---
title: Worker types
description: General, research, mail and uptime workers in detail — what each can do, what it needs, and its safety limits.
---

## General

A general worker follows its instructions using **only** the tools and sources
you grant it.

| With grant | It can |
|---|---|
| Selected context sources | Search the connected Slack, Jira and Gmail sources you chose. |
| Web search | Search and read the public web. |
| Mail read | Search a synced or connected mailbox. |
| Mail draft + credential | Create email drafts — never send. |
| Chat write | Propose Slack messages for approval. |

If you give it an output format, its result is checked against that format.
Everything it reads is treated as data, never as instructions.

## Research

A research worker runs a **bounded public web search** and returns a synthesis
with its sources and links. Use it for recurring market, competitor or
regulation watches. Needs: *web search*.

## Mail

A mail worker works through a connected mailbox:

1. **Read** — it queries the mailbox (by default, unread messages) and looks at
   a limited number of recent messages as metadata and snippets — not a full
   mailbox dump. Needs: *mail read*.
2. **Draft** — with *mail draft*, it creates a draft reply in the mailbox. A
   draft can always be deleted; it isn't sent.
3. **Send** — with *mail send*, the run pauses until you approve that **exact**
   draft (recipient, subject and body), then sends it **once**.

Sending always requires approval — the setting can't be turned off.

## Uptime monitor

An uptime worker checks a public URL on its schedule.

| Setting | Range |
|---|---|
| URL | Public `http://` or `https://` only |
| Timeout | 1–30 seconds |
| Failures before *down* | 1–10 |
| Successes before *up* | 1–10 |

It records the status code and response time of every check, and reports two
kinds of change: **outage** and **recovery**. Requiring several failures before
declaring an outage stops one slow response from paging anyone.

For safety it refuses URLs containing credentials and any address on a private
or internal network, and it doesn't follow redirects. Needs: *HTTP read*.
