# Agent Activity And Sandbox

> Agent Control helps workspace owners investigate operations performed by scoped API keys or OAuth apps and test new workflows with bounded synthetic data.

- Human page: https://mailrith.com/docs/agent-activity-and-sandbox
- Markdown page: https://mailrith.com/docs/agent-activity-and-sandbox.md
- Category: AI Writing
- Reading time: 8 min read
- Last updated: 2026-07-22
- Related keywords: Agent Activity And Sandbox, Agent Activity And Sandbox documentation, AI Writing, AI Writing documentation, Mailrith documentation, Mailrith help, How Agent Authorization Works, Open Agent Control, Investigate Agent Activity, Enable Agent Sandbox, Manage Agent Sandbox, Resolve Agent Problems, Agent Safety Checklist, API Keys and Authorized Apps, AI Connections, Broadcasts

## AI Agent Notes
- Use this article as step-by-step Mailrith product guidance, not as legal, financial, or deliverability advice unless the article says so.
- Preserve exact Mailrith UI labels from the steps when explaining a workflow.
- Prefer Mailrith's product term Subscribers when referring to people on an email list.

## What this guide covers
Review redacted agent activity and test agent workflows safely in an isolated sandbox workspace.

## Sections
- How Agent Authorization Works
- Open Agent Control
- Investigate Agent Activity
- Enable Agent Sandbox
- Manage Agent Sandbox
- Resolve Agent Problems
- Agent Safety Checklist

## Visual Reference
![Mailrith Agent Control showing compact redacted activity for agent operations.](https://mailrith.com/docs/screenshots/agent-control.png)

Agent Control lets a workspace owner inspect safe activity metadata and use an isolated synthetic-data sandbox.

## How Agent Authorization Works

Mailrith uses API key and OAuth Permissions to decide what a connected agent or app can do. A connection with a read Permission can read only the matching resource. Sending, bulk changes, deletions, and administration each require their own Permission.

Mailrith does not ask the workspace owner to approve every action again. If a credential has the required Permission, the operation runs directly and Mailrith records compact, redacted activity metadata. Revoke the API key or Authorized App when the connection should no longer have access.

## Open Agent Control

1. Sign in to Mailrith.
2. Use the workspace selector at the top of the left sidebar to choose the workspace the agent uses.
3. Under **Account** in the left sidebar, click **Integrations**.
4. On the **Agent Control** card, click **View**.
5. Use **Activity** to investigate operations or **Sandbox** to test a new workflow.

Only the workspace owner can use Agent Control. API keys remain under **Settings** → **API Keys**, and OAuth connections remain under **Integrations** → **Authorized Apps**.

## Investigate Agent Activity

1. Open **Integrations**, click **View** on the **Agent Control** card, and stay on **Activity**.
2. Enter an exact **Operation**, **Request ID**, or **Activity ID**, or choose an **Outcome**.
3. Click **Apply Filters**. Activity searches cover up to 30 days and return 25 rows at a time.
4. Click a row to review the operation, credential, required Permissions, attempts, duration, result resource, and changed field names.
5. Click **Load Next Page** when more results are available.
6. Click **Export Current Page** to download only the current bounded page.
7. To remove a terminal record, click **Delete Activity** and confirm. A record under a legal hold cannot be deleted.

Activity does not store request bodies, email content, Subscriber names or email addresses, custom-field values, provider credentials, webhook secrets, or raw provider responses. Use **Clear Filters** to return to the recent seven-day view.

## Enable Agent Sandbox

Agent Sandbox is available only for a new workspace with no existing resources and no email delivery connection. It creates a fixed, small set of synthetic Subscribers, a form, a segment, a Broadcast, form events, and engagement totals.

1. Create a new workspace and leave it empty.
2. Choose that workspace from the workspace selector.
3. Open **Integrations**, click **View** on the **Agent Control** card, then click **Sandbox**.
4. In **Allowed Test Recipients**, enter up to 20 email addresses, one per line.
5. Click **Enable Agent Sandbox**.
6. Wait for **Sandbox On** and the synthetic data totals to appear.

Sandbox Broadcast sends and workflow activations are simulated. They do not enter ordinary provider or delivery queues. External webhook actions are blocked, and an ordinary email delivery connection cannot be added to a sandbox workspace.

## Manage Agent Sandbox

1. Open **Integrations** → **Agent Control** → **Sandbox**.
2. Edit **Allowed Test Recipients**, then click **Save Settings**.
3. To replace the seeded data, click **Reset Synthetic Data**.
4. Read the confirmation. Mailrith removes only resources recorded in the current seed manifest. Resources you created are not removed.
5. Click **Reset Synthetic Data** in the confirmation dialog.

## Resolve Agent Problems

### Fix A Permission Failure

1. For an API key, open **Settings** → **API Keys**. For an OAuth app, open **Integrations** → **Authorized Apps**.
2. Find the connection and check its status, Permissions, expiration, and recent use.
3. If the connection is active but the operation is denied, create or reconnect it with the smallest Permission set that includes the operation.
4. If it is expired or revoked, reconnect the Authorized App or create a new task-specific API key.

### Investigate An Uncertain Outcome

1. Stop the agent from retrying the operation.
2. Open **Agent Control** → **Activity**, enter the exact **Request ID**, and click **Apply Filters**.
3. Open the result and check its target, result resource, attempts, and failure code.
4. For a Broadcast, open **Campaigns** → **Broadcasts**, select the Broadcast, and check its progress before taking another action.
5. Contact Support when Mailrith and provider evidence do not show one clear final outcome. Share only the workspace name, request or activity ID, time, and client version.

## Agent Safety Checklist

- Grant only the API or OAuth Permissions the workflow needs.
- Use separate credentials for unrelated workflows.
- Run new write workflows in Agent Sandbox before using a production workspace.
- Use an idempotency key for supported writes and reuse it only for the same logical operation.
- Check Agent Activity before retrying an uncertain operation.
- Revoke an API key or Authorized App as soon as the connection should no longer have access.

## Related Guides
- [API Keys and Authorized Apps](https://mailrith.com/docs/api-keys-and-authorized-apps.md): API keys and authorized apps control how outside systems access a workspace. This guide explains when to use each credential type, how to create credentials safely, and when to revoke access.
- [AI Connections](https://mailrith.com/docs/ai-connections.md): AI connections let Mailrith draft content with your own provider account. This guide explains providers, API key and OAuth setup, workspace assignments, default models, connection statuses, and repair flows.
- [Broadcasts](https://mailrith.com/docs/broadcasts.md): Use broadcasts for newsletters, product launches, announcements, and any message you send once to selected subscribers. Compose, target, test, and send or schedule the campaign in one workflow.
