Field note · September 15, 2026

Can an AI assistant in iMessage actually handle your admin work?

Five days with an agent that lives in a text thread: what it booked, what it handed back, and why the messaging app is the part that matters.

An AI assistant that lives in iMessage can handle real admin work, because it is there when your laptop is not. Over five days it rebooked a flight mid-meeting, read calendars, and booked dinner. It also stalled on slower tasks and handed some back. Two-factor codes still need a person.

The capability is not the new part. The location is.

We spent five days running Instinct, an AI assistant that lives inside iMessage. No relationship with the company, no payment either direction, and it is free during their beta. The reaction from anyone technical is usually the same: what is the big deal? Codex and Claude already drive a browser. They can research a place, fill a form, and click the button.

True. But the laptop is not always open. The admin work of a life and a business happens while you are at lunch, in a meeting, at the gym, or standing in an airport. Vet appointments, doctor appointments, reservations, rebookings, the fifteen tabs of small friction that eat an afternoon. An agent you have to sit down at is an agent you use on purpose. An agent in your text thread is one you use in the gap between two other things.

What five days of real use looked like

It was given read access to every calendar and to Gmail. No write access anywhere. From there, in normal use:

  • A flight got delayed on a work trip and the layover was going to be missed. A text from inside a meeting was enough: it found new seats, paid for them, and got the front row. Three minutes of margin on the connection.
  • Asked what the day looked like, it read across all the connected calendars and answered like a person would, not like a calendar export.
  • It made dinner reservations, including one at a restaurant that normally runs two months out.
  • It kicked off a lead-generation campaign for the business.

None of that is exotic on its own. All of it is work that otherwise waits until you are back at a desk, and most of it never gets done well because it waits.

Read access first. Write access much later.

Read-only is the right starting posture and it is the same rule we set for the agents we build for clients: the agent sees everything, and the actions it can take on its own are named explicitly. Everything else it escalates to a human. Booking a flight is a decision you can hand over. Sending an email from your address is not, at least not in week one.

That posture is also what makes the honest failures readable. If an agent has write access to everything and something goes sideways, you are auditing damage. If it can only read and ask, the worst case is a wasted five minutes.

Where it fell down

This is a beta under load, and it showed. Tasks that returned in seconds four days earlier were taking three and four minutes. One dinner booking ran through the whole flow, collected three verification codes, and then failed because the codes did not stick in the browser session. It said so plainly: it hit a wall, and the task was coming back to a human.

The vet request was more interesting. It found the clinic, worked out that dental cleanings are not bookable through the online portal at all, and reported that the only path was a phone call, along with two days the calendar was open for it. That is the right answer. An agent that tells you a thing cannot be done online is worth more than one that quietly pretends it did it.

Two-factor is the ceiling nobody designs around

The agent is working on its own machine, logging into sites as you. So every two-factor prompt becomes a handoff: it texts asking for the code that just landed on your phone, or the one in your authenticator app. That is the main recurring human step, and it is not going away soon.

Worth planning for rather than being surprised by. Tasks that touch accounts with strict authentication will need you in the loop. Tasks that only need reading and reasoning will not.

The morning brief is the part that makes it stick

The single best output was not a booking. It was the summary waiting each morning: the calendar with the conflict already flagged, the vendor call sitting on top of a protected deep work block with an offer to move it, the autopay landing Friday, the airline refund that finally posted, a family birthday on Sunday with an offer to send something today so it arrives in time.

That is a dashboard delivered in the one app you already open first. It looks ahead instead of reporting backwards, and every line comes with an action attached.

Why this matters for your business, not just your phone

The same pattern is already working inside companies through Slack and Teams. Nobody has to learn a new tool. They tag the agent instead of tagging a person, in the channel where the question was going to be asked anyway. Adoption stops being a training problem.

Whether this particular product wins is not the point. Assistants are moving into the messaging apps people already live in, and over the next six months more of them will. If you are deciding where to put an agent for your team, put it where they already are.

The short version

  • An agent's usefulness is set by where it lives, not just what it can do. A laptop-only agent gets used on purpose; a messaging agent gets used constantly.
  • Start read-only. Name the short list of actions the agent takes on its own, and escalate everything else.
  • Two-factor authentication is the recurring human step. Any agent logging into sites as you will need you for codes.
  • The morning brief that looks ahead and offers to act is the habit-forming feature, not the individual bookings.
  • In a company, the same idea belongs in Slack or Teams, because adoption is a location problem before it is a capability problem.

Questions this raises

Is an AI assistant in a messaging app safe to connect to my email and calendar?
Connect it read-only first. Reading a calendar and an inbox is low risk and is where most of the value sits. Grant write access one action at a time, only after you have watched how it behaves. Anything that sends mail from your address or spends money should be an explicit, separate decision.

What kinds of tasks does an agent like this fail at today?
Anything behind two-factor authentication needs you to supply the code. Long browser sessions can drop partway through and hand the task back. And some things genuinely cannot be booked online, which a good agent will tell you instead of faking. Expect a handoff rate, not a clean sweep.

Does this replace an AI setup inside Slack or Teams for a business?
No. A personal assistant in iMessage handles your admin. A business agent in Slack or Teams handles work that a team shares, with defined rules about what it decides on its own and what it escalates. Both work for the same reason: they sit in the app people already have open.

Get the next one.

Short, practical notes on making AI actually run work in an owner-led business. A few a week. Unsubscribe whenever.

Ready to move sooner? Start with the $999 AI Opportunity Assessment, or book a free intro call.