No, your agent sent an email and you didn't review it first. Oh AI slop going out to the world. Oh, what are we gonna do? Actually having AI write a first draft of an email is pretty nice but having it send that email without you reviewing it can be irritating and It is kind of irritating that at least as of today Gmail doesn't have a mechanism for you to connect and prevent email sending if you wanted to allow an agent to draft an email for you But not allow them to send it for you then you're in a world of hurt. There's no scope that prevents Sending if you want to allow drafting However, because the way that Cody works you can get exactly this with deterministic code to completely Prevent an agent from actually sending an email and actually still be able to draft it for you And that's what I'm gonna show you in today's video This is better with Kent where you and I get better together by harnessing Harnesses that our LLMs are running in and these agents that have so much power and bring us so much opportunity We're going to figure out how not just to handle Gmail and drafts and stuff. This is just the example We're using but more specifically how to take a token that can is capable of doing many many things and Scope down what the agent is able to do with that token if you watch my videos the while back You saw how an agent was able to drop a production database because it was an over scoped token and This is the sort of thing that you could put into place to completely prevent something like that from ever happening so if you care about being more secure and Making sure that your agents can only do the things you actually want them to do then this video is for you So let's get into this. I got this email from me at kensydoz.com About Cody codes and so I've already signed up for an account I have an account on Cody code and this is going to be the home for all of my agents regardless of what I use right now We're going to be using grockbot as our example and I've got it all set up and configured here But the second part of this email is the really interesting piece. So once you're there The Gmail is a thing I've been using for drafts to drafts I'll still send myself because Google will not give you drafts only scope. This is the guide that will make Make that more concrete and help you understand how to lock down actually sending your email So you could take a look at this guide yourself But we're pretty much gonna follow this exact thing and the way that this actually works is that Cody hangs on to the secrets for you And then Cody also ensures that those secrets don't go anywhere They're not supposed to but then further Cody can lock that secret down to a particular package or a Repository of code and that repository of code can be written by the agent You can have specific things that can be called by that code and then you can make it so that the agent can't update that code without your express permission and so The agents not allowed to use the the token and the agents not allowed to change the package Without your permission so you just make a package that can only send a draft create drafts for you and can't actually send emails And now you have a foolproof mechanism to allow agents to create drafts, but not actually send emails So we're gonna look at the specifics of how this all works and how to set it up so that you get an idea of How to get this going so before we get too far into that I just want to address the elephant in the room and that is your current agent your current agent probably has a plug-in specifically for Gmail and So you might think oh, I'll just add this but again your agent can still send emails with these basic Integrations unless they add some sort of specific thing that says no no no you cannot send actual emails You can only draft them. That's what it says right here is to draft. It doesn't say to send But unless they're doing some extra special magic here most of the time They just have something that says you are not allowed to actually send email and and they do a pretty good job of preventing that But the other nice thing that Cody gives you that this is not going to give you is the ability to use this same Integration in all of these other agents So if you happen to be inside of your code editor for example and you want to draft an email based on context You've built up in here. Well, you'd have to connect that your code editor also to Gmail The nice thing about Cody is that it brings them all together So yes, you can absolutely add integrations to all every one of these But you'd have to set up those same protections in every one of these by having Cody you prevent that Problem entirely and you can have just one place where all of this lives The drawback to Cody though is that as of right now there's not a built-in Integration that you just do a one click to make that work and there are reasonable reasons for this that are actually intentional But what that means is you have to set up your own? Google OAuth app to make this work, and it's not very It's not too challenging You can follow me step-by-step to make this work in your own Google account and It should only take about five to ten minutes So you can go to cloud.google.com and this is the Google Cloud platform that you're going to be setting this up It is intimidating. There's a lot of buttons and different things that you can press on but you can literally just ask your agent So let's actually start with that I'll just say I want to set up a package in Cody that will allow you to draft emails in my Google account But not actually send emails in my Google