An invoice lands, and the total sits in the PDF hanging off the bottom of the email. You can open the file and hunt for the number. You can also just ask for the number, and get it back in a sentence with a link to the page it came from. Point reads the attachment for you.
- The time goes on working out which of the eleven files on that thread had the figure in it. That’s the part you skip.
- A question that names one fact gets a better answer than a question that asks for a summary. There’s measured evidence for why.
- Every answer arrives with a link to its source. The thing an attachment gets wrong most often is which version it read, and the link settles that in a second.
- A document from outside your firm is somebody else’s writing, handed to software. That’s a real security question with a name, and it has a real answer you can run as a habit.
The question that gets an answer
Ask for the fact.
Find the Whitmore invoice gives you a file, which is where your work starts. What’s the total on the Whitmore invoice and when is it due gives you 4,180.00 and net 30, and the errand’s over.
A question that lands has three parts. People leave out the third.
Which document, in the terms you actually remember it by. The sender, the company, the kind of document, roughly when. The engagement letter Bell’s office sent back last month. Filenames arrive looking like scan_0043_final_v2.pdf, and nobody remembers those. You’re describing the document the way you’d describe it to a colleague. The same habit that finds a message finds the file attached to one, which is searching your inbox by meaning if you want that skill on its own.
What you want out of it, stated narrowly. A number, a date, a name, a term, a yes or no. The renewal notice deadline. Whether there’s a late fee. Who signed it. Narrow is the whole technique here, and the next-but-one section is about why.
Where in the document, if you happen to know. In the payment terms section. On the summary page. This part’s optional, and most of the time you won’t know it. When you do, it’s worth four words. It turns a search of forty pages into a look at one.
Two habits go with those. Ask one thing at a time, because a compound question comes back as a compound answer and you have to audit all of it at once. And when an answer looks wrong, add a detail. What unsticks a bad match is more of what you know.
Six things worth asking a file
The advice gets easier the moment it’s worked. These are the shapes that come up in a small firm most weeks.
A figure on an invoice or statement. What’s the total on the Cordova invoice, and what are the terms? This is the most common one by a distance, and it’s the one where opening the file is plainly the long way around. You wanted twelve characters and a payment window.
A date buried in a contract. When does the Harlow lease renewal notice have to be in by? Renewal windows are the classic thing a small firm discovers three days late. The date lives on page 22 of something nobody’s opened since it was signed.
A term you half remember agreeing to. Does the Bell engagement letter say anything about who owns the workpapers? You’re unsure the clause is in there at all. That’s the question that costs the most to answer by reading, because establishing that something’s absent takes a full pass through the document.
A comparison across two files. How does the fee in the new Ardmore proposal compare to last year’s? Two sources, so two things to check. The links underneath matter most here.
What actually arrived against what you asked for. Which of the documents on the Marisol list did she actually send? Half of a busy season is this question. If you send those lists routinely, handling a PBC list covers the rest of that loop.
Something you sent yourself. What did I quote in the proposal I sent Dana in June? Your own outgoing attachments are attachments, and your sent mail is as searchable as your inbox. This one saves an embarrassment more often than it saves time.
Any of these can be spoken on a morning when your hands are on something else. You phrase it the same way either way. That’s talking to your inbox hands-free.
The receipt, and the version problem
What comes back is a sentence with a link under it, and the link goes to the document the sentence came from. Point shows its source, every time.
That link is the difference between a fact you can use and a fact you’d rather not have to defend. With attachments it’s doing one specific job that mail search never has to do.
Here’s the job. A thread about an engagement letter holds three engagement letters: the one you sent, the one they marked up, and the one that got signed. A thread about a fee schedule holds the original and the revision you emailed twenty minutes later apologizing for the typo. Ask what the fee is and you can get an entirely correct answer about the wrong document.
That failure doesn’t look like a failure. It looks like a confident sentence with a number in it, which is precisely why it’s the one worth building a habit around.
The habit is small. Look at what the link points to before you use the number. Just the name and the date on the thing the answer came out of. If it’s the file you meant, you’re done in a second. If it’s another one, say which one you meant and ask again.
Two ways to head this off before it happens. Name the version in the question when there’s any doubt: the signed one, the revised schedule, the one from after the call. And when a thread has genuinely piled up files, the attachments across your mail also collect into a single list, with each file still carrying the thread it came in on. Seeing that there are three engagement letters is much quicker there than scrolling the conversation.
Where the answer is about a conversation rather than a document, the receipt does the same job. How much weight it should carry is set out in how far to trust what you are told about your own mail.
What answers and what does not
Attachments come in kinds, and the kinds answer differently. Knowing where this gets thin saves you from finding out on something that mattered.
A document made of text is the easy case. A PDF generated from a word processor, an accounting package, a billing system, a contract drafting tool. The words are in the file as words. Ask a question and you get an answer.
