Airtable: Redact PII in Record Reads
Scans the responses of the Airtable record-read tools — the calls that return row fields values — and rewrites high-confidence PII shapes to a fixed…
Scans the responses of the Airtable record-read tools — the calls that return row fields values — and rewrites high-confidence PII shapes to a fixed…
On the Asana MCP read path, this transform scans the free-text business fields that ride back in task, comment/story, and status-update responses — notes,…
Scans the content returned by BigQuery's result-returning tools and rewrites high-confidence PII shapes to fixed, non-recoverable redaction tokens before the…
Blocks agent-initiated Microsoft 365 email sends when any recipient address falls outside a corporate-domain allowlist.
Inspects the raw GoogleSQL string carried by BigQuery SQL tools and denies any statement that moves data out of the tenant's own project — even when the call…
bigqueryguard-warehouse-exportingresssqlexfiltrationsoc2pci-dssgdpr-ccpa
Blocks Snowflake SQL-execution tool calls whose query text moves whole tables off the Snowflake perimeter — bulk export to cloud storage or a stage, and…
snowflakeguard-warehouse-sqlexportexfiltrationingresssoc2pci-dssgdpr-ccpa
Denies Google Calendar event-write tool calls — create event / create-event, update event / update-event, and the consolidated manage event — whenever any…
google-calendarguard-external-sendingresscalendarsoc2hipaagdpr-ccpa
Inspects Notion data-source query tool calls (notion-query-data-sources on the hosted server, query-data-source on the official local server) and denies any…
Inspects the SQL text that Snowflake MCP tools carry in their query argument and denies any statement in a mutating or destructive class — DROP, TRUNCATE,…
snowflakeguard-warehouse-sqlingresssqlreadonlysoc2pci-dsssox
Inspects the raw GoogleSQL string carried by BigQuery write-capable query tools and denies any statement in a state-changing class — DML…
Every Zapier MCP tool — in both the agentic and classic modes — accepts a free-text instructions string that Zapier's server-side AI uses to fill any…
Stops a Zoom Team Chat agent from pulling external parties into the organization's chat surface.
Blocks the classic BEC/exfiltration persistence primitive: Gmail filters that can auto-forward or auto-delete mail and outlive the agent session.
Denies the irreversible destructive operations on the Docusign agent path:
Unconditionally denies any Linear tool that creates, updates, or deletes a webhook — linear createWebhook, linear deleteWebhook, and update variants.
linearguard-webhook-persistenceingresswebhookexfiltrationsoc2
Unconditionally denies the classic business-email-compromise (BEC) persistence surface in Microsoft 365: creating or updating Outlook mail rules, changing…
ms365guard-mailbox-persistenceingressbecemailfinserv-commssoc2
On Microsoft's remote Power BI MCP server (https://api.fabric.microsoft.
Denies, by default, the Dropbox tools that turn an internal file into an internet-visible resource in a single call — before the request ever reaches Dropbox:
dropboxguard-share-linkssharingexternal-sharingingresssoc2hipaagdpr-ccpa
Blocks Google Calendar create and update event calls that would expose the event to the world or hand control of it to guests.
Blocks Confluence write calls whose body looks like it contains a live credential — an API key, password, token, or PEM-formatted private key — before the…
Blocks Slack send-message tool calls whose message body looks like it contains a secret — API keys, passwords, tokens, or PEM-formatted private keys.
Blocks Zoom Team Chat send/update tool calls whose message content looks like it contains a live secret — API keys, passwords, bearer tokens, or…
Makes Box read-only by default on the MCP path.
boxrole-gate-writesaccess-controlleast-privilegeingresssoc2gdpr-ccpa
Caps the blast radius of Asana's official V2 batch write tools. At ingress it:
Bounds the two largest data-out channels in the Docusign MCP landscape:
docusigncap-bulk-exportpiidata-minimisationegresssoc2gdpr-ccpa
Clamps the bulk-export parameters on Glean search calls before they reach the Glean MCP server, so a single agent request cannot pull an entire indexed…
gleancap-bulk-exportdata-minimisationingresssoc2hipaagdpr-ccpa
Clamps the page size of Google Drive search and listing calls to a documented cap (25 results per call).
google-drivecap-bulk-exportdata-minimizationingresssoc2hipaagdpr-ccpa
caller is a CRM admin); clamp page size on everything else; allow the rest
intercomcap-bulk-exportcontact-enumerationdlpingresssoc2hipaapci-dssgdpr-ccpa
Clamps the bulk-read levers on every QuickBooks Online search tool so an agent cannot pull the entire general ledger — or a full customer, vendor, or…
quickbookscap-bulk-exportbulk-exportdlpingresssoc2pci-dssgdpr-ccpa
Airtable bases routinely hold CRM contacts, applicant-tracking pipelines, customer/financial trackers, and — on HIPAA-eligible Enterprise plans — health-ops…
An Airtable OAuth grant (or Personal Access Token) with the workspacesAndBases:read scope spans the entire workspace — every base the connected identity can…
Stops a prompt-injected or erring agent from broadcasting Confluence content org-wide or to anonymous external readers.
confluenceatlassiandeny-public-exposurepublicationgovernanceingressfinserv-commseu-ai-actsoc2gdpr-ccpa
Freezes the two irreversible Confluence deletion tools on the agent channel: confluence delete page and confluence delete attachment.
confluenceatlassianfreeze-destructive-opsdata-protectioningresssoc2
Scans the responses of Confluence page, comment, and search read tools and rewrites personally identifiable information to fixed redaction tokens before the…
confluenceatlassianredact-piipiidlpredactionegresssoc2hipaagdpr-ccpa
Notion's hosted MCP server (notion-search) does not just search Notion pages — through Notion AI connectors it also searches connected Slack, Google Drive,…
Pins an allowlist of the exact Databricks tool names your team audited and denies every other tool name on the Databricks MCP server(s).
databricksdefault-deny-unknown-toolsallowlistaccess-controlingresssoc2
Masks payment-card numbers (PANs) in Databricks tool responses before the agent receives them.
databricksmask-pan-egressegresscardholder-datadlpsoc2pci-dssgdpr-ccpa
Scans the response payloads of the Databricks MCP tools that carry lakehouse data back to the agent and rewrites personally identifiable information to fixed…
The community JustTryAI/databricks-mcp-server exposes cluster and job control — create cluster, start cluster, terminate cluster, run job, and export…
databricksrole-gate-writesaccess-controlleast-privilegeingresssoc2
Maintains a per-tenant allowlist of audited Airtable tool-name suffixes and denies any call whose tool name does not end with an allowlisted entry.
Maintains a per-tenant allowlist of audited BigQuery tool-name suffixes and denies any call whose tool name does not end with an allowlisted entry.
bigquerydefault-deny-unknown-toolsallowlistaccess-controlingresssoc2
Pins an allowlist of the 36 official Gusto MCP tool names and allows a call only when lower(input.resource.name) is an exact member of that list.