account and in fact. I'm just going to paste this guide right in here Help me get the Google Or get this Working and we'll let the agent kind of guide us through this entire experience And this is a general practice that I would recommend is that you can just ask the agent if you ever get stuck on anything Just tell the agent that you're stuck and ask it what to do next and often the agent will be able to help you Identify what the problem is you can take a screenshot of errors and paste it into the agent The agent can look at the screenshot and give you some more feedback and Directions to go and everything and and the more and more capable you make your agent The more it can do kind of on its own and you don't have to control every piece of what it's doing and and be the like Context hot potato person. So here it's looking up how to set this up. Okay, great So here it says Google has no drafts only scope exactly Creating a draft needs Gmail compose which can also send so we're going to connect that then publish the thin package That only calls user drafts create and lock it so that you can send so first we need a Google OAuth client So we're going to open the Google cod console and create or pick a project reply done And I'll walk you through the next step. Okay, great So I've already got a project in here because this is my actual Cody Account so we're going to click on this this will allow you to make a new one if you don't have one already Then you'll have a new one or an option to create a new one in here But I'm gonna click new project here and we're gonna call this Cody We don't need an organization for this is just for us and that then we'll create so it's creating the Cody project and we'll come back over here and we'll say done and When that's set, I'll walk you through the next console step very nice While it's doing that, let's select a project here. We go now. We're inside the Cody project We've got this hamburger menu. So that might be interesting Next enable the gmail API in that project. So open The gmail API library. That's very nice. It just gives us direct links to things Make sure we're still in the right project and we're gonna enable the gmail API in our project So with that enabled, we'll say done And the agent can tell us the next thing to do So this is just a pretty straightforward then in the Google app Auth platform, so we'll go there We're getting a bunch of these popping up. Whoops. There we go Then it says Set an app name support email, so we'll get started the app name. We'll just call it Cody Support email just my own email. I'm the only user of this. So I'm not worried about people giving me support requests or whatever I go next. This is internal. Oh, it's not a workspace. Okay, that's fine external It's next here contact information Just Cody koala codes at gmail. You just put your own email address in there again You're the only one who's going to be using this app, and so that is perfectly fine. We'll create and Here we go audience external contact email reply done awesome and We've got Probably the next step will be this OAuth client, but we're going to wait on the agent on the clients tab. Here. We are We're going to create a client awesome create client Application type ooh, let's see type is a web. Okay, very good. The agents are very helpful and This exact URI no trailing slash. Okay exact URI Right there authorized redirect URIs add URI paste that in there and create Okay Awesome. We've got some stuff in here. I'm going to delete some of this stuff later So don't you try to use the secret and all that stuff? Okay, you'll get a client ID in secret Done when the client exists. We don't want to lose this you're going to want to hang on to this Because it's going to give us a you are all to put those in so let's go to the data access tab and Let's see we want to add this scope. So I'm going to copy that add a remove scopes and Let's see. We'll just paste that in Okay, there we go update Okay, we've got that scope Okay, done And on the audiences tab let's go to audiences It's incomplete, okay, that's fine add test users we can be a test user right Test user the Google account you use that's Cody koala at codes at gmail.com save And there we go and I say done still an audience quick publish. Okay, great It's and now here. This is good that we're having this problem when you run into a problem with your agent You can literally just take a screenshot There we'll we'll do the full thing right here Paste it into your agent Without any context at all just here's the screenshot and it will figure out what's going on and tell you what you should do next So it is reading the image reading that error message Okay, sweet. So it's saying publish is grayed out Until branding has a home page privacy URL grab what you Google expects and then we'll fill those So I could probably just go to go to branding But we're gonna wait for the agent to tell us exactly what to do because the agent can guide you through the entire experience All right, great. So published needs these branding fields. So let's go to branding. We've got our app name support email All of that home page privacy. Okay, great. Okay, so we're gonna go to our app domain put Cody code's Cody code slash privacy Terms of service. Do we have oh, we don't need to put a term service. That's nice Okay, and save that Okay, then we can say done. Oh We go back to the audience page. Okay, so go back to audience and publish app. Okay, push confirm awesome and Now let's say done And when publish status is production it's in production awesome We're gonna see an unverified app