{
  "name": "DTwo Policy Catalog",
  "description": "Curated catalog of reusable OPA/Rego policies for governing MCP tool calls via the DTwo MCP Gateway.",
  "source": "https://github.com/dtwoai/policy-store",
  "site": "https://www.intentbasedpolicy.com",
  "indexes": {
    "llms": "https://www.intentbasedpolicy.com/llms.txt",
    "llmsFull": "https://www.intentbasedpolicy.com/llms-full.txt",
    "sitemap": "https://www.intentbasedpolicy.com/sitemap-index.xml"
  },
  "counts": {
    "policies": 190,
    "apps": 33,
    "bundles": 9,
    "stories": 19
  },
  "apps": [
    {
      "slug": "airtable",
      "title": "Airtable",
      "url": "https://www.intentbasedpolicy.com/apps/airtable",
      "policyCount": 5
    },
    {
      "slug": "asana",
      "title": "Asana",
      "url": "https://www.intentbasedpolicy.com/apps/asana",
      "policyCount": 4
    },
    {
      "slug": "bigquery",
      "title": "Bigquery",
      "url": "https://www.intentbasedpolicy.com/apps/bigquery",
      "policyCount": 5
    },
    {
      "slug": "box",
      "title": "Box",
      "url": "https://www.intentbasedpolicy.com/apps/box",
      "policyCount": 5
    },
    {
      "slug": "confluence",
      "title": "Confluence",
      "url": "https://www.intentbasedpolicy.com/apps/confluence",
      "policyCount": 5
    },
    {
      "slug": "databricks",
      "title": "Databricks",
      "url": "https://www.intentbasedpolicy.com/apps/databricks",
      "policyCount": 6
    },
    {
      "slug": "docusign",
      "title": "Docusign",
      "url": "https://www.intentbasedpolicy.com/apps/docusign",
      "policyCount": 5
    },
    {
      "slug": "dropbox",
      "title": "Dropbox",
      "url": "https://www.intentbasedpolicy.com/apps/dropbox",
      "policyCount": 5
    },
    {
      "slug": "github",
      "title": "Github",
      "url": "https://www.intentbasedpolicy.com/apps/github",
      "policyCount": 6
    },
    {
      "slug": "glean",
      "title": "Glean",
      "url": "https://www.intentbasedpolicy.com/apps/glean",
      "policyCount": 5
    },
    {
      "slug": "gmail",
      "title": "Gmail",
      "url": "https://www.intentbasedpolicy.com/apps/gmail",
      "policyCount": 6
    },
    {
      "slug": "google-calendar",
      "title": "Google Calendar",
      "url": "https://www.intentbasedpolicy.com/apps/google-calendar",
      "policyCount": 4
    },
    {
      "slug": "google-drive",
      "title": "Google Drive",
      "url": "https://www.intentbasedpolicy.com/apps/google-drive",
      "policyCount": 6
    },
    {
      "slug": "gusto",
      "title": "Gusto",
      "url": "https://www.intentbasedpolicy.com/apps/gusto",
      "policyCount": 5
    },
    {
      "slug": "hubspot",
      "title": "Hubspot",
      "url": "https://www.intentbasedpolicy.com/apps/hubspot",
      "policyCount": 10
    },
    {
      "slug": "intercom",
      "title": "Intercom",
      "url": "https://www.intentbasedpolicy.com/apps/intercom",
      "policyCount": 5
    },
    {
      "slug": "jira",
      "title": "Jira",
      "url": "https://www.intentbasedpolicy.com/apps/jira",
      "policyCount": 8
    },
    {
      "slug": "linear",
      "title": "Linear",
      "url": "https://www.intentbasedpolicy.com/apps/linear",
      "policyCount": 5
    },
    {
      "slug": "monday",
      "title": "Monday",
      "url": "https://www.intentbasedpolicy.com/apps/monday",
      "policyCount": 5
    },
    {
      "slug": "ms365",
      "title": "Ms365",
      "url": "https://www.intentbasedpolicy.com/apps/ms365",
      "policyCount": 8
    },
    {
      "slug": "netsuite",
      "title": "Netsuite",
      "url": "https://www.intentbasedpolicy.com/apps/netsuite",
      "policyCount": 6
    },
    {
      "slug": "notion",
      "title": "Notion",