Pins an audited allowlist of the verified official Linear MCP tool names and allows a call only when the incoming tool name matches an allowlisted name on…
Maintains a per-tenant allowlist of audited monday tool-name suffixes and denies any call whose tool name does not end with an allowlisted entry.
Pins a per-tenant allowlist of audited Power BI tool-name suffixes and denies any call whose tool name does not end with an allowlisted entry.
power-bidefault-deny-unknown-toolsallowlistmodelingingresssoc2
Maintains an allowlist of audited ServiceNow tool-name suffixes and denies any tool call whose name does not match an allowlisted entry.
Fails closed on tool drift. The policy carries a pinned allowlist of the 39 tools in the verified official Tableau web toolset (tableau/tableau-mcp v2.24.
Maintains an allowlist of audited Zapier tool-name suffixes and denies any tool call whose name does not match an allowlisted entry, with an alert-worthy…
Denies Gmail send-class tool calls when any recipient in to, cc, or bcc falls outside a documented corporate-domain allowlist.
Blocks the Microsoft 365 MCP server's raw-Graph passthrough tool (graph-batch, observed live as ms365-graph-batch).
Denies the stripe api write meta-tool — the single raw passthrough on the official Stripe MCP server that can execute any Stripe POST, PATCH, PUT, or DELETE…
Scans the responses of Docusign envelope- and agreement-reading tools and rewrites high-confidence regulated identifiers before the response reaches the…
docusignredact-piitab-valuespiiphipandlpredactionegresssoc2gdpr-ccpa
Scans the responses of the Dropbox file-content read tools and sanitises the returned text before it reaches the agent.
dropboxredact-contentredact-piimask-pansecretspiidlpegresssoc2hipaagdpr-ccpa
Fences a configurable set of restricted Confluence spaces (placeholder keys: HR, LEGAL, SEC) out of the agent's read and search paths unless the caller's IdP…
confluenceatlassianfence-sensitive-scopesaccess-controlingresssoc2hipaagdpr-ccpa
Denies any GitHub tool call whose arguments.owner (read from input.payload.args.
githubfence-sensitive-scopesorg-allowlistanti-exfilingresssoc2
Glean's search tool fans out across every system the tenant has indexed (Drive, Confluence, Slack, Jira, Gmail/Outlook, GitHub, Salesforce, Gong, HR…
gleanfence-sensitive-scopesaccess-controldatasourceingresssoc2hipaagdpr-ccpa
Denies the highest-sensitivity Gusto read tools unless the caller's IdP-asserted groups include the placeholder group hr-payroll-admins.
gustofence-hr-and-credit-scopecompensationpayrollingresssoc2gdpr-ccpa
Gates Intercom's structured-PII read surface — customer contact and company profiles — by IdP group.
intercomfence-sensitive-scopescontact-readspiiingresssoc2hipaapci-dssgdpr-ccpa
Fences the single biggest exfiltration surface on the NetSuite MCP server — ns runCustomSuiteQL, which runs arbitrary read-only SuiteQL across the entire ERP.
Denies calls to the Notion member-directory tool (notion-get-users, matched by the -get-users suffix) unless the caller's IdP groups include an admin or IT…
notionfence-sensitive-scopesaccess-controlpiiingresssoc2gdpr-ccpa
Fences customer-designated regulated BigQuery data domains by data-domain IdP group, at ingress, before any statement or metadata lookup reaches BigQuery.
bigqueryfence-sensitive-scopesingressrbacsoc2hipaapci-dssgdpr-ccpa
Fences an admin-maintained denylist of restricted Google Drive file and folder IDs — HR records, M&A deal rooms, board packs, payroll — off the agent channel:
google-drivefence-restricted-folderssensitive-scopesingresssoc2hipaagdpr-ccpa
Fences the responses of Linear's roadmap, initiative, and strategy read tools.
Fences pinned sensitive Box subtrees (HR, Finance, Legal, …) by ID.
Fences off the most sensitive lakehouse namespaces from agents on the read side of Databricks.
databricksfence-sensitive-scopesingresssoc2hipaapci-dssgdpr-ccpa
Fences protected Dropbox subtrees by path prefix . Dropbox addresses files and folders by a root-relative path (/Finance/2026/payroll.
monday boards are schemaless business databases: HR/recruiting boards (candidate PII), CRM/deal boards (financial), and IT/security trackers routinely live…
Fences off the most sensitive ServiceNow tables from two routes that reach them:
servicenowfence-sensitive-tablespiiingresssoc2hipaapci-dssgdpr-ccpa
Fences customer-designated sensitive data domains inside a Snowflake warehouse by inspecting the SQL text the agent is about to run — not by tool name, which…
snowflakefence-sensitive-scopesingresssoc2hipaapci-dssgdpr-ccpa
Tableau's MCP server is a warehouse proxy: query-datasource runs a VizQL Data Service (VDS) query and returns raw row-level data — PII, PHI, payroll,…
tableaufence-sensitive-scopesaccess-controldatasourceingresssoc2gdpr-ccpa
Asana is routinely used for HR (hiring, performance, offboarding), legal, M&A, and incident work; those project bodies, comments, custom fields, and status…
Constrains Zoom's agentic-search tool ( search zoom) so it can only reach Zoom-native content.
Keeps agent-drafted Jira Service Management (JSM) comments off the customer-facing portal by rewriting addCommentToJiraIssue calls to carry a restrictive…
jiraforce-internal-commentscommentsjsmservice-managementingresssoc2atlassian
Keeps agent-drafted ServiceNow comments off the customer/employee-visible journal by rewriting add comment calls to internal work notes.
servicenowforce-internal-commentscommentswork-notesingresssoc2finra
Denies every destructive Airtable tool call unless the caller's IdP token carries the placeholder group airtable-admins.
Denies irreversible Google Calendar mutations on the agent channel:
Denies every destructive Asana tool call unless the caller's IdP token carries the placeholder group asana-admins.
Freezes deletes and retention tampering on the community self-hosted Box MCP server (box-community/mcp-server-box).
Freezes the irreversible and bulk-mutation Dropbox tools on the agent channel, regardless of path. At ingress it denies, by tool-name suffix:
Denies the irreversible destruction surface that community Gmail MCP servers expose — permanent email deletion, label deletion, and filter deletion — for…
Blocks Google Drive delete operations issued by agents.
Denies destructive Linear tool calls — the delete , archive , and session-logout classes — unless the caller's IdP token carries the placeholder group…
Denies every Microsoft 365 tool call whose verb segment is delete- or cancel- unless the caller's IdP token carries the placeholder group m365-admin.
Splits monday's destructive tool surface into two tiers and treats each differently at ingress, before the call ever reaches the monday MCP server:
Denies every destructive QuickBooks Online (QBO) tool call on the agent channel before it reaches the MCP server.
