Pattern: follow the proven HyreKit mail mechanism exactly (memory: hyrekit-mail-is-a-sendas-alias, support-reply-cc-hyrekit-identity), since it already works and is tested.
Corrected 2026-10-10 (lane L5) after a live check — this is more involved than this draft originally assumed, so it was not created this lane (time-boxed, see below), but the exact mechanism is now verified instead of guessed:
python3 bin/exo_admin.py Get-Mailbox --json '{"Identity":"allie@offsite.ee"}' (read-only, run livetoday) shows EmailAddresses: ["SMTP:allie@offsite.ee"] only — hyrekit@offsite.ee is not a proxy address on allie's own mailbox, contradicting this draft's original assumption.
brain/allie_memory_deep.md line 181 has the real shape: hyrekit@offsite.ee is its **own distributionlist (DL) object, forwarding to erkki@offsite.ee + allie@offsite.ee; the "SendAs" capability bin/hyrekit_reply.py relies on is a Send-As permission grant on that DL object**, trustee allie@offsite.ee (Add-RecipientPermission -Identity hyrekit@offsite.ee -Trustee allie@offsite.ee -AccessRights SendAs) — not a Set-Mailbox -EmailAddresses edit on allie's own mailbox.
safetyloop@offsite.ee for real: (1) `New-DistributionGroup -Name safetyloop -PrimarySmtpAddresssafetyloop@offsite.ee (or a mail contact, whichever matches the hyrekit pattern exactly — re-check Get-DistributionGroup -Identity hyrekit@offsite.ee first), (2) Add-RecipientPermission granting SendAs to allie@offsite.ee, (3) a new bin/safetyloop_reply.py cloned from hyrekit_reply.py's mechanism (createReply in allie@offsite.ee → PATCH from/sender → send), never copying HyreKit's own identity/secrets. All three steps are within Allie's existing EXO admin app-only hand (bin/exo_admin.py`, no new consent needed) — genuinely creatable without the owner, just not done this lane (time-boxed against the rest of this lane's scope; two DL-admin mutations deserved a dedicated, unhurried pass rather than being rushed at the end of a QA+listing lane).
erkki@offsite.ee directly for launch (no DL neededfor this), revisit a hyrekit.io-style dedicated CC-DL only if the product gets its own domain.
PRIVACY.md/TERMS.md this lane) — this is explicitly the brief's own fallback, not a missed step.
NEEDS_REVIEW / UNKNOWN) means, how to re-run an audit.
not issue a compliance certificate; point to the specific NEEDS_REVIEW/UNKNOWN items and what evidence would resolve them.
this; Allie explains the mechanism (see PRICING.md), does not change anyone's plan or issue refunds without the owner.
applicable to my specific business" is a legal question, not a support question).
fined") — escalate immediately, do not improvise a legal position.
Follow the HyreKit precedent language ("usually within one business day, EET, UTC+2/+3") — [OPEN: confirm the owner wants the same commitment for a second product before publishing this externally].
No alias created, no DL decision made, no reply script written — this file is the plan, not the implementation. Needs an explicit owner "yes" (Exchange admin action) before [app-alias]@offsite.ee can send or receive anything.