      "url": "https://www.intentbasedpolicy.com/apps/notion",
      "policyCount": 5
    },
    {
      "slug": "onboarding",
      "title": "Onboarding",
      "url": "https://www.intentbasedpolicy.com/apps/onboarding",
      "policyCount": 3
    },
    {
      "slug": "power-bi",
      "title": "Power Bi",
      "url": "https://www.intentbasedpolicy.com/apps/power-bi",
      "policyCount": 5
    },
    {
      "slug": "quickbooks",
      "title": "Quickbooks",
      "url": "https://www.intentbasedpolicy.com/apps/quickbooks",
      "policyCount": 6
    },
    {
      "slug": "salesforce",
      "title": "Salesforce",
      "url": "https://www.intentbasedpolicy.com/apps/salesforce",
      "policyCount": 9
    },
    {
      "slug": "servicenow",
      "title": "Servicenow",
      "url": "https://www.intentbasedpolicy.com/apps/servicenow",
      "policyCount": 6
    },
    {
      "slug": "slack",
      "title": "Slack",
      "url": "https://www.intentbasedpolicy.com/apps/slack",
      "policyCount": 10
    },
    {
      "slug": "snowflake",
      "title": "Snowflake",
      "url": "https://www.intentbasedpolicy.com/apps/snowflake",
      "policyCount": 6
    },
    {
      "slug": "stripe",
      "title": "Stripe",
      "url": "https://www.intentbasedpolicy.com/apps/stripe",
      "policyCount": 6
    },
    {
      "slug": "tableau",
      "title": "Tableau",
      "url": "https://www.intentbasedpolicy.com/apps/tableau",
      "policyCount": 5
    },
    {
      "slug": "zapier",
      "title": "Zapier",
      "url": "https://www.intentbasedpolicy.com/apps/zapier",
      "policyCount": 5
    },
    {
      "slug": "zoom",
      "title": "Zoom",
      "url": "https://www.intentbasedpolicy.com/apps/zoom",
      "policyCount": 5
    }
  ],
  "bundles": [
    {
      "slug": "atlassian",
      "title": "Atlassian",
      "url": "https://www.intentbasedpolicy.com/bundles/atlassian",
      "policyCount": 13
    },
    {
      "slug": "crm",
      "title": "Crm",
      "url": "https://www.intentbasedpolicy.com/bundles/crm",
      "policyCount": 19
    },
    {
      "slug": "gdpr-ccpa",
      "title": "Gdpr Ccpa",
      "url": "https://www.intentbasedpolicy.com/bundles/gdpr-ccpa",
      "policyCount": 100
    },
    {
      "slug": "hipaa",
      "title": "Hipaa",
      "url": "https://www.intentbasedpolicy.com/bundles/hipaa",
      "policyCount": 42
    },
    {
      "slug": "im-messaging",
      "title": "Im Messaging",
      "url": "https://www.intentbasedpolicy.com/bundles/im-messaging",
      "policyCount": 3
    },
    {
      "slug": "pci-dss",
      "title": "Pci Dss",
      "url": "https://www.intentbasedpolicy.com/bundles/pci-dss",
      "policyCount": 24
    },
    {
      "slug": "slack",
      "title": "Slack",
      "url": "https://www.intentbasedpolicy.com/bundles/slack",
      "policyCount": 7
    },
    {
      "slug": "soc2",
      "title": "Soc2",
      "url": "https://www.intentbasedpolicy.com/bundles/soc2",
      "policyCount": 173
    },
    {
      "slug": "sox",
      "title": "Sox",
      "url": "https://www.intentbasedpolicy.com/bundles/sox",
      "policyCount": 17
    }
  ],
  "stories": [
    {
      "slug": "stop-secrets-leaking-into-slack",
      "title": "Stop AI agents from leaking secrets into Slack",
      "dek": "Once an agent posts to Slack, an API key is in channel history and search. Catch it before the send, not after.",
      "url": "https://www.intentbasedpolicy.com/stories/stop-secrets-leaking-into-slack",
      "policies": [
        "https://www.intentbasedpolicy.com/policies/slack/block-secrets",
        "https://www.intentbasedpolicy.com/policies/slack/redact-sensitive-info"
      ]
    },
    {
      "slug": "keep-customer-pii-inside-your-crm",
      "title": "Keep customer PII from walking out of your CRM",