Denies the irreversible content-mutation tools on the official tableau/tableau-mcp web server unless the caller's IdP token carries the placeholder group…
Freezes directory and membership mutations on the Microsoft 365 MCP surface. The policy denies, by tool-name suffix:
ms365freeze-identity-planeingressidentityentragroupsiso27001-nistsoc2
Denies notion-update-page calls whose command argument is replace content — the one edge on Notion's hosted MCP server that overwrites a page's entire body…
Freezes edits to row-level-security (RLS) roles on the Power BI MCP surface.
power-bifreeze-identity-planeingressrlsidentitygroupssoc2iso27001-nist
Denies all Salesforce record-deletion capability on the agent channel unless the caller's IdP groups claim contains the placeholder group sf-admins.
Freezes the identity-and-access mutation surface of the ServiceNow MCP server. The policy denies, by tool-name suffix:
servicenowfreeze-identity-planeingressidentitygroupssoc2iso27001-nist
Denies the monday tools that install side effects which outlive the governed MCP session. Two classes of tool are blocked:
In its default agentic mode, Zapier MCP exposes meta-tools that let the agent widen its own blast radius mid-session : enable zapier action and auto…
Baseline least-privilege policy for Google Drive MCP traffic.
google-driverole-gate-writesleast-privilegeingresssoc2gdpr-ccpa
Gates retrieval of Zoom meeting transcripts, AI Companion summaries, and next-steps on the connector's core egress tools, enforcing minimum-necessary access:
Scans the responses of GitHub's crown-jewel read tools and masks known credential shapes with a fixed [REDACTED-SECRET] marker before the text enters agent…
Pins a per-tenant allowlist of the verified built-in read tools on the Glean managed remote MCP server and denies every other tool suffix on the Glean server…
gleandefault-deny-unknown-toolsallowlistaccess-controlingresssoc2
Gates mutating calls to Glean's long-term memory surface — the built-in tool exposed as memory (and as read memory in Glean's own client guide).
gleangate-memory-writesrole-gate-writesmemoryaccess-controlleast-privilegeingresssoc2
Scans the responses of Glean's content-returning read tools and rewrites high-confidence PII to fixed redaction tokens before the response reaches the…
Throttles mass-harvesting of a mailbox by capping the per-call blast radius of the two Gmail MCP surfaces that return many full email bodies at once:
gmailcap-bulk-exportdata-minimisationingresssoc2hipaagdpr-ccpa
Makes Gmail read-only by default on the MCP path. Verified read tools pass for everyone.
gmailrole-gate-writesaccess-controlleast-privilegeingresssoc2gdpr-ccpa
Scans the responses of the content-returning Google Drive tools — file reads, downloads, and Docs/Sheets/Slides content fetches — and rewrites personally…
google-driveredact-piipiidlpredactionegresssoc2hipaagdpr-ccpa
Blocks the externally-visible Box sharing surface — the riskiest Box surface an agent can touch — before the call ever reaches Box:
boxguard-share-linkssharingexternal-sharingingresssoc2hipaagdpr-ccpa
Inspects the structured VizQL Data Service (VDS) query carried by Tableau's query-datasource tool and denies the call for callers outside the data-analysts…
Inspects the SQL statement string that Databricks SQL-executing tools carry in their argument and denies any statement that performs a write, schema change,…
databricksguard-warehouse-sqlingresssqlreadonlypci-dsssoxsoc2
Power BI semantic models front the warehouse: a model imports or DirectQueries lakehouse/warehouse tables — finance, HR, customer PII.
power-biguard-warehouse-sqlingressdaxexfiltrationsoc2gdpr-ccpa
Blocks Docusign envelope-creation and recipient-update tool calls when any recipient email address has a domain outside the configured counterparty allowlist.
Denies Google Drive get file permissions tool calls unless the caller's IdP groups claim contains infosec. All other tool calls pass through unchanged.
Stops agents from opening OneDrive/SharePoint files to the whole internet. It guards the two Microsoft 365 sharing tools:
ms365share-linkssharingingresssoc2iso27001-nisthipaagdpr-ccpa
Throttles full-roster exfiltration on Gusto's two broad outbound list tools — list company employees and list company contractors — by rewriting their…
gustocap-bulk-exportpiidata-minimisationingressgdpr-ccpasoc2
Instantiates PF-02 (redact-pii-egress) on the Gusto read path.
gustoredact-pii-egressredact-piipiifinancial-piidlpredactionegresssoc2gdpr-ccpa
Clamps the page size of HubSpot bulk-read tool calls before they reach the HubSpot MCP server, so a single agent request to a covered bulk-read tool can…
hubspotcap-bulk-exportpiidata-minimisationingresssoc2hipaapci-dssgdpr-ccpa
Blocks every archive/deletion-class HubSpot tool call, plus the consent-destroying contact unsubscribe, before it reaches the MCP server.
Makes the HubSpot connection read-only by blocking the write tool.
hubspotaccess-controlgovernanceread-onlyingresssoc2gdpr-ccpa
Sits one privilege tier above hubspot/role-gate-writes: ordinary crm-writers can create and edit CRM records, but two higher-blast-radius write classes are…
hubspotrole-gate-schema-consentaccess-controlleast-privilegesegregation-of-dutiesconsentingresssoc2
Gates every HubSpot write tool behind an IdP group: callers whose JWT groups claim contains crm-writers may create and update CRM records; everyone else gets…
hubspotrole-gate-writesaccess-controlleast-privilegeingresssoc2gdpr-ccpa
Unconditionally denies the ServiceNow change-management control-gate tools — the ones whose names end in approve change, reject change, or submit change for…
servicenowrequire-human-approvalchange-managementseparation-of-dutiesingresssoc2
Keeps agent-authored Intercom Help Center articles in draft so a human reviews them before they go live on the public Help Center.
intercomdeny-public-exposureingressarticleshelp-centerpublicationgovernancesoc2
Masks payment-card numbers (PANs) in Intercom conversation content returned to agents by the conversation- and free-text-returning read tools.
intercommask-pan-egressegresscardholder-datadlpsoc2pci-dssgdpr-ccpa
Scans the free-text returned by Intercom's conversation- and contact-read MCP tools and rewrites high-confidence personal identifiers and credential shapes…
Blocks any official Jira write call — transitionJiraIssue, editJiraIssue, or createJiraIssue — that carries a historyMetadata block, before it reaches the…
jiraatlassianfreeze-destructive-opsaudit-integrityingresssoc2
Narrows the breadth of JIRA read requests before they run, on the two read surfaces that can pull large amounts of issue data into model context:
jiraatlassiancap-bulk-exportdata-minimisationingresssoc2gdpr-ccpa
Keeps issues that belong to a configurable set of "sensitive" JIRA projects out of read access through the JIRA MCP server.
jiraatlassianaccess-controldata-protectioningresssoc2gdpr-ccpaiso27001-nistfinserv-comms
Freezes the three irreversible Jira operations on the agent channel: jira delete issue, jira remove issue link, and jira remove watcher.
jiraatlassianfreeze-destructive-opsrecord-integritydata-protectioningresssoc2
Blocks write operations against issues that belong to a configurable set of "sensitive" JIRA projects.
jiraatlassianaccess-controldata-protectioningresssoc2gdpr-ccpaiso27001-nistfinserv-comms
Makes Jira read-only by default on the MCP path.
jiraatlassianrole-gate-writesaccess-controlleast-privilegeingresssoc2gdpr-ccpa
Masks commercial and contact identifiers in the responses of Linear's Customers read tools before they reach the agent.
