AI Recommendations

Written By Matt Sywulak

Last updated About 2 hours ago

Overview

AI Recommendations reviews your recent mail flow and suggests specific, individual changes to your allow list, block list, and sender-trust settings β€” each one with the evidence behind it, so you can decide whether to apply it.

Recommendations are never applied automatically. Every one is reviewed and applied by you, one at a time.

AI Recommendations is a beta feature and is enabled per team. If you do not see it on your Overview page or in Settings, it is not yet switched on for your team.

How recommendations are produced

This matters for judging what you're looking at, so it's worth being precise about it.

The recommendations themselves are produced by rule-based analysis of your mail flow. They're deterministic: the same mail flow produces the same recommendations. A large language model is not writing them.

An LLM then reviews what the rules produced. Its role is deliberately limited β€” it can only:

  • Hide a recommendation it judges wrong, or one where the evidence doesn't support the change.

  • Annotate a recommendation it agrees with, adding a one-sentence explanation that appears as a separate AI line on the card.

The LLM cannot create a recommendation, and it cannot change what a recommendation does. An annotation explains the existing recommendation; it never alters the action. If the review fails or times out, recommendations are shown exactly as the rules produced them.

Cleanup recommendations aren't sent for LLM review at all.

Where you'll find recommendations

  • The Overview page β€” a widget showing how many recommendations are waiting, with a link through to all of them.

  • The AI Recommendations page, under Settings β€” the full list, with search, category filters, and sorting by impact or confidence.

  • The Allow List and Block List pages β€” a tab alongside your existing entries, showing just the recommendations for that list.

What gets recommended

  • Allow List β€” senders worth allowing. For example, a sender your users keep reporting as safe after INKY flagged it.

  • Block List β€” senders worth blocking.

  • Known External Senders β€” authenticated domains and addresses worth labelling as known external.

  • Trusted Third-Party Senders β€” third parties sending on your behalf that INKY may otherwise treat as internal-sender spoofing.

  • Cleanup β€” existing entries that no longer earn their place.

Each category covers several distinct kinds of recommendation, each with its own evidence thresholds. For the complete list β€” every kind, what has to be true before it appears, and whether it lands on the organization or one team β€” see AI Recommendations: the full catalogue.

What's on a recommendation

  • The change β€” what's being suggested, stated as a sentence. For an allow, it names both the sender and the specific warning being switched off.

  • Why β€” one line. If the AI review wrote its own explanation, that takes the lead instead.

  • The numbers β€” the observations from your mail flow that decide the question.

  • Confidence β€” 0–100, shown as high, medium or low. It also decides the order recommendations appear in.

  • Impact β€” how much this changes, separately from how sure we are. High confidence in a low-impact tidy-up is perfectly normal.

  • Applying will β€” exactly what happens, in the same words the allow and block list pages use.

  • Applies to β€” the organization, or one named team. Check this before applying: an org-wide change reaches every team beneath it by inheritance.

Applying or dismissing a recommendation

Each card offers two actions:

  • Apply β€” makes the change. You'll be asked to confirm first, and the confirmation states what will change and at what scope.

  • Dismiss β€” removes the recommendation from your list without making any change.

If your mail flow has moved on since a recommendation was produced, applying it reports that it's no longer applicable and nothing is changed.

Permissions

Seeing recommendations and applying them are separate permissions.

Viewing the recommendations needs read access to your allow and block lists. Applying one makes an ordinary change to a list or a policy setting, so it needs permission to modify the thing it touches β€” allow list, block list, or analysis policy. If you don't have that permission, Apply isn't offered on that recommendation.

Turning LLM review off

The LLM review step is covered by the LLM Assistance setting, the same per-team switch that governs Smart Insights and borderline message analysis. You'll find it under Settings > Admin Center > Analysis.

With LLM assistance turned off for a team, recommendations are still generated and still shown β€” the rule-based analysis is unaffected. What stops is the LLM review pass, so you won't see the AI explanation line on cards.

LLM Assistance and AI Recommendations are controlled separately, so a team may have recommendations available without the LLM Assistance setting appearing for it.