      "dek": "An agent reading Salesforce or HubSpot pulls emails, phone numbers, and addresses into its context and your chat logs. Mask them on the way out.",
      "url": "https://www.intentbasedpolicy.com/stories/keep-customer-pii-inside-your-crm",
      "policies": [
        "https://www.intentbasedpolicy.com/policies/salesforce/redact-pii",
        "https://www.intentbasedpolicy.com/policies/hubspot/redact-pii",
        "https://www.intentbasedpolicy.com/policies/salesforce/protect-contact-fields"
      ]
    },
    {
      "slug": "read-only-crm-for-ai-agents",
      "title": "Give AI agents read-only access to your CRM",
      "dek": "For a low-risk CRM pilot, give the agent a one-way mirror: it reads every record and changes none. The read-only policies enforce that, and a query allowlist tightens it further.",
      "url": "https://www.intentbasedpolicy.com/stories/read-only-crm-for-ai-agents",
      "policies": [
        "https://www.intentbasedpolicy.com/policies/salesforce/read-only",
        "https://www.intentbasedpolicy.com/policies/hubspot/read-only",
        "https://www.intentbasedpolicy.com/policies/salesforce/query-allowlist"
      ]
    },
    {
      "slug": "guard-high-stakes-crm-writes",
      "title": "Guard the CRM writes your revenue depends on",
      "dek": "You want agents logging activities and creating records, just not closing deals or reassigning owners on their own. Gate the few writes that matter.",
      "url": "https://www.intentbasedpolicy.com/stories/guard-high-stakes-crm-writes",
      "policies": [
        "https://www.intentbasedpolicy.com/policies/hubspot/block-deal-closure",
        "https://www.intentbasedpolicy.com/policies/hubspot/protect-deal-owner",
        "https://www.intentbasedpolicy.com/policies/hubspot/protect-associations",
        "https://www.intentbasedpolicy.com/policies/hubspot/protect-lifecycle-stage"
      ]
    },
    {
      "slug": "wall-off-sensitive-jira-projects",
      "title": "Wall off sensitive Jira projects from AI agents",
      "dek": "Security, legal, and HR projects share the same Jira as your sprint board. Keep agents from reading or writing them, and redact whatever still comes back.",
      "url": "https://www.intentbasedpolicy.com/stories/wall-off-sensitive-jira-projects",
      "policies": [
        "https://www.intentbasedpolicy.com/policies/jira/deny-view-search-sensitive-projects",
        "https://www.intentbasedpolicy.com/policies/jira/deny-write-sensitive-projects",
        "https://www.intentbasedpolicy.com/policies/jira/redact-sensitive-info"
      ]
    },
    {
      "slug": "slack-hygiene-for-ai-agents",
      "title": "Slack hygiene for autonomous AI agents",
      "dek": "Slack's OAuth scopes pick capabilities, not the channels they apply to: you can grant an agent 'post messages,' but not 'post only in #status' — one scope covers every channel at once.",
      "url": "https://www.intentbasedpolicy.com/stories/slack-hygiene-for-ai-agents",
      "policies": [
        "https://www.intentbasedpolicy.com/policies/slack/deny-channel-creation",
        "https://www.intentbasedpolicy.com/policies/slack/deny-direct-messages",
        "https://www.intentbasedpolicy.com/policies/slack/deny-read-search-summarize-sensitive-channels"
      ]
    },
    {
      "slug": "hipaa-aligned-controls-for-ai-agents",
      "title": "HIPAA-aligned controls for AI agents touching PHI",
      "dek": "A connector into email, a helpdesk, or a warehouse can pull protected health information into an agent's context. These policies support HIPAA-aligned minimum-necessary, access, and de-identification controls on the MCP path.",
      "url": "https://www.intentbasedpolicy.com/stories/hipaa-aligned-controls-for-ai-agents",
      "policies": [