Masks payment-card-number (PAN) shapes in email content returned to agents by Gmail mailbox-read tools.
gmailmask-pan-egressegressemailcardholder-datadlpsoc2pci-dssgdpr-ccpa
Scans the responses of the highest-density PII read surfaces in Microsoft 365 — mail bodies, Excel ranges, SharePoint list items, meeting transcripts, and…
Two egress controls in one policy, both scoped to the monday MCP read path:
Instantiates the PF-08 cap-bulk-export family as a transform-only ingress policy on ns runCustomSuiteQL — the NetSuite MCP tool that runs arbitrary read-only…
netsuitecap-bulk-exportsuiteqldata-minimisationingresssoc2pci-dssgdpr-ccpa
Pins an allowlist of the audited NetSuite MCP Standard Tools and denies every other tool call before it reaches the NetSuite AI Connector.
netsuitedefault-deny-unknown-toolsallowlistaccess-controlingresssoc2
Instantiates PF-02 (redact-pii-egress) on the NetSuite read path.
netsuiteredact-piipiifinancial-piidlpredactionegressgdpr-ccpasoc2
Scans the responses of the Notion hosted MCP server's content-returning read tools and rewrites personally identifiable information to fixed redaction tokens…
Scans the content returned by Power BI's result-returning tools and rewrites high-confidence PII shapes to fixed, non-recoverable redaction tokens before the…
Stops the agent from exposing private code to the public across three GitHub write tools, at ingress — before the call reaches the GitHub MCP server, so a…
githubdeny-public-exposureanti-exfilingresssoc2finserv-commseu-ai-act
On the read path, this policy masks sensitive identifiers in the responses of four QuickBooks Online (QBO) name-entity read tools — get employee, search…
The least-privilege baseline for Microsoft 365 through the gateway: every tool call is allowed only if it is a read , or the caller's IdP token carries the…
Establishes the least-privilege baseline for the GitHub MCP connector on the agent channel.
Establishes a read-only-by-default Stripe posture over the MCP path. The named write and destructive billing tools —
striperole-gate-writesingressleast-privilegerbacsoc2pci-dsssoxgdpr-ccpa
Scrubs sensitive fields from the responses of Google Calendar read tools before they reach the agent, for callers who lack the placeholder calendar-full-read…
google-calendarredact-piipiiphidlpredactionegresssoc2hipaagdpr-ccpa
Keeps a human in the loop on the two GitHub actions that consummate a code change: merging a pull request and approving one .
Zapier MCP is an aggregator: one connector proxies actions across 9,000+ apps, and every create/update/delete/send funnels through a small, predictable…
Establishes the per-app least-privilege write floor for Dropbox.
dropboxrole-gate-writesrbacleast-privilegeingresssoc2gdpr-ccpa
Blocks bulk PII extraction through Salesforce query tools by inspecting the free-text query arguments that are the real policy surface for these servers.
salesforcecap-bulk-exportdata-minimizationdlpingresssoc2hipaapci-dssgdpr-ccpa
Unconditionally denies the raw-code and raw-API tools exposed by the community Salesforce MCP servers — tools that bypass every object- and argument-level…
salesforcedeny-escape-hatchesaccess-controlingresssoc2iso27001-nist
Blocks Salesforce Contact updates that modify protected fields — ownership, account linkage, contact PII, name, and consent flags.
salesforcecontactspiiaccess-controlgovernanceingresssoc2gdpr-ccpaiso27001-nist
Restricts Salesforce SOQL queries so only Account, Contact, and Opportunity records can be retrieved.
salesforceaccess-controldata-protectiongovernanceingresssoc2pci-dssgdpr-ccpaiso27001-nist
Restricts the Salesforce MCP server to read-only access.
salesforceaccess-controlgovernanceread-onlyingresssoc2gdpr-ccpaiso27001-nist
Redacts personal contact information from Salesforce tool responses before they reach the caller.
salesforcepiidlpredactionegresssoc2hipaagdpr-ccpaiso27001-nist
The PF-12 least-privilege baseline for Salesforce.
salesforcerole-gate-writesaccess-controlleast-privilegeingresssoc2gdpr-ccpacrm
Scrubs the post-payment redirect from Stripe payment-link creation calls.
stripeguard-share-linksingresstransformphishingprompt-injectionsoc2
else fails closed
servicenowrole-gate-writesaccess-controlleast-privilegeingresssoc2gdpr-ccpa
Gates every Slack write-class tool behind an IdP group: callers whose JWT groups claim contains slack-writers may send and schedule messages, add or remove…
slackrole-gate-writesaccess-controlleast-privilegeingresssoc2gdpr-ccpa
Denies Slack message-write calls whose destination is an externally shared Slack Connect channel.
slackguard-external-sendslack-connectexfiltrationingresssoc2gdpr-ccpahipaa
Blocks Slack channel-creation tool calls at ingress. Every other Slack tool — and every non-Slack tool — passes through untouched.
Denies the agent read reach into Slack DMs and private conversations on the paths below — the workspace's highest concentration of PII/PHI (HR issues, health…
Blocks read, search, and summarize operations that target a configurable set of "sensitive" Slack channels.
slackaccess-controldata-protectioningresssoc2hipaagdpr-ccpaiso27001-nist
Blocks Slack message-write calls whose destination resolves to a direct conversation — a 1:1 DM, a message posted to a user ID (which Slack auto-opens as a…
slackaccess-controlgovernanceingresssoc2iso27001-nistfinserv-comms
Masks payment-card numbers (PANs) in Slack content returned to agents by message-read, thread-read, canvas-read, history, and search tools.
slackmask-pan-egressegresscardholder-datadlppci-dsssoc2gdpr-ccpa
Pins an allowlist of the exact Snowflake tool names your team audited and denies every other tool name on the Snowflake MCP server(s).
snowflakedefault-deny-unknown-toolsallowlistaccess-controlingresssoc2
Denies the opaque composite and generic passthrough tools on the Snowflake-managed MCP server whose execution the gateway cannot inspect one SQL statement at…
snowflakedeny-escape-hatchesaccess-controlcortexingresssoc2iso27001-nist
Scans the row content returned by the result-returning Snowflake MCP tools and rewrites personally identifiable information to fixed redaction tokens before…
Masks customer PII in the responses of Stripe's bulk PII egress channels before they reach the agent.
