Email Copilot
Concept Paper · Banking & Compliance

Trust first. Productivity second.

A concept for governed AI email drafting inside regulated banks — human-in-the-loop review, policy gating, and audit-ready records before any AI-drafted message reaches a customer. This paper describes the interaction design already validated end to end, and the governance engine planned to sit behind it.

Banks want the productivity of AI-drafted email, but an unreviewed AI send creates conduct, compliance, and reputational risk the moment it reaches a customer. Most AI email tooling is built for speed, not for the audit trail and human sign-off a regulated institution actually needs before a draft goes out.

Email Copilot is designed around a single rule: an AI draft is a draft until a human approves it. The full review workflow — a human-in-the-loop queue, policy and confidence-based blocking, an audit and accountability view, and an executive command view — has been designed and validated as a complete interaction flow, so the governance model can be evaluated and agreed before the drafting engine itself is wired in.

A fully interactive prototype of the review workflow exists, with every screen navigable end to end:

  • A human-in-the-loop review workspace — approve, edit, or reject a drafted email with visible confidence and routing rationale.
  • An audit and accountability view, and a workflow governance view for tracking commitments made in correspondence.
  • An executive command dashboard summarizing review throughput and risk.
  • Google sign-in via Firebase, with a graceful demo fallback.

The workflow above is designed as the front end for a governance engine that is planned as, not yet built:

  • An actual AI drafting engine — today, every draft, confidence score, and routing rationale shown in the demo is illustrative content, not a live model call.
  • Policy and confidence-based blocking driven by a real policy engine rather than fixed demo values.
  • A genuine audit record — durable, tamper-evident storage (WORM-style retention) rather than a CSV export.
  • On-prem / hybrid model routing for banks that require data to stay in their own environment.
  • Banks wanting AI email productivity without losing sign-off control.
  • Compliance officers and risk/CISO teams who need a provable review trail.
  • Contact centers and regulated enterprises evaluating AI email governance before adoption.

React + Vite client with Firebase Auth. Stage: Tech Ready — the governance workflow and UI are fully designed and demonstrable; the AI drafting engine, policy enforcement, and audit persistence behind it are the next build phase.