# AI Email Drafting

## Objective

Draft an email from the record on screen, the intended outcome, and a chosen tone.

A drafting step in the app's existing compose flow that turns a record, a stated goal, and a tone selection into an editable message.

## Before You Begin

This feature is being added to an application that already exists and already
works. Do not scaffold a new project, and do not assume a blank slate.

Inspect the codebase first and establish:

- The existing application structure and where code of this kind already lives.
- The framework and version in use.
- The existing design system — colours, spacing, typography, and component conventions.
- Existing UI components you can reuse instead of writing new ones.
- The existing database structure, if this feature needs to persist anything.
- The existing authentication and authorization system, if this feature is user-scoped.
- Dependencies already installed, so you don't add a library that duplicates one.
- The existing test setup and conventions.

Only start writing code once you understand the above. If the application
already implements part of this feature, extend it rather than replacing it.

## Implementation Instructions

1. Hook this into the compose surfaces the app already has rather than adding a separate writing screen. The draft must land in the same editor the user would otherwise have typed into, with the same validation and sending path.
2. Build the context sent to the model from an explicit allow-list of fields on the record the sender can already see. Do not pass the whole record or the whole thread on the assumption that more context produces a better draft.
3. Always deliver the result as an unsent draft. Do not send, schedule, or queue a message from this feature under any circumstances, and keep the send action exactly where it was before.
4. Constrain the model to the facts supplied. Dates, prices, commitments, links, and attachment references must come from the record; anything not supplied must be left as an obvious placeholder for the sender to fill.
5. Short in-thread responses belong to AI Reply Suggestions; this feature owns composing a new message from a record. Where both are present, keep one shared tone vocabulary and one shared context allow-list rather than two that drift apart.

## UI and UX Requirements

Match the application's existing design system exactly. Reuse its components,
spacing, and typography. This feature should look like it was always there.

## Responsive Requirements

Works on mobile, tablet, and desktop. Touch targets are large enough to hit on a
phone, and nothing overflows horizontally at 320px.

## Accessibility Requirements

- Fully keyboard navigable.
- Correct semantic elements and ARIA roles.
- Visible focus states.
- Meets WCAG AA contrast.
- Dynamic changes are announced to screen readers.
- Respects prefers-reduced-motion.

## Edge Cases

- The sender may see internal notes the recipient must never receive. Exclude private notes, internal comments, and staff-only fields from the context by default, and require an explicit setting to include anything of that kind.
- A model asked to write persuasively will invent a delivery date, a discount, or an attachment that does not exist. Treat any specific number, date, or promise not present in the supplied context as a defect, not a stylistic choice.
- Recipient names, roles, and pronouns must come from the record rather than from the model's reading of the thread, and a recipient whose name is unknown must be addressed neutrally rather than guessed at.
- The draft must never be applied over text the user has already typed. Offer it alongside, or require an explicit accept, so an in-progress message is not destroyed.
- Confidential context that reached the draft once must not linger in a stored prompt or a debug log where it can be read later by someone without access to the underlying record.
- A refusal, a timeout, or a truncated response must leave the compose window usable with a plain error, not a half-finished sentence that the user sends without noticing.
- Repeated regeneration is the main cost risk. Cap generations per message and per account per period, and tell the user when they have hit the cap.
- When the model is unavailable, the compose flow must work exactly as it did before the feature existed, with the drafting control disabled and explained.

## Testing

Exercise the feature end to end in the running application. Cover every edge case
above, then run the existing test suite and confirm nothing regressed.

## Acceptance Criteria

- [ ] Drafting produces an editable message inside the existing compose flow and never sends or schedules anything.
- [ ] Context is assembled from a documented allow-list of fields the sender already has access to.
- [ ] Internal notes and staff-only fields are excluded from what is sent to the provider.
- [ ] Dates, prices, commitments, and attachment references appear only when present in the supplied context.
- [ ] Text the user has already typed is never overwritten without an explicit accept.
- [ ] Generation is capped per message and per account, with the limit surfaced to the user.
- [ ] With the model unavailable, composing and sending work unchanged.
- [ ] The feature matches the existing design system.
- [ ] No existing functionality is broken.

## Adaptation Rules

- Match the existing design system. Do not introduce a new colour palette,
  spacing scale, or component library.
- Reuse existing components and utilities wherever they fit.
- Follow the naming, file layout, and code style already present.
- Do not upgrade, replace, or remove existing dependencies to make this
  feature fit. Adapt the feature to the app, not the app to the feature.
- Do not break existing functionality. If a change is genuinely required in
  existing code, make the smallest one that works and say so.
- If something in these instructions conflicts with how the application is
  built, follow the application and explain the deviation.

## Final Verification

Before you report the work as done:

1. Re-read the acceptance criteria above and check each one against what you
   actually built.
2. Run the application and exercise the feature end to end.
3. Run the existing test suite and confirm you have broken nothing.
4. Check the feature on mobile, tablet, and desktop widths.
5. Check keyboard navigation and focus handling.
6. Summarize what changed: files added, files modified, and anything you
   deliberately did differently because of how this application is built.

If any acceptance criterion is unmet, fix it before reporting completion.