Tableau is a warehouse proxy: the data-returning tools stream raw row-level content out of whatever the published datasource connects to — PII, PHI, payroll,…
tableauredact-pii-egresspiipandlpredactionegresssoc2gdpr-ccpa
Masks payment-card numbers (PANs) in Zapier MCP read responses before they reach the agent.
zapiermask-pan-egressegresscardholder-datadlpsoc2pci-dssgdpr-ccpa
Scans the responses of Zoom's meeting-intelligence read surfaces — AI summaries, verbatim transcripts, recording resources, and Zoom Docs content — and…
SOC 2 is not a law and not a data type — it is an attestation framework. A licensed CPA firm examines a service organization's controls against the AICPA Trust Services Criteria: the Security Common Criteria (CC1–CC9, mandatory) plus the optional Availability, Processing Integrity, Confidentiality, and Privacy categories. The criteria are principles-based — the entity defines its own system, commitments, and controls, and the auditor tests whether they are suitably designed and operating effectively over a period. When an employee connects Salesforce, GitHub, or Snowflake to an AI agent over MCP, the agent inherits that user's credential and becomes a new, privileged access path into systems that sit inside the SOC 2 boundary. This bundle is a starting posture for that path: a DTwo policy can be the control an entity describes for the agent channel, and the gateway's per-decision log its evidence.
These policies support alignment with SOC 2 (Trust Services Criteria) on the MCP path only. They act on agent traffic that flows through the gateway; web-UI logins, native-API integrations, and in-app activity are outside their reach by design, and no policy or bundle makes an organization SOC 2 compliant. SOC 2 is an attestation over your whole control environment — the agent channel is one control among the many an auditor tests.
173 policies across 32 apps, grouped below by the Trust Services Criteria they support. Each policy appears once, under its primary theme. Every policy is single-purpose and composes with the others on the same pipeline direction. Policy bodies live under apps/; this page only links to them.
The per-decision audit log beneath the bundle — principal, action, resource, context, decision — is a property of the gateway, not a policy in it. That record is the Type II operating-effectiveness evidence for the CC6.x access criteria and the monitoring input for CC7.2 (anomaly detection) and CC7.3 (event evaluation). Every allow, deny, and transform below lands in it, attributed to an authenticated user.
The core CC6.3 pattern: reads stay open, writes require the matching IdP group, and specific high-impact writes are gated or denied outright. This is the per-app baseline that makes tool-level authorization keyed to identity — least privilege on the agent channel.
| Policy | App | Direction | Purpose |
|---|---|---|---|
| role-gate-writes | ms365 | ingress | Reads pass for everyone; writes require the m365-writers IdP group. |
| role-gate-writes | gmail | ingress | Read-only by default; every write/send/label/filter/delete tool requires the writer group (fail-closed). |
| role-gate-writes | google-drive | ingress | Gate Drive write-class tools to the drive-writers IdP group; reads pass through. |
| role-gate-writes | slack | ingress | Gate Slack write-class tools behind an IdP writers group. |
| deny-channel-creation | slack | ingress | Deny Slack channel-creation tool calls. |
| role-gate-writes | salesforce | ingress | Reads for all; create/update gated to approved groups; unknown tools fail closed. |
| read-only | salesforce | ingress | Allowlist-based read-only posture; all write tools fail closed. |
| protect-contact-fields | salesforce | ingress | Block Contact updates that modify protected fields (ownership, PII, consent flags). |
| role-gate-writes | servicenow | ingress | Reads open; verified writes require the servicenow-writers group; unknown tools fail closed. |
| role-gate-writes | box | ingress | Read-only by default; gate all Box write/mutating tools behind a writer IdP group. |
| role-gate-writes | hubspot | ingress | Gate all HubSpot write tools behind the crm-writers IdP group. |
| read-only | hubspot | ingress | Deny the write tool to enforce a read-only HubSpot posture. |
| role-gate-writes | jira | ingress | Gate all Jira write tools to the writer IdP group; reads open to everyone. |
| role-gate-writes | zapier | ingress | Read-only by default; deny all writes across the aggregator unless caller is in automation-writers. |
| role-gate-writes-billing | stripe | ingress | Read-only by default; gate named billing write/destructive tools to finance/billing-admin groups. |
| gate-memory-writes | glean | ingress | Role-gate Glean memory writes (add/update/delete) to a pilot group; reads pass. |
| role-gate-writes | dropbox | ingress | Deny create/upload/copy/move/restore tools unless caller is in the dropbox-writers group. |
| role-gate-compute-ops | databricks | ingress | Role-gate cluster/job/notebook-export compute control to the platform-engineering group. |
| role-gate-writes-engineering | github | ingress | Gate write/destructive GitHub tools to the engineering IdP group; read-only for everyone else. |
| block-rls-bypass-service-principal | power-bi | ingress | Deny RLS-sensitive read/query tools under service-principal or unconfirmed identity. |
CC6.6 makes the gateway the boundary control for the agent channel; CC6.8 and CC9.2 extend it to unauthorized tools and vendor risk. Default-deny allowlists fail closed on renamed or newly introduced upstream tools; escape-hatch denials shut the raw-API passthroughs that would bypass every other policy; and persistence guards deny the standing automations, filters, and webhooks that outlive a session.
| Policy | App | Direction | Purpose |
|---|---|---|---|
| deny-graph-batch | ms365 | ingress | Blanket-deny the raw Graph batch passthrough (the escape hatch that bypasses per-tool policy) except for admins. |
| guard-mailbox-persistence | ms365 | ingress | Deny mail-rule/mailbox-settings/Graph-subscription creation (BEC persistence and exfil channels). |
| guard-mailbox-persistence | gmail | ingress | Deny Gmail filter-creation tools that can auto-forward or auto-delete mail — BEC persistence outliving the session. |
| deny-escape-hatches | salesforce | ingress | Unconditionally deny raw-code/raw-API tools (anonymous Apex, Tooling API, REST passthrough) that bypass policy. |
| default-deny-unknown-tools | servicenow | ingress | Allowlist audited tool-name suffixes; deny any unknown/renamed/instance-defined tool (fail closed). |
| default-deny-unknown-tools | zapier | ingress | Default-deny any Zapier tool name not on the audited allowlist (upstream tool-drift fail-closed). |
| freeze-toolset | zapier | ingress | Deny the self-modifying meta-tools (enable/auto_provision/write_code/skill writes) for non-admins. |
| constrain-connected-search | notion | ingress | Deny Notion search scoped to connected Slack/Drive/Jira sources (aggregator side-door). |
| deny-escape-hatches-api-write | stripe | ingress | Deny the stripe_api_write raw passthrough (role gate + money-movement/account endpoint hard stop). |
| default-deny-unknown-tools | snowflake | ingress | Deny unaudited/renamed Snowflake tool names; pass other servers. |
| deny-composite-cortex-tools | snowflake | ingress | Deny opaque CORTEX_AGENT_RUN/GENERIC agent-service tools the gateway cannot inspect per-statement. |
| default-deny-unknown-tools | netsuite | ingress | Allowlist audited ns_* standard tools; deny and alert on unknown/custom SuiteScript tools. |
| default-deny-unknown-tools | monday | ingress | Allowlist audited tool suffixes; block the GraphQL escape hatch, manage_tools, apps-mode, and drift. |
| freeze-standing-automation | monday | ingress | Freeze standing automations/workflows and autonomous AI agents that outlive the session. |
| default-deny-unknown-tools | glean | ingress | Allowlist verified built-in tools; deny self-expanding agents-as-tools/proxied writes. |
| default-deny-unknown-tools | gusto | ingress | Permit only the official Gusto tool names; deny drift/aggregator/community/renamed tools. |
| default-deny-unknown-tools | airtable | ingress | Default-deny allowlist; surface drift from new/renamed/unverified community tools. |
| default-deny-unknown-tools | databricks | ingress | Default-deny unknown/dynamic Databricks tools; fence system.ai proxies. |
| default-deny-unknown-tools | bigquery | ingress | Only audited BigQuery tool suffixes pass; surface renamed/self-expanding tools as drift. |
| fence-agentic-search | zoom | ingress | Fence agentic-search fan-out to Zoom-native corpora, stripping external Salesforce/Workday/ServiceNow entities. |
| default-deny-unknown-tools | tableau | ingress | Default-deny allowlist of the verified official Tableau tools; fail closed on tool drift. |
| default-deny-unknown-modeling-ops | power-bi | ingress | Allowlist audited tool suffixes and deny unlisted/renamed tools past the modeling server's bypass. |
| default-deny-unknown-tools | linear | ingress | Pin verified official Linear tool names; deny renamed/aggregator/community tools as drift. |
| guard-webhook-persistence | linear | ingress | Unconditionally deny webhook create/update/delete tools to block standing out-of-band exfil channels. |
CC6.3 asks for segregation of duties; CC8.1 asks that changes to systems be authorized and approved. These policies keep the human authorization step intact: the agent may draft, propose, and read, but approval, dispatch, and identity-plane mutation stay with a named human or a gated group.
