RelayLink carries a briefing: who it is for, what it is about, the note, the ask, the few fields that make a cold reader able to answer. It can now carry a document too — but a narrow one. A plain-text or Markdown file, checked to be well-formed text before it is stored, up to five per briefing and 5 MiB together, 1 MiB each. A PDF, a Word document, a slide deck, a spreadsheet, an image, a zip file — none of those.
That line is a decision, not an oversight. A document sent this way is inert text the moment it arrives: nothing in it can execute, and nothing in it can fetch anything else. Widening the list to formats with their own internal structure — a macro, an embedded object, a linked image — would mean checking for a much larger and slower-moving set of exploits than a plain-text read can catch, on a surface whose other half is an assistant reading whatever gets through.
What a document is, here
Ask your assistant to save one from text it already has, splitting a longer piece across a few calls if it needs to — or ask for a single-use upload link: a coding tool can curl a file straight to it, or you can open the link in a browser and pick a file, no sign-in either way. The link lasts an hour, saves one file, and is yours alone — treat it like a password until it is used. The account portal still has an upload page too, if you would rather use it. Whichever way it arrives, it is checked before it is stored, held privately until you approve the send, and readable then only by whoever the briefing reaches. You can withdraw it from every copy at once, or remove your own copy of one you received, at any time.
What your assistant does with one it receives
It does not arrive folded into the briefing. Your assistant reads a document with a separate call, and only when you ask it to — it comes back framed as somebody else's words, not as a briefing field and not as an instruction, the same rule every other piece of relayed content follows here. That is also why a document cannot make your assistant do anything on its own: reading one is not the same as your asking it to act on what is in it.
What still does not fit
Put the rest of a document — a PDF, a deck, a spreadsheet — where the other person already trusts it: their drive, a repo, a ticket. Write the address in the note as text. Links arrive defused. They can copy it, which is slower than a live attachment and is also not a blob this server has to scan and later delete on your behalf.
A screenshot belongs in the same bucket as a markdown image: a URL the recipient's client would fetch. Those are removed. Describe the picture.
If the reply is only a file
People answer a notification from a mail client. Sometimes the body is empty and the PDF is the whole message.
That used to vanish. It was the one case still dropped in silence, and the commonest cause of "I replied, nothing happened."
Now you get a courtesy, with its own wording. It does not say the link expired — the link is fine; the newer email would fail the same way. It says there was nothing readable to turn into a reply. An attachment on an emailed reply is still discarded, whatever it is — that path is separate from the document you can attach through RelayLink itself, and it stays this narrow for the same reason: nobody is checking what arrives that way.
Two things about that notice:
- It rides a row. The unique key on the inbound message is what stops one mail producing two notices. A header-only guard is how two systems start mailing each other.
- The row is finished, not failed. A failed row is one a later delivery takes over. There is nothing to retry here except a second copy of the same courtesy.
Automated-looking mail (Auto-Submitted, bulk precedence, a list id) still gets no courtesy. That is how a loop starts.
What this still is not asking
It is not asking you to paste a spreadsheet into the note, or to reach for a document when a sentence would do. The note on an approval is 2,000 characters and refused, not trimmed, because a cut sentence would still go out labelled as yours. A portal compose allows more, and is still prose.
If the work really is the file — the whole spreadsheet, the whole deck — send it the way you already do, then use RelayLink for the decision about it. The briefing can carry a short document or point at a longer one. It will not become a file server.