A scan is a picture of a page. Somebody photographs it with their phone, or runs it through a copier that emails a PDF. What you have is an image, and the answer depends entirely on how well the text comes back out of that image. A clean, straight, printed scan usually recovers well. A skewed one, a faint fax, a page with a coffee ring on it, or anything handwritten recovers badly, and it recovers badly in a particular way: you get a plausible answer with a digit changed. If a meaningful share of what your clients send you is phone photographs, test this once on a file whose answer you already know. Then you’ll know what to expect on one where you don’t.
Signatures, stamps and handwritten margin notes are the weakest case of all. Whether a document is signed is a question to answer with your eyes.
The further a file gets from prose, the worse the fit. A memo, a contract, a letter or an invoice is text with structure, which is what a question of this kind is built for. A workbook with fourteen tabs and a model in it is closer to a small database, and asking it a question in a sentence is a different act from opening it. Use the sentence for the lookup and the spreadsheet for the analysis.
A locked file stays locked. A password-protected or encrypted attachment is closed to this the same way it’s closed to you until you type the password.
And a message Point held at the door stays unread. That’s deliberate, the section after next is about why, and if the term is unfamiliar, what a quarantine folder is covers the general idea.
The practical test for any file type you’re unsure about is the same, and it takes a minute. Pick one document you know cold. Ask it the question you already know the answer to. See what comes back. That minute teaches you more than any list somebody else wrote.
Why a narrow question beats a summary
There’s a measured reason that what is the late fee works better than summarize this contract, and it’s worth having, because it turns a vague instinct into a rule you can apply.
In 2024, Nelson Liu, Kevin Lin, John Hewitt, Ashwin Paranjape, Michele Bevilacqua, Fabio Petroni and Percy Liang published Lost in the Middle: How Language Models Use Long Contexts in Transactions of the Association for Computational Linguistics. They ran a controlled experiment. Take the piece of information that answers a question, move it to different positions inside a long stretch of input, and see whether the answer changes.
It changes. “We observe that performance is often highest when relevant information occurs at the beginning or end of the input context, and significantly degrades when models must access relevant information in the middle of long contexts, even for explicitly long-context models.”
They named the shape of it a U-shaped performance curve. The two ends carry the labels a psychologist would use: a primacy bias at the very beginning of the input, a recency bias at the end. In between, a sag.
The obvious hope is that a bigger window fixes it. The measurements went the other way: “we find that models often have identical performance to their extended-context counterparts, indicating that extended-context models are not necessarily better at using their input context.”
Two honest notes about the scope of that study. It measured position within a model’s input, across a multi-document question answering task and a synthetic retrieval task, and mailbox attachments were outside what it tested. And it’s a finding about language models generally rather than about any one product. The practical lesson survives both, because the lesson is about the shape of what you ask. The same effect has a cousin on the other side of the mailbox, where the long input is a forty-message thread rather than a long file. That one’s covered in what a summary of a very long chain leaves out.
Three rules come out of it, and they’re the ones that make the difference in real use.
Ask for the fact rather than for the whole. The narrower the target, the less there is to get lost in. What’s the termination notice period is a better question than what are the key terms, even though the second one sounds more thorough.
Anchor it if you can. Naming a section, a heading or a page range is worth more than it looks like it’s worth. It turns the middle of a long document into the beginning of a short one.
Give the middle of a long document extra suspicion. If the answer you needed came from page 30 of 60 rather than from the first page or the signature block, that’s the case where you open the link. It’s how you learn which of your questions are the cheap ones and which are the ones that earn a click.
The document is somebody else’s writing
An email attachment is content that a third party composed, sent to you unsolicited, and that software is now reading on your behalf. That’s a specific and well-documented security situation, and it deserves to be said plainly.
In March 2025 the National Institute of Standards and Technology, part of the U.S. Department of Commerce, published Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations, by Apostol Vassilev, Alina Oprea, Alie Fordyce, Hyrum Anderson, Xander Davies and Maia Hamin. It’s the federal government’s reference vocabulary for how AI systems get attacked, and one of its categories is exactly this one.
The root cause is structural: “Because GenAI models combine the data and instruction channels.” Text that a model reads as material and text that a model reads as orders arrive through the same door. So a document can carry instructions in it, and an attacker who can get a document in front of your software has a channel to it.
The report is careful about who is doing this to whom. “Unlike in direct prompt injection attacks, indirect prompt injection attacks are mounted not by the primary user of a model but instead by a third party. In fact, in many cases, it is the primary user of the model who is harmed by the compromise of the integrity, availability, or privacy of the GenAI system.”
And the effects it lists are precisely the ones that matter when the thing being read is a document you’re about to act on. Researchers, it says, have demonstrated attacks “that can cause a GenAI system to produce arbitrarily incorrect summaries of sources, to respond with attacker-specified information, or to suppress or hide certain information sources.”
That third one is the one to sit with. A confident answer, with something quietly taken out of it.
The report is straight about the state of the art: “Because current mitigations do not offer full protection against all attacker techniques, application designers may design systems with the assumption that prompt injection attacks are possible if a model is exposed to untrusted input sources.”
That assumption is the design Point is built on. Mail that carries the patterns of a manipulation attempt is held first, in a separate place, unread by the assistant. Open a held message and you get a sealed, read-only view. The raw text is visible to you, and nothing in it runs. Releasing it is your decision, and until you make it the attachment stays unread.
