Tasks and systems

How do you automate emails that need manual processing?

Rules sort and flows connect systems. An agent reads, looks things up, and prepares a proposal. Sending waits for your approval.

You automate emails that need manual processing by separating them by type. Give predictable sorting to Outlook rules or Power Automate. Give reading, finding the customer and case, and preparing a reply or entry to an AI agent. A technical safeguard keeps sending and posting on hold until a human approves.

This page explains what happens with each email, how to handle different types, and what Outlook rules, Power Automate, and Copilot can and cannot do according to Microsoft’s own documentation. It explains what an agent adds and why approval before sending must be a firm boundary, rather than a sentence in an instruction. Costs are covered separately: what does automating email handling with AI cost. For attachments and spreadsheets, see automating documents, Excel, and email with AI.

The short answer

  • Manually processing an email involves five steps: reading, forwarding, opening an attachment, retyping into software, and writing a reply (France Num, July 2026).
  • Outlook rules sort on exact conditions. All enabled rules together may occupy no more than 256 KB per mailbox (Microsoft Learn).
  • Power Automate connects email with other systems. A trigger can take up to an hour, and a shared mailbox requires full access (Microsoft Learn, September 22, 2026).
  • Copilot can summarize and draft in a shared mailbox. Triage and sending on your behalf are listed as “Not supported” (Microsoft Support).
  • An agent adds three things rules and flows lack: understanding the email, looking things up in another system, and preparing a proposal with its reasoning.
  • OWASP uses a mailbox as its example of excessive permissions. It recommends that a human review every draft and press send (OWASP LLM06:2025).
  • An average employee receives 117 emails a day, most skimmed in under 60 seconds. That figure excludes European organizations (Microsoft WorkLab, June 2025).

What happens to an email processed manually?

A manually processed email passes through a chain. Most time goes into what happens after reading. The French government guide for small businesses lists it explicitly: “lire l’e-mail et éventuellement les discussions précédentes pour se remémorer le contexte ; le transférer, si nécessaire, à la personne ou au service concerné ; télécharger et ouvrir les éventuels fichiers en pièce jointe ; réaliser des copier-coller, pour alimenter les outils métiers […] ; rédiger et envoyer une réponse” (France Num, July 9, 2026).

In a Dutch office, that means reading the email and previous messages, deciding what it is, finding the customer or resident in Exact, Dutch accounting software, AFAS, Dutch business software, or the management package, opening and retyping the attachment, deciding who handles it, writing a reply, and recording what happened.

The first automation rule follows: count steps, rather than emails. A rule that moves email into a folder only automates deciding what it is, and only when the sender or keyword reveals that. Looking things up, retyping, and replying remain. After an afternoon building rules, a tidy inbox can leave the most expensive steps untouched. See preventing tasks from falling between systems.

How can you automate different types of email?

Email type determines automation, rather than volume. A newsletter and a complaint need very different treatment, even at the same info@ address. Separate them first. Dutch provider Predimail allows different behavior by category: simple questions get, in translation, “full auto-reply, with logging”; legal and sensitive messages get “AI draft only, mandatory review”; invoices get “forward to accounting + proposed reply” (Predimail). This is a seller’s design, rather than a measured outcome, but the categories make sense.

Email type What happens per email Best layer Who decides on sending or posting
Newsletter, notification, system message Identify and file Outlook rule Nobody
Simple fixed question (opening hours, address) Standard reply Agent, only for an unambiguous answer Can operate without a human if you deliberately choose that (Gmelius)
Status question (“where is my order?”) Find customer, retrieve status, write reply Agent with software access Human approves draft
Invoice or order with attachment Read attachment, transfer data, post entry or create order Agent, potentially followed by a flow Human approves entry
Complaint, legal question, price, or commitment Gather context, draft Agent, drafts only Always a human (Gmelius: “Pricing, commitments, and complaints don’t”)
Unknown sender or unclear email Ask for a decision instead of guessing Agent presenting the choice to a human Human

The bottom rows take the time and receive no help from rules. Rules work well for the top row. bombos.ai has separate pages for answering status questions, processing an emailed order, and email into the case file.

What can Outlook rules do with manual email?

