Agent and knowledge
The agent is a chat assistant that works inside one workspace. It can read the workspace's conversations, customers, and labels, and it can propose changes such as assigning a thread or saving a reply draft. It runs with your own permissions, so it can never see or change anything you could not.
Where to open it
Open Agent in the left rail to see your chats. Press New chat and type into the box that reads "What would you like to work on?". Each chat keeps its own history, and you can search past chats from the sidebar.
On a desktop screen, the Ask Agent button in the bar at the bottom of the app opens a new chat in a window. The window stays open while you move between the inbox and other pages, and it can sit next to your email drafts. A chat in a window and a chat on the Agent page are the same chats. Recent, the clock button at the end of the bar, lists past chats and opens one in a window. The inbox page describes the bar and its windows.
You can attach files to a message. An image can be up to 5 MB, and any other file can be up to 20 MB.
What the agent can do
The agent works through a fixed set of tools. It picks the tool, and you see each call in the chat as it happens.
| Tool | What it does |
|---|---|
| Read workspace data | Runs a read-only query, for example to list threads, read a conversation, search mail, or look up a customer. Reads run straight away. |
| Change workspace data | Calls a function that writes, for example to assign a thread, change its status, add a label, add a note, or save a reply draft. Writes follow the approval setting. |
| Look up a function | Fetches the exact inputs of a workspace function before the agent calls it. |
| Search the web | Searches the live web and returns titles, links, dates, and short snippets. |
| Fetch a web page | Reads the full text of one page, either a search result or a link you gave it. |
| Run code | Runs JavaScript that the agent writes in an isolated sandbox. The sandbox has no network access and can only read workspace data. It cannot write. |
| Load a knowledge document | Loads the full text of one document from the Knowledge page when a question needs it. |
| Remember and recall | Saves a short note about your preferences or decisions, and searches those notes in later chats. |
Some tools depend on how Intray is deployed
Web search, web page fetching, running code, and memory are each switched on for a deployment as a whole. When one of them is off, the agent does not have the tool and does not offer it.
What the agent cannot do
These limits are enforced by the backend. An instruction in the chat cannot lift them.
- It cannot send email. It can save a reply draft on a thread, and a person sends the draft from the inbox.
- It cannot create, rotate, or revoke API keys, and it cannot manage connected applications.
- It cannot add or change domains, addresses, forwarding addresses, or connected mailboxes.
- It cannot read customer profiles that come from your own product.
- It cannot edit its own instructions or knowledge documents. Only people edit those.
- It cannot reach another workspace, your account settings, or any admin function. Its access is limited to the workspace the chat belongs to.
- It can read the log of its own actions, and it cannot change that log.
Approval modes
The composer has an approval control next to the model picker. It applies to every write the agent makes and is saved for you in this workspace.
| Mode | What happens |
|---|---|
| Ask first | The agent pauses before each write and shows you the function and its inputs. The write runs only after you approve it. |
| Auto-approve | Writes run as soon as the agent calls them. Reads, web tools, and sandboxed code never needed approval, so they are unchanged. |
A change of mode applies from the agent's next turn. An approval request that is already on screen still waits for your answer.
Choose a model
The model control in the composer lists the models available to the agent. The list is grouped, with smaller and open models under their own headings. Some models also let you pick a reasoning effort of Low, Medium, or High. Your choice is saved for you in this workspace.
Knowledge
Open Agent, then Knowledge in the sidebar. The page has the tabs Documents, Instructions, and Memory. Any member of the workspace can edit documents and instructions, and everyone in the workspace shares them.
Instructions
The Instructions tab holds one text called Workspace instructions. Intray includes it in the agent's prompt on every turn, so keep it short and limit it to rules that apply to every conversation. You can switch the instructions off without deleting them.
We are a team of four building a scheduling product for clinics.
Write in a friendly, direct tone. Sign off with the first name only.
Never promise a release date for a feature.
Refunds within 30 days of purchase need no approval. Later refunds go to Anouk.
When a question is about DNS or email setup, link the setup guide before explaining steps.Documents
A document has a title, a one-line description, and content written in Markdown. The agent always sees the titles and descriptions. It loads the full content of a document only when a question matches its description, so a clear description matters more than a long one.
Good candidates are texts your team already points people to, such as a refund policy, a pricing page, or a setup guide. Press New document to add one. You can switch a document off, and the agent then stops seeing it.
| Field | Limit |
|---|---|
| Title | 120 characters |
| Description | 200 characters |
| Content | 24,000 characters |
Memory
Memory is a list of short notes the agent saved about working with you, such as a preference you stated or a decision you made. Memory belongs to one person in one workspace. Your teammates have their own, and the agent does not share notes between people.
The Memory tab lists your notes, newest first, with where each came from: You told it, Inferred, or Derived. To remove a note, choose Forget on it. A note is at most 2,000 characters. When you start a new chat, the agent is given your most recent notes, and it can search the rest.
Write with AI in the composer
Write with AI is a separate feature in the reply composer and in a new email. Open it with the button in the composer or with Cmd+J on a Mac and Ctrl+J elsewhere.
When the reply is empty, it drafts one. You can type your own guidance or pick a preset such as "Draft a reply", "Acknowledge and say we're looking into it", or "Politely decline". When the reply already has text, it offers Shorten, Friendlier, More formal, and Fix grammar, and it accepts a custom instruction.
Write with AI reads the thread you are replying to. It receives the subject, the customer's name and address, the address you reply from, and up to the 12 most recent emails and form submissions in the thread, with long messages cut short. It does not read internal notes. In a new email there is no thread, so it uses the recipients, the subject, and your instruction. It does not use workspace instructions, knowledge documents, or memory. Those belong to the agent.
AI draft reply in automations
The AI draft reply action in Automations writes a draft on a thread when a rule matches. It reads the same thread content as Write with AI, and it also does not use workspace instructions or knowledge documents. The draft waits on the thread until a person reads it and sends it.
Privacy and untrusted email
The agent reads email only when a tool call asks for it, for example when you ask it about a thread. It reads with your permissions and only inside the current workspace.
Email from outside your workspace can contain text that tries to give orders to an AI. Intray marks that content before the agent sees it. Every inbound email body and snippet the agent reads carries the marker contentTrust: "untrusted_inbound", and the agent's standing rules tell it to treat anything under that marker as data. It may summarize, quote, or translate the text, but the text cannot change which functions it calls, what it drafts, or what it asks you to approve. Write with AI applies the same rule by wrapping customer messages in a tag that marks them as untrusted.
With Ask first on, you see every write before it happens, which is the last check against a message that tries to steer the agent.