• ID: CF003.004
  • Created: 26th August 2026
  • Updated: 26th August 2026
  • Contributor: James Weston

Delegated Mailbox and Calendar Access

Delegated mailbox and calendar access occurs when a synthetic subject is granted permission to read, summarize, draft, send, forward, schedule, or route communications through an employee’s mailbox or calendar.

 

This configuration creates an elevated exposure condition because the synthetic subject can act through high-trust communication channels. It may process inbound messages, retrieve attachments, summarize threads, send replies, schedule meetings, forward information, or route calendar events using the employee’s communication context.

 

The primary risk is communication authority through a human identity. A synthetic subject may disclose sensitive information, send unauthorized messages, create misleading commitments, forward internal content, or schedule actions that appear to come from the employee.

Investigators should review mailbox permissions, calendar permissions, delegated access grants, OAuth scopes, sent items, forwarding behavior, calendar event history, prompt logs, and message audit records. Particular attention should be given to external recipients, sensitive attachments, unusual forwarding, automated replies, and calendar actions associated with AI tools.

 

Investigative Relevance

Delegated mailbox and calendar access is relevant because mail and calendar systems are trusted channels for organizational action. This sub-section is especially relevant where AI tools can send messages, forward content, schedule meetings, process attachments, or act on inbound communications through a human account.