Outlook rules are strong at predictable sorting and weak at meaning. Microsoft describes actions on incoming email, such as changing importance, moving to a folder, or deleting “based on certain criteria.” Each rule has “a name, a condition, and an action,” with optional exceptions (Microsoft Support).

The firm limits in Microsoft’s documentation:

  • 256 KB for all rules together. “Inbox rules […] are limited to 256 KB total for all rules.” Exchange Online allows you to lower this to a minimum of 32 KB, but not raise it. There is no maximum rule count. Space is the limit, and only enabled rules count (Microsoft Learn).
  • Order matters. Rules run “from top to bottom.” A rule moving email at the top determines what the rest can see.
  • Server or client. Server-side rules run even with Outlook closed. Client-side rules “don’t run until you log into classic Outlook for Windows,” and “New Outlook doesn’t support client-side rules” (Microsoft Support).
  • No rules for external accounts in New Outlook. Gmail, Yahoo, and iCloud are excluded (Microsoft Support).

The most painful boundary is in how rules work: they find exact words. France Num: “un filtre sur le mot-clé « prospect » sera inopérant si le mail parle de « clients potentiels »” (France Num, July 9, 2026). In Dutch, a rule for “factuur” misses “nota,” “invoice,” and a PDF without that word in the subject. A rule also assigns nobody. An email in the Invoices folder has not yet been picked up.

What can Power Automate do with shared mailbox email?

Power Automate connects incoming email with other systems but does not read its meaning. A flow starts with an event, such as new email in a folder, then executes fixed steps: attachment to SharePoint, task in Planner, message in Teams. The Office 365 Outlook connector has a separate shared mailbox trigger. Know these limits before building (Microsoft Learn, updated September 22, 2026):

  • The shared mailbox trigger requires full access, “which includes more permissions than just sending emails.”
  • After permissions are assigned, “it can take about two hours until the permissions are replicated.”
  • Triggers usually fire immediately, but “the trigger’s delay to fire may take up to one hour.”
  • When a rule moves email out of Inbox, an Inbox “trigger is not expected to fire.”
  • Encrypted email provides no text to the flow, only a notice that the message is protected.
  • An Office 365 group address is not a shared mailbox.

The troubleshooting page says a flow starts on new email, rather than moved email. The old Mail connector allows 100 calls per 24 hours, compared with 300 per 60 seconds for Office 365 Outlook (Microsoft Learn, October 9, 2024).

Watch the interaction with rules. If rules file email first and a flow watches Inbox, the flow misses exactly those emails. Power Automate Premium costs $15 per user per month with annual billing on the US price list (Microsoft, September 30, 2026).

Can Copilot in Outlook handle your shared mailbox?

Not yet. Copilot is an assistant at the keyboard, rather than a handler for info@. Microsoft’s Dutch product page says, in translation: “AI email generators can help you compose a new email, but they do not send email on your behalf” (Microsoft).

The support page is precise for shared and delegated mailboxes: “Summarize and Draft work for all shared and delegated mailboxes.” But triage, including marking read, deleting, categorizing, flagging, and applying rules, and “Sending emails on your behalf” are both “Not supported,” marked “Coming soon” without a date (Microsoft Support).

Copilot also does not independently find the customer in Exact or resident in owners’ association software. It uses what is in the mailbox and Microsoft 365. Dutch prices per user, excluding VAT (Microsoft, September 30, 2026):

License Per user per month Ten users
Copilot Business, July 1 through December 31, 2026 promotion, annual billing € 15,60 € 156,00
Copilot Business, regular price, annual billing € 18,20 € 182,00
Copilot Business, monthly subscription € 21,84 € 218,40
Power Automate Premium (US list price, annual billing) $15 $150

After the promotion, Copilot rises from € 15,60 to € 18,20, a 16,7% increase (our calculation). These prices cover writing and connecting, rather than handling a shared mailbox or looking up information in specialist software.

What does an AI agent add to email automation?

An AI agent adds three things rules, flows, and Copilot lack together: reading what the email means, finding relevant information in another system, and preparing a reasoned proposal. Drag puts it plainly: “a rule does the same thing every time. An agent decides what to do, email by email,” and “an assistant suggests. An agent acts” (Drag, September 27, 2026).