        "https://www.intentbasedpolicy.com/policies/box/redact-pii-egress",
        "https://www.intentbasedpolicy.com/policies/gmail/cap-bulk-export",
        "https://www.intentbasedpolicy.com/policies/intercom/redact-conversation-pii",
        "https://www.intentbasedpolicy.com/policies/slack/guard-dm-privacy"
      ]
    },
    {
      "slug": "pci-dss-aligned-controls-for-ai-agents",
      "title": "Keep cardholder data out of an AI agent's reach",
      "dek": "A PAN can surface in a chat message, a support ticket, or a warehouse query. These policies support PCI DSS-aligned masking and least-privilege controls on the agent channel.",
      "url": "https://www.intentbasedpolicy.com/stories/pci-dss-aligned-controls-for-ai-agents",
      "policies": [
        "https://www.intentbasedpolicy.com/policies/slack/mask-pan-egress",
        "https://www.intentbasedpolicy.com/policies/stripe/gate-money-movement-refund-cap",
        "https://www.intentbasedpolicy.com/policies/snowflake/guard-warehouse-sql",
        "https://www.intentbasedpolicy.com/policies/salesforce/query-allowlist"
      ]
    },
    {
      "slug": "soc2-access-controls-for-ai-agents",
      "title": "SOC 2-aligned access control for AI agents",
      "dek": "Auditors increasingly treat an agent as a privileged identity. These policies support the most-tested SOC 2 access, boundary, and change-management criteria — with a per-decision audit trail.",
      "url": "https://www.intentbasedpolicy.com/stories/soc2-access-controls-for-ai-agents",
      "policies": [
        "https://www.intentbasedpolicy.com/policies/salesforce/read-only",
        "https://www.intentbasedpolicy.com/policies/ms365/role-gate-writes",
        "https://www.intentbasedpolicy.com/policies/servicenow/default-deny-unknown-tools",
        "https://www.intentbasedpolicy.com/policies/github/require-human-approval-merge"
      ]
    },
    {
      "slug": "sox-controls-for-ai-agents-in-finance",
      "title": "SOX-aligned controls for AI agents in finance systems",
      "dek": "An agent in the ERP can draft — but it should never post, pay, delete, or approve on its own. These policies support SOX ICFR and ITGC controls on the agent channel.",
      "url": "https://www.intentbasedpolicy.com/stories/sox-controls-for-ai-agents-in-finance",
      "policies": [
        "https://www.intentbasedpolicy.com/policies/netsuite/protect-closed-periods",
        "https://www.intentbasedpolicy.com/policies/quickbooks/gate-money-movement",
        "https://www.intentbasedpolicy.com/policies/netsuite/guard-vendor-banking",
        "https://www.intentbasedpolicy.com/policies/github/require-human-approval-merge"
      ]
    },
    {
      "slug": "stop-ai-agents-sending-mail-as-your-staff",
      "title": "Stop an AI agent from sending mail as your employees",
      "dek": "An agent with mailbox access can email outsiders, and quietly set forwarding rules that leak every future message. Gate the send and freeze the rules.",
      "url": "https://www.intentbasedpolicy.com/stories/stop-ai-agents-sending-mail-as-your-staff",
      "policies": [
        "https://www.intentbasedpolicy.com/policies/ms365/guard-external-send",
        "https://www.intentbasedpolicy.com/policies/ms365/guard-mailbox-persistence",
        "https://www.intentbasedpolicy.com/policies/ms365/freeze-identity-plane",
        "https://www.intentbasedpolicy.com/policies/gmail/guard-external-send"
      ]
    },
    {
      "slug": "keep-agents-from-oversharing-files",
      "title": "Keep an AI agent from sharing your files with the internet",
      "dek": "A file connector's most dangerous tool isn't read — it's the one that mints a public share link. Deny anonymous links and fence the folders that matter.",
      "url": "https://www.intentbasedpolicy.com/stories/keep-agents-from-oversharing-files",
