# Six agents, one inbox: what changed in v1.2.0, sgit.ai

> The changes to the article "Six agents, one inbox" in v1.2.0, paragraph by paragraph.

*Source: <https://sgit.ai/articles/versions/six-agents-one-inbox/v1.2.0.html> · site v0.7.38 · this file is generated from the same content as the page, so the two cannot drift. Every page on this site has a `.md` twin; internal links below point at them.*

---

[Home](../../../index.md) / [Articles](../../index.md) / [Six agents, one inbox](../../six-agents-one-inbox.md) / [Versions](../six-agents-one-inbox.md) / v1.2.0

# Six agents, one inbox: what changed in v1.2.0

From v1.1.0 (2026-10-02, `23d0aad35`) to v1.2.0 (2026-10-05, `4d6a7b929`), paragraph by paragraph.

0 paragraphs added, 0 removed, 3 changed in place, 66 unchanged. About 0 words added and 0 removed. Insertions are marked like this, deletions like this; unchanged runs are folded to one line; figures appear as their file names.

[← v1.1.0](v1.1.0.md) · [all versions](../six-agents-one-inbox.md) · [v1.2.1 →](v1.2.1.md)

9 unchanged paragraphs, under In short

• **Enforcement is a ladder, and most rules sit on the bottom rung.**step.** Identity boundaries and cryptographic keys enforce themselves. Compliance rules enforce at the platform. Approval prompts enforce at the human. Everything else is the agent doing as it was told. The table at the end grades every rule in the setup.

26 unchanged paragraphs, under The setup, and what it costs, Finding one: the account does more than segregate, Finding two: the exception arrived before the policy…

Here is the catch I promised in finding one. The Gmail API's [scopes](https://developers.google.com/workspace/gmail/api/auth/scopes) put drafting and sending in the same grant: `gmail.compose` is *"Manage drafts and send emails,"* and `gmail.modify` is *"Read, compose, and send emails."* There is no scope that allows drafts and forbids sending. So the Workspace admin's scope limit, the sharpest tool in the box, cannot express the one rule the mailbox agent most needs, *drafts only*. That rule has to be enforced one rungstep down the ladder, by a delivery restriction on the unit, or by an approval prompt, or by the agent doing as it was told.

5 unchanged paragraphs, under Where the reach differs: Cowork and Claude Code, The table

!shot six-agents-ladder.webp | images/ | Where a rule is enforced, from the top of the ladder down. Identity and keys enforce themselves. Compliance rules enforce at the platform, per organisational unit. Approval prompts enforce at the person. Below that, a rule is the agent doing as it was told. Every rule in the table sits on one of these rungs,steps, and the policy is as strong as its lowest.

26 unchanged paragraphs, under What I would tell somebody starting this, What exists today, and what does not, Sources

[← v1.1.0](v1.1.0.md) · [all versions](../six-agents-one-inbox.md) · [v1.2.1 →](v1.2.1.md)


---

*[Site index for agents](../../../llms.txt) · [HTML version](https://sgit.ai/articles/versions/six-agents-one-inbox/v1.2.0.html)*
