attachments, redaction counts), a redacted excerpt of up to 1,500 characters, the reasons and the draft. Control is a registered agent of your environment with exactly these six action types. Each message carries an idempotency key, so a retried run never produces a second decision. Gate's answer and its reason codes are recorded with the proposal; in the console they appear like any other decision.

Limits

Messages assessed per run 20; the rest wait for the next run a few minutes later
Attachment size 3 MB; larger files are named, not read
Attachments per message 5
Text per message 6,000 characters; per attachment 4,000
Monthly assessment budget agreed with Työäly; above it messages are recorded as not assessed and listed in the report

When something fails

A message that cannot be processed is recorded with the reason and listed in the report; the run goes on. A mailbox that cannot be read at all stops the run and alerts Työäly. Gate not answering is recorded as assessed, Gate did not answer; the proposal is kept.

Something missing or unclear on this page? Write to hei@tyoaly.fi.