      "policies": [
        "https://www.intentbasedpolicy.com/policies/box/guard-share-links-external",
        "https://www.intentbasedpolicy.com/policies/dropbox/guard-share-links-external",
        "https://www.intentbasedpolicy.com/policies/google-drive/fence-restricted-folders",
        "https://www.intentbasedpolicy.com/policies/google-drive/guard-acl-recon",
        "https://www.intentbasedpolicy.com/policies/google-drive/redact-pii-egress"
      ]
    },
    {
      "slug": "query-the-warehouse-without-draining-it",
      "title": "Let agents query the warehouse without draining it",
      "dek": "Natural-language SQL is one tool call away from a full-table export. Constrain the statement, cap the pull, and mask what comes back.",
      "url": "https://www.intentbasedpolicy.com/stories/query-the-warehouse-without-draining-it",
      "policies": [
        "https://www.intentbasedpolicy.com/policies/snowflake/guard-warehouse-sql",
        "https://www.intentbasedpolicy.com/policies/snowflake/guard-warehouse-export",
        "https://www.intentbasedpolicy.com/policies/snowflake/fence-sensitive-schemas",
        "https://www.intentbasedpolicy.com/policies/bigquery/guard-warehouse-sql",
        "https://www.intentbasedpolicy.com/policies/snowflake/redact-pii-egress"
      ]
    },
    {
      "slug": "let-agents-touch-stripe-without-moving-money",
      "title": "Let an AI agent touch Stripe without letting it move money",
      "dek": "Refunds, payouts, and disputes are irreversible the moment they fire. Cap the amounts, gate the approvals, and close the raw-API back door.",
      "url": "https://www.intentbasedpolicy.com/stories/let-agents-touch-stripe-without-moving-money",
      "policies": [
        "https://www.intentbasedpolicy.com/policies/stripe/gate-money-movement-refund-cap",
        "https://www.intentbasedpolicy.com/policies/stripe/require-human-approval-dispute-submit",
        "https://www.intentbasedpolicy.com/policies/stripe/deny-escape-hatches-api-write",
        "https://www.intentbasedpolicy.com/policies/stripe/role-gate-writes-billing",
        "https://www.intentbasedpolicy.com/policies/stripe/redact-pii-egress-customer"
      ]
    },
    {
      "slug": "give-agents-github-without-leaking-code",
      "title": "Give an agent GitHub access without letting it merge or leak code",
      "dek": "Source code is crown-jewel data, and a merge or a public repo is a one-call mistake. Keep the agent to drafts and keep secrets out of commits.",
      "url": "https://www.intentbasedpolicy.com/stories/give-agents-github-without-leaking-code",
      "policies": [
        "https://www.intentbasedpolicy.com/policies/github/require-human-approval-merge",
        "https://www.intentbasedpolicy.com/policies/github/deny-public-exposure-repos",
        "https://www.intentbasedpolicy.com/policies/github/block-secrets-commits",
        "https://www.intentbasedpolicy.com/policies/github/redact-secrets-egress",
        "https://www.intentbasedpolicy.com/policies/github/fence-scopes-org-allowlist"
      ]
    },
    {
      "slug": "govern-enterprise-search-across-every-system",
      "title": "Govern the one search tool that reaches every system",
      "dek": "Enterprise search fans out across everything indexed, so one query can surface what a dozen per-app policies would each have caught. The chokepoint is egress.",
      "url": "https://www.intentbasedpolicy.com/stories/govern-enterprise-search-across-every-system",
      "policies": [
        "https://www.intentbasedpolicy.com/policies/glean/fence-datasource-scope",
        "https://www.intentbasedpolicy.com/policies/glean/cap-search-export",
        "https://www.intentbasedpolicy.com/policies/glean/redact-pii-egress",