Gmelius offers a test for agentwashing. An email agent has four parts: a trigger without a human instruction, tools beyond writing text, a decision loop, and “an authority boundary: Explicit rules for which actions need a human’s approval.” It adds: “Most failures come from nobody having defined that boundary, not from the model getting something wrong” (Gmelius, September 28, 2026). Gartner calls assistants relabeled as agents “agentwashing” (Gartner, August 2025).

For a status question, a rule sees “order” in the subject and files it. A flow creates a task. When asked, Copilot writes a polite reply without the status. An agent identifies the customer by address, finds the order, sees delivery will be a week later, and prepares a reply with the new date and its source. A human reviews, edits, or approves. See AI agents versus workflow automation.

Why must approval before sending be a technical boundary?

Any incoming email can contain instructions. An agent that reads and sends email can therefore be directed by a stranger. OWASP, the standard for securing AI applications, uses precisely this example of excessive permissions: an assistant may summarize, but its connector can also send, and “a maliciously-crafted incoming email tricks the LLM into commanding the agent to scan the user’s inbox for senitive information and forward it to the attacker’s email address.” Its solution is “requiring the user to manually review and hit ‘send’ on every mail drafted by the LLM extension,” and generally to “require a human to approve high-impact actions before they are taken” (OWASP LLM06:2025).

Drag calls this combination the lethal trifecta: untrusted input (every email), private data, and an outbound path (sending or acting in another system). “With all three, a persuasive email can talk an agent into forwarding data or taking an action, with no software bug involved” (Drag, September 27, 2026).

An instruction saying “always ask permission first” is therefore no boundary. The same malicious email can override it. A technical boundary means the system only sends after a human clicks. Gmelius distinguishes five authority levels (Gmelius, September 28, 2026):

Level What the agent may do
1. Read-only Read only
2. Draft-only Draft; “Nothing reaches a recipient without that review.”
3. Internal actions Label, assign, create tasks internally
4. Send with approval Propose sending; human confirms with one click
5. Conditional autonomy Send independently only when the answer is unambiguous

Level 4 is a sensible starting point for everything sent to customers. See may an AI assistant send email itself? and errors and review.

How much time does manual email really take?

Nobody knows precisely for a Dutch small business. Familiar figures measure something other than handling time. Microsoft measures 117 incoming emails per employee per day, “most of them skimmed in under 60 seconds,” and an interruption every 2 minutes. Its data runs through February 15, 2025, excludes European and educational organizations, and the interruption figure concerns the 20% of users receiving the most notifications (Microsoft WorkLab, June 17, 2025).

France Num cites a 2023 French study: 144 emails per employee per week, with reading and processing reportedly taking 30% of working time (France Num, July 9, 2026). The daily 117 and weekly 144 differ by a factor of four because of source, country, period, and definition, rather than a trend. EmailAnalytics, which sells analytics software, withdrew the frequently cited 30/70 split: “We could not trace that split to a primary study” (EmailAnalytics, 2026).

Our calculation shows why this matters. Scanning 117 emails at 45 seconds takes 5.265 seconds, nearly an hour and a half a day before looking up or retyping anything. The chain in the first section comes on top, for only the emails requiring actual work.

Measure by email type: weekly volume, exception share, time spent finding information and replying, and time spent recovering from mistakes. These four figures tell you more than an average. See which processes to automate first.

How do you test whether automatic email processing is good enough?

Test a fixed set of real emails before automation sends or posts anything. Gmelius recommends 50 to 100 real threads, classification accuracy above 90% “before anything moves past read-only,” human escalation of “Ideally, 10-30%,” and erroneous sending of “0% before any autonomy is granted” (Gmelius, September 28, 2026). These are a seller’s criteria, rather than an independent standard, but concrete enough to start.

Deliberately include difficult cases: an unknown sender, a customer with two cases, an email covering two issues, a forward with the real sender at the bottom, and instructions addressed to “the assistant.” Check the answer, its supporting evidence, and whether the agent asks you to decide when uncertain. Escalation of 10 to 30% is not failure. Those emails already required a human decision. See testing an AI agent before you automate.