Your side of it is two habits, and both are ordinary.
Anything that moves money gets checked outside the answer. A changed bank account, new wire instructions, an unexpected balance owed. That’s the version of this attack a seven-person firm actually meets, and it usually works with no AI involved at all. The control has always been the same: confirm it by a channel the document didn’t arrive on.
A held message is telling you something. When something’s in quarantine, look at why before you release it.
Where this sits in Point’s broader controls, and what’s written down about every action taken on your behalf, is the activity log.
When to open the file anyway
Some jobs want the document open in front of you. Forgetting that is how somebody ends up quoting a clause they never read.
When you’re going to sign it, file it, or attest to it. A question returns a fact. Signing a document is a statement about the whole document. Those are different acts, and the second one wants your own reading. If your obligations here are professional rather than merely prudent, AI and the AICPA code of conduct is the piece that takes that seriously.
When the answer is going into something that leaves your building. A client email, a return, a filing, a letter to opposing counsel. Opening the link costs a few seconds. A transposed digit in a document nobody looked at costs a great deal more.
When there’s a genuine dispute about what the document says. Two readings of a clause is a matter for judgment, and reading the clause is how you form one.
When you need the whole document in your head. You’re about to negotiate the contract, rather than look something up in it. That’s reading, and reading is still reading.
And when the document, rather than the mailbox, is the work. If your day is spent inside long PDFs, marking them up, comparing revisions and pulling them apart, a dedicated PDF tool is built for that job. Adobe’s own page for AI Assistant in Acrobat, checked September 6, 2026, describes it as a way to “generate clear, quick overviews of your files with precise citations that link directly to the source in your docs.” That works on the document you’ve already opened. Point fills the gap before that, when the file is somewhere in a thread from March and you were never going to open it at all.
One boundary worth naming, so you’re not surprised. What gets read is what arrived in your mail. A question here covers your messages and their attachments, and a shared drive or a document management system is a separate place.
Common questions
Can Point read a PDF attached to an email and answer questions about it?
Yes. Ask in plain words for the thing you want out of the file, in the same box you’d use to find a message, and the answer comes back as a sentence with a link to the source document underneath it. Describe the document however you remember it, and Point works out the filename, the attachment and the message it’s sitting on.
Does this work on scanned documents?
It depends on the scan, and that’s the honest answer rather than a hedge. A clean, straight scan of a printed page usually reads well. A phone photograph at an angle, a faint fax, or anything handwritten reads badly, and the failure mode is a confident answer with a wrong character in it, which reads like a good one. If scans are a large part of what your clients send you, spend one minute testing it on a file whose answer you already know.
How do I know it read the right version of the document?
Look at what the link under the answer points to. That’s the single most useful second you’ll spend on this, because a thread with three drafts of the same letter on it will happily produce a correct answer about the wrong draft. You can also head it off in the question, by naming the version you mean: the signed one, the revised schedule, the one that came back after the call.
Is it safe to let AI read a client’s documents?
There are two questions inside that one, and they have different answers. On confidentiality, where the file goes and what’s kept is set out in where your mail goes when AI reads it. On security, a document from outside your firm is untrusted input, which NIST’s 2025 taxonomy of AI attacks treats as a category of its own, and Point’s response is to hold suspicious mail away from the assistant. Your own judgment still governs a document that moves money.
Can I ask about several documents at once?
Yes, and comparisons across two files are one of the better uses of it. Keep the question to one fact across the documents, because each source you add is another link to check, and a four-part answer built from two files takes longer to audit than it took to ask.
Can I ask for something to be done with the answer?
Yes, and that’s where a question turns into work. What’s the total on the Cordova invoice is a lookup. Reply to Cordova confirming we’ll pay the 4,180.00 by the 30th is work, and whether that comes back finished or waiting on you is decided by a per-task setting rather than by how you phrased it. Saying what you want done in one ordinary sentence covers the difference, and how far your inbox goes on its own covers the setting.
What about files that are not in my email?
This reads what arrived in your mailbox. A file somebody shared with you as a link rather than as an attachment, or one that lives in a folder on a shared drive, sits outside that. For most small firms that’s a smaller gap than it sounds. The copy that matters was emailed to somebody at some point anyway.
The short version
The answer you need is often in the file underneath the message, which is why so much of an ordinary week goes on opening documents to retrieve one number. Ask for the number instead. Describe the document the way you remember it, ask for one fact rather than a summary, and name the part of the document if you happen to know it. Then look at what the link under the answer points to, because the mistake attachments make most often is being right about the wrong version. Give the middle of a long document more suspicion than its first page, on the evidence of the research above. Open the file yourself when you’re going to sign it, file it, or send the number to somebody else. And treat any document that changes a payment instruction as a thing to confirm by another channel, whatever read it first. Everything else Point does with your mail is inventoried on the benefits page. The honest summary of this particular piece of it is smaller than that: an attachment stops being a file you have to open, and becomes a thing you can just ask.