| Policy | App | Direction | Purpose |
|---|---|---|---|
| freeze-identity-plane | ms365 | ingress | Deny group/team membership and ownership mutations (identity-plane escalation) unless caller is IAM-admin. |
| freeze-identity-plane | servicenow | ingress | Deny user/group create/update and group-membership changes unless caller is in identity-admins. |
| require-human-approval-changes | servicenow | ingress | Unconditionally deny approve_change/reject_change/submit_change_for_approval (human-only SoD gate). |
| role-gate-schema-consent | hubspot | ingress | Gate portal-schema and marketing-consent mutations to the hubspot-admins group (tier above writers). |
| require-human-approval-merge | github | ingress | Keep a human in the loop on PR merges and approvals (SoD / change control). |
| freeze-rls-role-edits | power-bi | ingress | Freeze RLS-role edit tools for all callers except a governance IdP group. |
CC6.7 is the strongest DLP hook in SOC 2 — restrict the transmission, movement, and removal of information — and P6.1 limits disclosure of personal information to third parties. These policies cap bulk export and search fan-out, deny agent sends and share links to external destinations, block public exposure, keep customer-facing surfaces internal, and keep secrets from being written into governed content.
| Policy | App | Direction | Purpose |
|---|---|---|---|
| guard-external-send | ms365 | ingress | Deny agent email sends when any recipient is outside the corporate-domain allowlist. |
| guard-share-links | ms365 | ingress | Downgrade anonymous share links to org scope, inject expiry, deny anonymous-edit links and external invites. |
| cap-bulk-export | gmail | ingress | Cap batch content reads and clamp search maxResults to throttle mass mailbox harvesting. |
| guard-external-send | gmail | ingress | Deny sends when any to/cc/bcc recipient is outside the corporate-domain allowlist; draft instead. |
| cap-bulk-export | google-drive | ingress | Clamp Drive search/listing page sizes to a cap (transform-only, never denies). |
| guard-external-attendees | google-calendar | ingress | Block calendar invites to attendees outside the corporate-domain allowlist. |
| guard-public-exposure | google-calendar | ingress | Block public visibility and guest-delegation flags on event create/update. |
| block-secrets | slack | ingress | Deny Slack send-message calls whose body contains credentials/keys/tokens. |
| deny-direct-messages | slack | ingress | Deny message-write calls whose destination resolves to a DM/group DM. |
| guard-external-send | slack | ingress | Deny agent posts to externally shared Slack Connect channels. |
| redact-sensitive-info | slack | ingress | Redact PII/secrets/card numbers from outbound Slack message args. |
| cap-bulk-export | salesforce | ingress | Cap SOQL row limits and gate org-wide SOSL search by IdP group. |
| guard-share-links-external | box | ingress | Block external collaborations to non-corp domains and anonymous public share links. |
| cap-bulk-export | hubspot | ingress | Clamp bulk-read page sizes and batch-read arrays to 50 records. |
| cap-read-field-exposure | jira | ingress | Strip over-broad field tokens and clamp search maxResults to 50 (data minimisation). |
| force-internal-jsm-comments | jira | ingress | Inject a restrictive commentVisibility so agent-drafted JSM notes stay off the customer portal. |
| force-internal-comments | servicenow | ingress | Rewrite add_comment to an internal work note for non service-desk callers (keeps agent notes off the customer-visible journal). |
| block-secrets | confluence | ingress | Deny page/comment writes whose body contains a live credential before org-wide publication. |
| deny-public-publication | confluence | ingress | Deny agent-initiated org-wide blog posts and public/anonymous-access-space writes; force drafts private. |
| cap-directory-and-document-egress | docusign | egress | Truncate account-wide user-directory listings for non-admins and gate signed-document downloads. |
| guard-external-recipients | docusign | ingress | Deny envelope creation/recipient updates when any recipient domain is outside the counterparty allowlist. |
| guard-external-send | zapier | ingress | Deny writes naming a recipient outside corporate domains, including addresses hidden in free text. |
| guard-share-links-payment-redirect | stripe | ingress | Scrub unapproved post-payment redirect_url on payment-link creation (transform-only). |
| guard-warehouse-export | snowflake | ingress | Deny COPY INTO external stage/URL, CREATE STAGE, share creation, and PUT/GET off-perimeter export. |
| cap-bulk-export | netsuite | ingress | Clamp SuiteQL pageSize to bound per-call ERP bulk export (data minimisation). |
| cap-search-export | glean | ingress | Clamp bulk-export params (result ceiling, strip exhaustive) on Glean search. |
| cap-contact-enumeration | intercom | ingress | Deny bulk-enumeration query shapes on contact search and clamp page size. |
| deny-article-publish | intercom | ingress | Deny Help Center article writes that set state=published unless caller is a content-admin (human review before go-live). |
| cap-bulk-export | quickbooks | ingress | Clamp fetchAll/limit on search tools to prevent whole-ledger/roster bulk export. |
| block-secrets-commits | github | ingress | Block live credentials/secrets from being committed into repos, gists, PRs, issues, and comments. |
| deny-public-exposure-repos | github | ingress | Deny public gists and personal-namespace forks; force new repositories private. |
| guard-share-links-external | dropbox | ingress | Deny public share links, download URLs, and file requests unless caller is in the dropbox-sharing group. |
| cap-roster-export | gusto | ingress | Clamp per to a ceiling and strip include=custom_fields on roster listings for non hr-payroll-admins. |
| cap-bulk-record-reads | airtable | ingress | Cap maxRecords to 50 and strip raw filterByFormula for non-analysts (data minimisation). |
| guard-warehouse-export | bigquery | ingress | Block EXPORT DATA/MODEL, EXTERNAL_QUERY, cross-project writes, and out-of-allowlist project_id. |
| block-secrets-chat | zoom | ingress | Block live secrets (keys, passwords, bearer tokens, private keys) in Zoom Team Chat message content. |
| guard-external-chat-invites | zoom | ingress | Block external contact invites and external history exposure in Zoom Team Chat channels. |
| guard-warehouse-sql-dax | power-bi | ingress | Deny bare full-table EVALUATE DAX (whole-table dumps) to prevent wholesale read-back exfiltration. |
C1.1's "maintain and protect" half is enforceable on the MCP path, and P4.1 limits the use of personal information to identified purposes. These policies fence sensitive scopes — folders, channels, projects, schemas, boards, datasources — to the roles that own them, and redact or mask PII, PHI, and secrets from responses before they reach agent context.
