π Day 162 β An AI Secretary With a Kill Switch: Calendars, Sender Policy, and Emergency Control
π Topic
Hermes became a real secretary: it can read my calendars and handle personal email β so before it got those powers, it got a sender policy, an approval flow, and a remote emergency stop.
π― Goal
Give the agent genuinely personal capabilities (calendars, email) while keeping every risky action behind policy, and keep one guaranteed way to stop everything from anywhere.
π What I Did
I wired personal-data integrations and their controls in the same session.
Main areas covered:
- gave Hermes access to macOS Calendar via icalbuddy, tested with real queries like finding a specific personβs next birthday
- consolidated the scattered calendars onto Apple Calendar so the agent queries one source of truth instead of guessing
- handled locale details properly β Italian date formats, accented names β because a secretary that mangles βNiccolΓ²β fails at its one job
- rolled out a personal email sender policy: the agent may only send to defined recipients, and anything else requires explicit approval
- added the approval flow for out-of-policy sends rather than silently blocking or silently allowing
- built a remote emergency control β a way to stop the secretaryβs autonomous behavior from my phone, immediately, without SSH
- cleaned up superseded local models as part of the same hygiene pass
π Key Cybersecurity Connections
Calendars and email are the most personal data an agent can touch: who I know, where I am, what I say. Granting that access is a privacy decision, and the controls mirror real-world ones β the sender policy is an egress allowlist, the approval flow is exception handling with a human decision, and the emergency control is the incident-response requirement that every autonomous system needs a stop that works when things are weird.
π Investigation Questions
- Exactly which calendars and mailboxes can the agent read?
- Can it send to anyone outside the policy list without an approval?
- Does the emergency stop work when the normal channels are down?
- Are the agentβs calendar queries logged somewhere reviewable?
- What is the blast radius if the secretary misbehaves for an hour before I notice?
π¨ Detection Opportunities
Checks for a personal-assistant agent:
- send attempt to a recipient outside the sender policy
- approval flow bypassed or auto-approved
- emergency stop invoked β always worth reviewing what prompted it
- calendar queries spiking outside normal usage
- policy file modified without a corresponding decision record
Example:
project=hermes-secretary
signal=send_attempt_outside_sender_policy
risk_area=unauthorized_personal_communication
triage=hold_message_review_policy_and_approval_log
π§ MITRE ATT&CK Techniques
Possible mappings for the risks being controlled:
- T1114 β Email Collection
- T1534 β Internal Spearphishing
The sender policy and approval flow exist so the secretary cannot drift into these.
πΊ Visual Investigation Diagram
Personal capability requested
β
Policy written first (who, what, when)
β
In policy β act
Out of policy β approval flow
β
Everything β logged
β
Emergency control β stop all, from anywhere
β Challenges
The subtle work was data quality: an assistant is only trustworthy if its source is. Consolidating calendars mattered as much as any control, because an agent confidently answering from an incomplete calendar is wrong with authority.
π What I Learned
I learned to build the stop button before the feature. Writing the emergency control while the capability was still new took an hour; retrofitting it after an incident would have been a very different story.
β‘ Next Steps
- Test the emergency control routinely, not just once
- Review the sender policy list on a schedule
- Extend logging to calendar query patterns
- Keep new personal capabilities behind the same policy-first pattern
π§ Reflection
Handing an agent my calendar felt more sensitive than handing it a filesystem. Data about people demands a different level of care than data about code, and the controls should show that.
π§© Lessons Learned
What worked
Policy and kill switch shipped in the same session as the capability.
What broke
Early calendar answers were wrong because the calendars themselves were fragmented.
Why it broke
Years of events scattered across accounts with no single source of truth.
Fix / takeaway
Fix the data before trusting the agent that reads it β and never ship a personal capability without its stop button.
π Skill Progression Context
This supports my cybersecurity progression because egress policies, exception approval flows, and emergency-stop design are the same controls that govern privileged automation in any organization.
π TL;DR
The secretary got my calendar and my inbox β after it got a policy, an approval flow, and a kill switch.
