Blog · 2026-10-01 · James McIntosh

Give Meta Muse its own inbox, with guardrails

Meta's Muse agent is getting email one way or another. Meta has said Muse will get an address of its own, and you can already connect it to your inbox. So the useful question is no longer whether Muse can have email. It is who decides what reaches Muse and what leaves in your name.

Muse is getting email. The real question is control.

Meta launched Muse on 2026-09-08 (TechCrunch, 2026-09-08). At Connect on 2026-09-23, Meta said Muse "will have its own email address" (Meta newsroom, 2026-09-24). TechCrunch reported the address is coming "soon", with no date (TechCrunch, 2026-09-23).

An address is the easy part. Email is also a channel attackers use to reach an agent. Meta's own help page warns that "websites, emails, files and connected services can contain instructions intended to manipulate an AI agent" (Meta Help Center). An agent that can send can also be manipulated into sending. Ask of every option: who controls what reaches Muse, and what leaves it?

Three ways to give Muse email today

  1. Meta's Gmail or Outlook connector. It is in Muse's connector directory, and it connects your own inbox. Meta's write-up on Muse's security and safety says its email connector "filters out one-time tokens, password reset links, and login magic links" (Tarek Sheasha, Meta, 2026-09-08).
  2. An inbox service through a custom connector. Muse signs in to the service, or builds a connector from its API description, and gets a separate address. ReplyLayer works this way.
  3. Muse's own address from Meta. Announced, with no date.

Screening: what reaches Muse

Its own inbox keeps Muse's mail apart from yours. What matters more is what happens before Muse reads a message.

ReplyLayer scans every incoming email before Muse reads it. Mail that looks like an attack on the agent, such as prompt injection or a jailbreak attempt, is held for review, outside Muse's normal inbox flow. You review it in the dashboard, then release it or block the sender.

Picture an email that reads like a supplier note but ends with a line addressed to the assistant, asking it to forward the last three invoices to a new address. That hidden instruction is the kind of content the scan looks for. An approval prompt, Muse's or anyone else's, appears only when Muse is about to act: after it has read the email and may already have been steered by it.

Screening lowers risk; it cannot catch everything, so Muse should still treat an email body as data, not instructions. See content scanning.

What Meta does and doesn't check

Directory connectors are reviewed. Meta's platform page says submissions must meet "functional, security, and legal requirements, and complete end to end testing" (muse.ai/platform). Custom connectors are not. Meta's Help Center says: "Meta doesn't review custom connectors or how they use your information, so grant access with caution" (Meta Help Center, connectors).

ReplyLayer is a custom connector. Meta has not reviewed it, and ReplyLayer is not affiliated with or endorsed by Meta. That is a good reason to give Muse a connection that can do little. Whether Muse signs in or uses an agent key, it can use only the mailbox you choose, and you can revoke its access at any time.

If you connect with an agent key instead of signing in, Muse stores it in its Secure Credentials Store and asks for it in a credential prompt, so keep the key out of the chat. As Parallel puts it, "Pasting a key into the conversation defeats that design and leaves it in your history" (Parallel).

The other guardrails: what leaves

These limits are set in your dashboard and enforced by ReplyLayer when an email leaves, not by Muse.

  • A separate inbox. Muse gets its own ReplyLayer address. ReplyLayer never gives Muse your Gmail or Outlook. Muse can still reach them through Meta's own connector if you connect it.
  • Outgoing mail is scanned too. The outbound scan looks for credentials leaving in an email, such as API tokens, cloud access keys and private keys, and blocks that send.
  • A recipient list. Turn on a recipient list and Muse can start emails only to people on it. It limits Muse, not you: your own sends from the dashboard are not restricted by it, and Muse's connection cannot add names to it. On Sandbox it is opt-in, because a new Sandbox mailbox starts in blocklist mode. Replies to people who wrote in are not blocked by it. See the recipient list guide.
  • Optional human approval for every send. Muse's own prompt approves a type of action, not each email: choose "Always allow" and Muse can take that action through the connector "in the future without asking again" (Meta Help Center, guidance and approval). Set Human approval to Every send in the mailbox settings, and each email Muse writes waits for you in the dashboard. It is available on every plan, including Sandbox. Muse cannot approve it; its connection is refused at the approval step. For why a hold should be a normal product state, see when an agent reply needs human review.
  • Access limited to the mailbox you choose. Revoke the connection under API Keys and Muse loses access at once.
  • Held, not sent unchecked. If a temporary infrastructure problem stops the check, the email is held (held_infrastructure) instead of going out unchecked. Send outcomes defines every result.

Setup in three steps

  1. Start a free Sandbox, then verify your email and phone.
  2. On Connect Agent, create a mailbox, choose Meta Muse, and copy the test prompt. There is no key to copy: Muse signs in to ReplyLayer.
  3. Paste the prompt into a new Muse chat. When Muse's connect window asks for a client ID, enter meta-muse, then choose the mailbox and approve on ReplyLayer's page.

Muse then sends one email to ReplyLayer's test simulator and reports the result. sent means ReplyLayer accepted the email, not that it was delivered. We tested signing in end to end in production on 2026-09-26. If you'd rather not sign in, Muse can also connect with an agent key as a REST custom connector, which we tested in production on 2026-09-23. The Meta Muse guide covers both ways and each error Muse can report.

What the free Sandbox allows

The Sandbox lasts 30 days. You get one mailbox on a temporary trial address, up to 15 sends a day and 250 in total. On the free Sandbox you can email your own address and anyone who confirms by link, reply to people who write to you from an authenticated address, and add up to 5 people you know, yourself or through your agent. Add pay-as-you-go credit or upgrade to email anyone. Sandbox mail carries a ReplyLayer footer and "via ReplyLayer" in the sender name. Every limit is in the limits reference, and paid plans are on the pricing page.

When you don't need this

  • If Muse only reads, triages or drafts in your own inbox, Meta's Gmail or Outlook connector may be enough.
  • If you only forward Muse the occasional email, its own address may cover that when it ships. Meta has not given a date.
  • ReplyLayer fits when Muse reads mail from people you don't know, sends on its own, or writes to people outside your inbox.

FAQ

Does Meta review ReplyLayer's connector? No. ReplyLayer is a custom connector, and Meta does not review custom connectors. ReplyLayer is not affiliated with or endorsed by Meta.

Can Muse approve its own email? No. A held email is approved by a person in the dashboard or with an admin key. Muse's connection is refused, whether it signed in or uses an agent key.

Does "sent" mean delivered? No. sent means ReplyLayer accepted the email for sending. Delivery happens after that and can still fail.

Can Muse still read my Gmail? Only if you connect Meta's Gmail connector. ReplyLayer does not give Muse access to it.

Is the email end-to-end encrypted? No. ReplyLayer decrypts mail on its servers to scan it, processes data in the United States only, and does not hold SOC 2 yet. See security.

What happens when Muse gets its own address? You can use both. Meta's address may be enough for forwarding and simple tasks. ReplyLayer is for when you want incoming mail screened before Muse reads it, and limits on what Muse sends that ReplyLayer enforces.

Set up Muse with ReplyLayer.