| Policy | App | Direction | Purpose |
|---|---|---|---|
| redact-pii-egress | ms365 | egress | Redact SSN, Luhn-validated PAN, IBAN, and US phone numbers from mail/Excel/SharePoint/transcript/Teams responses. |
| mask-pan-egress | gmail | egress | Mask payment-card-number shapes in Gmail mailbox-read responses (transform-only). |
| fence-restricted-folders | google-drive | ingress | Deny reads/writes/copies touching an admin denylist of restricted Drive IDs (HR, M&A, board, payroll). |
| guard-acl-recon | google-drive | ingress | Deny ACL-read tools (collaborator emails + external-share map) unless caller is in infosec. |
| redact-pii-egress | google-drive | egress | Redact email/SSN/national-ID/phone from Drive content responses. |
| redact-attendee-pii | google-calendar | egress | Redact attendee PII/PHI and meeting join links from calendar read responses. |
| deny-read-search-summarize-sensitive-channels | slack | ingress | Deny read/search/summarize of a configured set of sensitive channels. |
| guard-dm-privacy | slack | ingress | Deny agent read reach into DMs and private conversations (group-exempt). |
| mask-pan-egress | slack | egress | Luhn-validated PAN masking to BIN+last4 in Slack read/search responses. |
| redact-profile-pii | slack | egress | Redact email/phone/custom-field PII from Slack user-lookup responses. |
| query-allowlist | salesforce | ingress | Restrict the SOQL FROM object to an allowlist (Account/Contact/Opportunity). |
| redact-pii | salesforce | egress | Redact contact PII fields and PAN/SSN/phone/email patterns in responses. |
| fence-sensitive-tables | servicenow | ingress | Fence sys_user / HR / CMDB tables and user-directory reads behind owner IdP groups. |
| fence-sensitive-folders | box | ingress | Fence pinned sensitive Box folder/file IDs by IdP group (read/move/copy/search). |
| redact-pii-egress | box | egress | Redact SSN/PAN/bank/email/phone PII from Box content responses (group-exempt). |
| redact-pii | hubspot | egress | Redact contact PII (phone/email/SSN) in tool responses. |
| deny-view-search-sensitive-projects | jira | ingress | Fence configured sensitive projects out of direct views and JQL search. |
| deny-write-sensitive-projects | jira | ingress | Block writes against configured sensitive projects. |
| redact-sensitive-info | jira | egress | Redact PII/secrets/PAN from Jira issue-view responses. |
| fence-restricted-spaces | confluence | ingress | Fence restricted spaces (HR/LEGAL/SEC) out of search, listing, and lookup unless the group grants access. |
| redact-pii-egress | confluence | egress | Redact SSN/email/US-phone PII from Confluence page/comment/search reads (group-exempt). |
| redact-tab-values-egress | docusign | egress | Redact SSN and bank routing/account numbers and mask card PANs in envelope reads (group-exempt). |
| mask-pan-egress | zapier | egress | Luhn-validated PAN masking to BIN+last4 in Zapier read responses. |
| fence-user-directory | notion | ingress | Fence the member-directory tool (names/emails/IDs) to admin/IT IdP groups. |
| redact-pii-egress | notion | egress | Redact email/phone PII from Notion reads for non-HR/legal callers. |
| redact-pii-egress-customer | stripe | egress | Mask customer email/phone/address/last4 in bulk Stripe read responses (finance group-exempt). |
| fence-sensitive-schemas | snowflake | ingress | Group-gate PII/PHI/HR/FINANCE schema references and block SELECT * on fenced schemas. |
| redact-pii-egress | snowflake | egress | Mask SSN/email/phone in result sets (pii-cleared group exempt). |
| fence-hr-payroll-suiteql | netsuite | ingress | Deny HR/payroll SuiteQL and saved-search reads outside the hr IdP group. |
| redact-financial-pii | netsuite | egress | Redact SSN/TIN/IBAN/labelled bank-account numbers in NetSuite read responses. |
| fence-sensitive-projects | asana | ingress | Fence writes to sensitive project GIDs (HR/legal/M&A/incident) to mapped IdP groups. |
| redact-task-pii | asana | egress | Redact SSN/email/phone/IBAN in task/comment/status reads (privacy-officer exemption). |
| fence-sensitive-boards | monday | ingress | Fence sensitive board/workspace IDs (HR, CRM, security) across reads, writes, and search. |
| redact-board-pii-egress | monday | egress | Redact SSN/email/phone/national-ID on board/doc/update reads; non-admin deny of the directory tool. |
| fence-datasource-scope | glean | ingress | Restrict which indexed datasource a Glean search may target by IdP group. |
| redact-pii-egress | glean | egress | Redact SSN/PAN/IBAN from Glean read responses before they reach agent context. |
| fence-contact-reads | intercom | ingress | Role-gate the structured-PII contact/company read surface to support/CRM groups. |
| mask-pan-egress | intercom | egress | Luhn-validated PAN masking to BIN+last4 in conversation responses. |
| redact-conversation-pii | intercom | egress | Redact SSN/national-ID/email/phone/credential shapes from conversation and contact reads. |
| redact-pii-egress-employee | quickbooks | egress | Mask SSN/address/pay/tax-ID/bank fields in employee/vendor reads for non-HR/finance callers. |
| fence-scopes-org-allowlist | github | ingress | Fence owner-bearing GitHub calls to a per-tenant company-org allowlist (read/write anti-exfil). |
| redact-secrets-egress | github | egress | Mask known credential shapes in GitHub read responses (file contents, code search, CI logs, diffs). |
| fence-sensitive-paths | dropbox | ingress | Fence protected path prefixes (HR/Finance/Legal/Customers) to mapped IdP team groups. |
| redact-content-egress | dropbox | egress | Mask card PANs and redact SSN/email/phone/secrets in file-content responses (pci carve-out). |
| fence-comp-payroll-reads | gusto | ingress | Deny compensation, pay-register, contractor-payment, and employment-action reads outside hr-payroll-admins. |
| redact-financial-ids-egress | gusto | egress | Mask US SSN and label-anchored bank-account/ABA-routing numbers in every Gusto response. |
| fence-base-allowlist | airtable | ingress | Confine base-scoped record/schema/page tools to an operator allowlist of sanctioned base IDs. |
| redact-pii-egress | airtable | egress | Redact SSN/email/phone/national-ID in record-read responses (data-privileged group exempt). |
| fence-sensitive-schemas | databricks | ingress | Deny SQL/metadata access to sensitive namespaces (hr/payroll/pii/phi/comp) outside the data-privacy group. |
| mask-pan-egress | databricks | egress | Luhn-validated PAN masking to BIN+last4 in SQL/Genie/AI-Search responses. |
| redact-pii-egress | databricks | egress | Redact SSN/email/phone in response payloads outside the data-privacy group. |