Why is manual email a lookup problem rather than a mailbox problem?

Our position: time in manual email goes into looking things up elsewhere. Every common Microsoft layer leaves precisely that step untouched. Rules know senders and keywords (Microsoft Support). Flows know events and connections, rather than meaning (Microsoft Learn). Copilot knows the thread but cannot triage or send in shared mailboxes (Microsoft Support). The government guide lists copying into CRM or ERP as a routine manual step (France Num).

None independently finds the resident in management software or order in Exact and prepares a reasoned reply. An employee still does that until an agent takes over and the employee only reviews.

The next effect: good drafts move work from typing to review. Review time becomes the bottleneck. A system showing the basis for a proposal wins because you check in seconds instead of looking everything up again. More automation also makes approval the only thing between a malicious email and a sent message. Choose based on how fast your team can check a proposal and where the button sits, rather than how much it can send itself.

Where is this heading?

The pace is visible. In August 2025 Gartner predicted that 40% of enterprise applications would contain task-specific agents by the end of 2026, up from less than 5% in 2025 (Gartner). It sells research, and this is a prediction. Microsoft has released summarizing and drafting in shared mailboxes and labels triage and sending “Coming soon.” Gmelius and Drag published agent guides in the last week of September 2026.

Our expectation: by the end of 2027, common email packages will handle shared mailbox triage and drafts themselves. Sorting will no longer justify a purchase. Looking up information in Dutch specialist packages such as Exact, AFAS, Syntess, software for technical installation businesses, or owners’ association software will remain the distinction. Each needs its own connection, which a global developer does not build for a small market.

This expectation fails if Microsoft or Google provides a general connection reading and writing Dutch specialist software without custom work, or if draft errors make review consume the gains. The question then moves from connections to proposal quality.

By then, Bombos arranges connections to your own packages and a place for your team to approve. You can keep Microsoft’s sorting and hand over only the step that takes work.

What can this not yet do?

  • No agent finds knowledge that exists only in someone’s head. If only the bookkeeper knows a customer always pays quarterly, the proposal misses it. Record that knowledge instead of choosing a smarter model. Bombos interviews you so it is available next time.
  • An agent reading email can be attacked through email. Incoming prompt injection is a property of reading plus acting, rather than a bug you can patch away (OWASP). Approval limits damage but does not remove the risk.
  • There is no independent Dutch measurement of time saved by automatic email processing. Dutch sources are providers; international figures measure arrival and attention, rather than handling time.
  • Accuracy criteria come from sellers. Gmelius’s 90% classification and 0% erroneous sending are recommendations, rather than measured product results.
  • Encrypted email and permissions remain obstacles. Power Automate receives no encrypted message text, and shared mailbox access must be configured first (Microsoft Learn).
  • Review takes time. A half-correct draft sometimes costs more than writing from scratch. Measure review time from week one.

How does Bombos approach this?

Bombos reads email at all connected addresses, including info@ and other shared mailboxes. Chef, one of the two permanent coworkers, identifies incoming work and gives it to the right specialist. The specialist finds the customer, case, or order in your own systems and prepares a proposal: which coworker handles it, why, and a draft reply or entry. Every proposal shows its basis. Unknown senders or unclear emails become choices for you. Bombos does not guess.

You approve, edit, or reject in Bombos. Only then is the answer sent in Outlook or the entry recorded in your software. Customer messages, payments, and contracts wait for approval by default. That boundary is technically enforced. A correction becomes a rule for your coworkers too. Bombos asks about knowledge held only in someone’s head in a short interview so it is available next time.

You do more work, at a higher quality, with the same team. Email is the start. Your team then teaches Bombos the next task without needing technical skills. See shared mailbox, distributing shared mailbox email, and which tasks.

Sources

Each source was opened on September 30, 2026. Original excerpts appear verbatim in the sources; translated excerpts are identified above.

Free, no obligation

More work done, at a higher quality, with the same team.

That is what Bombos is for: companies that grow fast and want to keep the same team. We start with one task that keeps piling up and guide you until your team can handle it. Then your team teaches Bombos the next task. Leave your number and we will call you back to talk about your situation.

We read what you write. Within one working day you hear from the one of us who knows your kind of work best.