AI inbox triage: classify, route, draft

2026-07-26 · 7 MIN READ · WORKFLOWS

AI inbox triage: classify, route, draft

How do I use AI to sort and answer a shared inbox without it sending something wrong?

Classify each message into a small fixed set of categories, route it using deterministic rules wherever a rule exists and the classifier only for what is left, and have replies written into the drafts folder for a person to approve. Nothing involving advice, money, deadlines or complaints should ever send itself.

What does AI inbox triage actually do?

It reads each incoming message, decides what kind of message it is, puts it where it belongs, and where appropriate writes a starting draft. It does not answer your mail for you.

The value is easier to see when you count the real cost of a shared inbox. Someone opens every message, works out who it is for, forwards it, and often re-reads it later because the forward carried no context. A small tax on every message, a large one across a year, and almost entirely mechanical.

Triage removes the mechanical part. What lands in a fee earner's queue is a message already sorted, already attached to a client or matter where one exists, and often with a draft attached. What they still do is read it and decide.

What categories should you classify into?

Six to eight, defined so precisely that two people in the practice would sort the same message the same way. If your own staff would disagree about which bucket something belongs in, a model will be inconsistent too.

A workable starting set for a professional firm:

  1. New enquiry. Someone who is not currently a client, asking about work.
  2. Existing client, existing matter. Correspondence attached to something already open.
  3. Existing client, new request. A live client asking about something outside the current scope. Worth separating, because it is revenue that often gets treated as admin.
  4. Supplier, invoice or account. Bills, statements, software notices, anything that ends up in accounts payable.
  5. Statutory, regulator or institution. Anything from a government body, court, professional body or bank. This one is defined by sender, never by content, and it always goes to a person.
  6. Recruitment, sales or unsolicited. The cold outreach that fills every info@ address.
  7. Internal and system notifications. Automated messages from your own tools.
  8. Unclear. The honest bucket. Anything the classifier is not confident about lands here and a person looks at it.

That last category is the one people leave out, and it is the one that keeps the system trustworthy. A classifier forced to choose will always choose, and a confidently mis-sorted regulator letter is exactly the failure you cannot afford. Set a confidence threshold, and route everything below it to a human without apology.

Add a separate urgency flag rather than an urgency category. Urgency cuts across every category, and a message can be an existing-client matter and time-critical at once.

Should the AI decide the routing?

Only for what rules cannot handle. Route deterministically wherever the information already exists, and use the classifier for the residual.

A surprising share of a shared inbox can be sorted without any AI at all:

  • Sender domain matches an existing client record, so it is client correspondence
  • Sender is your accounting software, your bank, the tax office or a regulator
  • Message is a reply to a thread already assigned to a matter
  • Recipient address is one you only publish in one place, such as a form endpoint

Rules of that kind are cheap, instant, auditable, and they do not change their mind. Use them first, then let the classifier work on what is left: genuinely ambiguous mail from unknown senders.

Route to a named person or a small queue, never to "the team". Anything with no obvious owner goes to whoever owns the unclear bucket. A shared inbox reorganised into smaller shared inboxes has not solved anything.

How should drafted replies work?

The draft is written into the drafts folder against the original thread, addressed and ready to send, and it waits there until a person reads it. The automation never sends it.

This is where the time saving comes from: a good draft is faster to correct than a blank page is to fill. The categories where drafting genuinely helps are narrow:

  • Acknowledgement of a new enquiry, confirming receipt and what happens next
  • Requests for the standard missing information an enquiry almost always omits
  • Booking and scheduling replies, pointing at whatever calendar link you use
  • Routine document requests where the list is the same every time
  • Straightforward status responses on an open matter, drawn from your practice management system

Give the model your real reply history for the category so the draft sounds like the firm rather than like a chatbot. Plain Australian English, the firm's own phrasing, no exclamation marks, no filler.

Mark drafts visibly. A short internal note at the top of the draft body, stripped before sending, saying what the classifier thought and how confident it was. That way the reviewer knows what assumption they are approving.

What should never be sent automatically?

Anything that gives advice, quotes a figure, commits to a date, touches money, responds to a complaint, or concerns a person's matter. That covers most of the mail in a professional practice, which is the point.

The permanent do-not-auto-send list:

  • Advice of any kind, including anything that could be read as advice
  • Fees, quotes, estimates, discounts or payment arrangements
  • Deadlines, lodgement dates, limitation periods or any commitment to timing
  • Anything to a regulator, court, professional body or insurer
  • Complaints, disputes, or any message with an unhappy tone
  • Anything involving a person's identity documents or personal information
  • First contact with a new client where a relationship is being formed
  • Anything the classifier was not confident about

The list you can auto-send is short and dull by comparison: a receipt acknowledgement to a new enquiry, an out-of-hours note, a confirmation that a form was received. Even those should carry a plain line saying a person will respond, because they will.

Some firms leave auto-send off entirely and lose very little. The drafting is where the hours are.

What about client confidentiality?

Assume every message in the inbox is confidential. Classification means sending message content to whatever service does the classifying, which is a decision worth making deliberately rather than by default.

Practical steps that make it defensible:

  • Use your own accounts and API keys, so the terms, the retention settings and the audit trail belong to the firm rather than to a vendor's shared arrangement.
  • Send the minimum. Subject line, sender and the first part of the body are usually enough to classify. Attachments rarely need to go anywhere.
  • Know where processing happens and what the provider retains, and record it.
  • Keep the drafts in your own mail system, not in a third-party tool that holds copies of client correspondence.
  • Log every classification and route so you can reconstruct what happened to a message months later.

Confidentiality duties and privacy obligations vary by profession, and they are yours rather than your vendor's. Check the arrangement with your professional body before it goes live. In a firm handling client information, that is the part that decides whether the build is usable.

What to do next

Run the classifier in shadow mode for two weeks: every message classified and logged, nothing moved, nobody affected. At the end you have a plain accuracy figure on your own mail and a list of categories to redefine. Most firms change their category set after seeing it.

Then switch routing on for the two safest categories, usually supplier mail and unsolicited outreach, and leave everything else manual. Add drafting for enquiry acknowledgements once routing has been quiet for a fortnight.

Keep the unclear bucket forever, keep auto-send off until you have a specific reason to turn it on, and make sure the workflow stops and tells someone when it breaks rather than guessing. If you would rather have it built in your own accounts and handed over documented, that is a standard Shift build, and the sequence does not change.

Common questions

Is it safe to let AI reply to emails automatically?

Automatic sending is safe only for a narrow class of message where being wrong costs nothing, such as acknowledging that an enquiry was received. Anything containing advice, a figure, a date, a commitment or a response to a complaint should be drafted and held for approval. The drafting saves most of the time anyway; the sending is where the risk sits.

How accurate is AI email classification?

Accuracy depends far more on how clearly you define the categories than on which model you use. Vague or overlapping categories produce inconsistent results no matter what is doing the sorting. Measure it on your own mail for a fortnight before trusting it, and keep a low-confidence bucket that goes to a person.

What happens to confidential client information in the inbox?

It gets sent to whatever service does the classification, which is why the vendor, the region the data is processed in, and the retention terms all matter. Use your own API keys so you control the account and the terms, and check the arrangement against your privacy obligations and any professional confidentiality duties before you switch it on.

Next step

Work out what yours is costing.

The calculator on the home page takes about ten seconds, and the fit call is thirty minutes with no deck. If the honest answer is "not yet", you'll hear that.