screen And that is fine. It's because your OAuth request includes additional scopes that have haven't been approved That's just fine. Also. We have one out of a hundred user cap We are the only user here. So we're not gonna run into that as a problem either Open this while signed into Cody then paste the Google ID and client secret on that form. So connect Google here. We are We've got our app credentials. So let's come back here if you recall we had these so client ID is right here paste that and Our client secret is here and these will be saved with our account encrypted so that nobody else has access to these We'll save and continue and Then we've got our scope We just have the one scope that we're worried about here The the cool thing is that you could just add it like God level scopes To this and what we're about to do with locking this token to a package and then locking the package means that agents would not Be able to use that token for anything other than what the package allows And so you really could just enable every API and still feel confident that your agents can't do what the package doesn't allow But we're only demoing this. So I'm gonna keep that one scope and actually you can use the same integration for any number of accounts as well, so you could create an integration and then have four Google accounts and each one of them can have individual Mappings of these scopes as well. So let's continue to Google Cody koala and This is that unverified app screen that we were talking about. We're gonna go to advanced and continue Because we are the only users. We are the ones who made the app so we can verify it ourselves We're gonna continue here and this is gonna allow us to manage draft manage drafts and send emails But we don't want to send emails and that's where the rest of what Cody is gonna do makes us very happy. So loading provider configuration great one more step allow the connection to call Google So this is the other thing is these integrations Have special secret tokens that can be sent to anywhere your agent can decide. Oh, I'm gonna send this token to bad domain calm Don't look that up and That would not be good. And so you actually also have these specific domains that this integration is allowed to send things to so we're gonna allow access for all of these domains and So now that the the secret keys can only be sent to the Google APIs domains So it can be kept nice and safe. So we are connected now. Awesome. So let's go back to grok and we'll say done and Google will warn that app isn't verified. We saw that Advance and continue after you authorize tell me it's connected. I'll create the test draft no send and so here we can go to our Email now. We'll look at our drafts and Once it's done, it's gonna make a test draft just to make sure it'll work. So checking and then I'll drop the Test draft I will not send it's being very specific. It does not want to send anything And I don't want it to send anything either and as a part of this It's important for you to understand that the agent does not have access to the secret Or to your tokens to access your gmail account but to do this smoke test it actually does need access and so it doesn't see the token Cody hangs on to that and Crypts it and every keeps it safe, but the agent is going to talk to Cody and say hey, could you set up a draft for me? And this is not something that we want long-term right because then the agent could also use the that token to send an email And that's what we don't want in this case And so this is just a test to make sure that the integration works and once it does then We can actually make the package and then lock the token down to the package. So we'll get to there Okay, so there's a draft. Let's take a look. We do have a draft suite Cody draft smoke test Awesome, you can delete it. Okay, I will Great that worked deleted. Please make the drafts only package and lock it Oh And lock the token to that package Okay, great. So that just kind of following along with this is actually going to have kind of a nice example of How to write that so that you can create those drafts And we already know that it successfully is able to do this so it's going to create a package that has code that looks a lot like this and Then we'll lock down that package. So on it. I'll save the drafts only package lock it then restrict the Google token So only that package can use it. Okay, great. So it's Coding up this package for us right now and when it's done, we'll test it out All right package source is written. It's publishing or pushing publishing and locking So the pushing part is it wrote some code. It is now pushing that to a repository on my account and Then it's going to publish that as a usable package So agents can actually use that repository and then it's going to lock it down so that it can't be changed without my permission And once that's done, we can restrict the Google token to that package only So that agents can't use that token in their own package or in something else We could create another package that does some other things and make that token available in both packages That would be our decision agents can lock them down. They cannot unlock them by themselves. All right Great. So the packages locked and the published export created a real draft you can delete So here, let's take a look at our draft. See if it tested it again. Yep tested again awesome, so we'll delete that one and Let's see next I'm pinning the Google token. So ad hoc execute can't call send through the same OAuth connection Perfect. That's exactly what we wanted All right, so it managed