| fence-sensitive-datasets | bigquery | ingress | Fence regulated dataset prefixes (phi_/finance_/pii_) by IdP group across SQL and metadata. |
| redact-pii-egress | bigquery | egress | Redact SSN/PAN/email in query results and optionally cap result rows (group exempt). |
| guard-transcripts-by-group | zoom | ingress | Gate Zoom transcript/summary and recording-passcode retrieval by IdP group. |
| redact-pii-meeting-intelligence | zoom | egress | Redact email/phone/SSN in Zoom meeting-intelligence responses (transcripts, summaries, docs). |
| fence-datasource-scope | tableau | ingress | Per-datasource LUID allowlist on query and analyst-only gate on image-render tools. |
| redact-pii-query-results | tableau | egress | Redact email/phone/SSN and mask card PANs in data-returning tool responses. |
| redact-pii-dax-results | power-bi | egress | Redact email/SSN and mask card PANs in returned DAX/query/report-metadata results (data-steward exemption). |
| fence-roadmap-egress | linear | egress | Fence roadmap/initiative/strategy/document read responses to product/exec IdP groups. |
| redact-customer-pii-egress | linear | egress | Redact customer revenue, tier/segment, and contact email in Customers read responses. |
PI1.5 asks that stored records keep their integrity, and PI1.2 that inputs are authorized. These policies deny agent-initiated deletion, overwrite, and history tampering, cap batch mutation blast radius, and block destructive SQL — so a stray plan or an injected instruction cannot erase a record of record or its audit trail. Break-glass admin groups keep legitimate cleanup possible.
| Policy | App | Direction | Purpose |
|---|---|---|---|
| freeze-destructive-ops | ms365 | ingress | Deny delete-/cancel- verb-family tools unless caller is in the admin group. |
| freeze-destructive-ops | gmail | ingress | Deny permanent email/label/filter deletion; reversible archive/label ops pass. |
| freeze-destructive-ops | google-drive | ingress | Block Drive delete-class tools unless caller is in drive-admins. |
| freeze-destructive-events | google-calendar | ingress | Freeze agent-driven event deletes and series-wide recurring changes. |
| freeze-record-deletes | salesforce | ingress | Deny record-delete capability (delete tools + DML delete verb) unless caller is in sf-admins. |
| freeze-destructive-ops | box | ingress | Freeze deletes and retention tampering; unconditional block on recursive folder delete. |
| freeze-destructive-ops | hubspot | ingress | Deny archive/delete/void/purge-class tools plus contact unsubscribe (consent destruction). |
| freeze-destructive-ops | jira | ingress | Deny the irreversible delete/remove-link/remove-watcher ops with a break-glass admin group. |
| deny-history-actor-spoofing | jira | ingress | Deny writes carrying a historyMetadata block that would forge change-history actor metadata. |
| freeze-page-deletion | confluence | ingress | Freeze irreversible page/attachment deletion on the agent channel (break-glass admin group). |
| freeze-destructive-ops | docusign | ingress | Deny envelope voids and Maestro workflow cancel/pause except for the contract-ops group. |
| freeze-content-overwrite | notion | ingress | Freeze full-body replace_content overwrites on update-page. |
| guard-datasource-sql | notion | ingress | Block destructive/export SQL on data-source queries; read-only SELECT only. |
| guard-warehouse-sql | snowflake | ingress | Block DROP/TRUNCATE/DELETE/UPDATE/INSERT/MERGE/ALTER/GRANT and DDL (data-platform-admins exempt). |
| cap-batch-mutation | asana | ingress | Cap blast radius of V2 batch create_tasks/update_tasks (oversize + mass-completion guard). |
| freeze-destructive-ops | asana | ingress | Freeze irreversible delete verbs (delete_task/section/project_status/tag) except for the admin group. |
| freeze-destructive-ops | monday | ingress | Block whole-board ops for all; admin-gate recoverable per-record deletes. |
| freeze-destructive-ops | quickbooks | ingress | Deny all destructive QBO calls (delete/void/deactivate; hard deletes) on the agent channel. |
| freeze-destructive-ops | dropbox | ingress | Freeze delete, folder-rewind, and revision-restore tools on the agent channel. |
| freeze-record-deletion | airtable | ingress | Deny delete tools (delete_records/delete_page) for non-airtable-admins to protect record/page integrity. |
| guard-warehouse-sql | databricks | ingress | Deny DML/DDL/GRANT/export/destructive SQL; read-only for non data-engineering callers. |
| guard-warehouse-sql | bigquery | ingress | Block mutating/destructive SQL (DML/DDL/GRANT/CALL/LOAD DATA/EXECUTE IMMEDIATE). |
| freeze-destructive-content | tableau | ingress | Admin-gated freeze of delete/extract-refresh mutation tools and their confirm- twins. |
| guard-query-calculation | tableau | ingress | Deny arbitrary calculation expressions in VDS queries for non-analyst callers. |
| freeze-destructive-ops | linear | ingress | Freeze delete/archive/session-logout verbs (plus removeUserFromTeam) unless caller is in linear-admins. |
Bundle membership is declared in each policy's policy.md frontmatter (the policy lists bundles: ["soc2"]). This page is a human-readable landing page; the generated manifest.json is the machine-readable source of truth. There is intentionally no separate bundle.json artifact — one source of metadata avoids drift.
The policies compose by direction. The egress redaction and masking policies (most of theme 5, plus the docusign directory cap) attach to the response pipeline and are transform-only where marked, so they never deny and never collide with the ingress controls. The ingress policies are each single-purpose — a role gate, a default-deny allowlist, a human-approval gate, an export cap, a scope fence, a destructive-op freeze — so several attach to the same app on the same direction without interfering. Where an app offers both a read-only posture and narrow write controls, pick one; combining them is redundant but harmless. Because SOC 2 scope is entity-defined, treat these themes as a menu: attach the controls that match the commitments in your own system description, not every policy by default.
These policies act only on agent traffic over MCP, and only some Trust Services Criteria reduce to a gateway decision. Out of scope by design:
finance, hr, infosec, sf-admins) are placeholders — map them to your directory's groups before relying on them.Compliance note. This bundle supports alignment with the cited framework controls on the MCP path only. No policy or bundle makes an organization compliant with any framework; web-UI, native-API, and in-app access are outside the gateway's reach by design. Validate against your own compliance program before relying on it.