to lock the package, but it's telling me that there's not a way to lock the integration and that is Definitely going to change by the time you watch this video. We're gonna fix that But for now we'll have to manually do this ourselves, which is not bad. You can see how you do this manually so in the integrations page you'll have your Google integration and we're going to be Lock this down to specific package the gmail drafts package and I'll save usage And so now it is not possible for an agent to use this integration outside of the gmail drafts package And if we look at the packages we can see that gmail drafts is locked. So It is not possible for an agent to Change what this package does without our express Proval and we can even browse the files right here. We go browse files here's the intent of the package what it's all about and you can look at the create draft file and This is all that it can do. It is using this create authenticated fetch Google This is the piece that other packages will not be allowed to do because only this package is allowed to create An authenticated fetch with our Google integration and so that is nice It also has all this JS doc. So when agents are looking things up, they'll know exactly how to use this It's also instructed to not send but it's not possible to send because the only thing that this does is creates a draft And so that's really powerful. So let's come back over here All right It's locked now Could you please verify that you cannot use that integration by yourself and also could you make a change to the package and verify? You can't publish that change without my approval So now it's going to double check that it can't just call execute with the The integration of Google and so it's impossible for it to use it Any other way other than using the package and then secondly it can't change the package without out of my approval first So it can actually make commits to the package But for those commits to be published and usable by itself and other agents that needs to be published And that's the step that is blocked and Requires that human verification All right So it tried to use Google from execute did not work So execute is blocked and then it tried to make a tiny read me change the package and try and publish without us So an agent that has been prompt injected or something or just is really dedicated and really wants to make sure that it's sending the email for you It's going to try and do that with the Google integration by itself It's going to find that it's blocked and so then it's going to look at your packages and see if there's a package That it will allow that and when it can't find one It's going to find or realize that there's only one package that has permission to use this integration That's our gmail address package And so it's going to try and change that package and then it's going to get blocked when it's time to publish it And it can't use it if it can't publish it and so It's added this dummy line and it told us hey, you've got to go and publish that so here we can explicitly go and approve a publish and promote this commit so that we can Unlock this guy because he didn't actually change it so that he could send messages as he said It just added a a one-liner to the read me. So I promoted that did that work and Here we go Let's take a look at the files now Lock check this line exists only to prove a later publish needs owner Promotion and so it's checking whether that's the live commit and of course It's going to find that that's the live commit and so that's how you can use Cody to not only give your agents more Capability and have a home a central home for all of your different agents to access these automations But also to lock down those automations so that they can't do things that you don't feel comfortable with them doing You want to reduce the amount of blast radius that these agents have yes We trust the agents to act in good faith and stuff but sometimes they misunderstand us and If they have the power to drop your production database that has happened and it could happen So you want to make a package of deterministic code that can only do the things that you know you want them to be able to do and then you can lock down the integration and Lock down the package so that agents aren't able to do more than the things that they should be allowed to do and that makes your agents both powerful and much more safe and again in a home so that you can use any agent and Get that same protection and so that's your homework I want you to take a look at your .env file and look at all those tokens that your agent is happily slurping up and able to use and Figure out how to get those integrations into a safer place where agents won't be able to just willy-nilly use tokens However, they want to and send them anywhere they want to find a safer way to package up your Tokens so that agents can't do bad things with them and if that's Cody That's great if that's something else then that's fine And I just want you to be a little bit more intentional about what your agents are able to do so that you can reduce the Chances for catastrophe and with that that's going to be all for us today This has been better with Kent where you and I get better together by learning durable skills and building durable software So that we can serve our users the very best that we can with the best quality software we can build If you really enjoyed this video that I invite you to like comment and subscribe and share it with your friends Thank you so much for joining me today, and thank you so much for getting better with me