        "https://www.intentbasedpolicy.com/policies/glean/default-deny-unknown-tools"
      ]
    },
    {
      "slug": "keep-meeting-recordings-need-to-know",
      "title": "Keep meeting recordings and transcripts need-to-know",
      "dek": "Recordings and transcripts are sensitive by default — comp talk, deal terms, health details. Gate who an agent can pull them for, and mask what it returns.",
      "url": "https://www.intentbasedpolicy.com/stories/keep-meeting-recordings-need-to-know",
      "policies": [
        "https://www.intentbasedpolicy.com/policies/zoom/guard-transcripts-by-group",
        "https://www.intentbasedpolicy.com/policies/zoom/redact-pii-meeting-intelligence",
        "https://www.intentbasedpolicy.com/policies/zoom/fence-agentic-search",
        "https://www.intentbasedpolicy.com/policies/zoom/block-secrets-chat"
      ]
    },
    {
      "slug": "protect-payroll-data-from-ai-agents",
      "title": "Keep payroll and compensation data out of an agent's reach",
      "dek": "An HR connector exposes salaries, bank details, and terminations. Fence the sensitive reads to HR, freeze the writes, and mask financial identifiers.",
      "url": "https://www.intentbasedpolicy.com/stories/protect-payroll-data-from-ai-agents",
      "policies": [
        "https://www.intentbasedpolicy.com/policies/gusto/fence-comp-payroll-reads",
        "https://www.intentbasedpolicy.com/policies/gusto/freeze-payroll-writes",
        "https://www.intentbasedpolicy.com/policies/gusto/redact-financial-ids-egress",
        "https://www.intentbasedpolicy.com/policies/gusto/cap-roster-export"
      ]
    },
    {
      "slug": "gdpr-aligned-controls-for-ai-agents",
      "title": "GDPR-aligned controls for AI agents handling personal data",
      "dek": "Almost every connector an agent touches holds personal data. These policies support GDPR and CCPA-aligned minimisation and special-category controls on the MCP path.",
      "url": "https://www.intentbasedpolicy.com/stories/gdpr-aligned-controls-for-ai-agents",
      "policies": [
        "https://www.intentbasedpolicy.com/policies/gmail/cap-bulk-export",
        "https://www.intentbasedpolicy.com/policies/google-drive/redact-pii-egress",
        "https://www.intentbasedpolicy.com/policies/salesforce/redact-pii",
        "https://www.intentbasedpolicy.com/policies/intercom/redact-conversation-pii",
        "https://www.intentbasedpolicy.com/policies/notion/fence-user-directory"
      ]
    }
  ],
  "policies": [
    {
      "slug": "airtable/redact-pii-egress",
      "name": "Airtable: Redact PII in Record Reads",
      "summary": "Scans the responses of the Airtable record-read tools — the calls that return row fields values — and rewrites high-confidence PII shapes to a fixed…",
      "url": "https://www.intentbasedpolicy.com/policies/airtable/redact-pii-egress",
      "markdown": "https://www.intentbasedpolicy.com/policies/airtable/redact-pii-egress.md",
      "app": "airtable",
      "apps": [
        "airtable"
      ],
      "bundles": [
        "soc2",
        "gdpr-ccpa"
      ],
      "tags": [
        "airtable",
        "redact-pii",
        "pii",
        "dlp",
        "redaction",
        "egress",
        "soc2",
        "gdpr-ccpa"
      ],
      "direction": "egress",
      "package": "airtable.egress.redact_pii",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:4111337a2e5dd289f5a8b38aad3414b212f22ffbd2cfd74e3d162726bfb06987",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/airtable/redact-pii-egress",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/airtable/redact-pii-egress/policy.md"
    },
    {
      "slug": "asana/redact-task-pii",
      "name": "Asana: Redact PII in Task & Comment Reads",
      "summary": "On the Asana MCP read path, this transform scans the free-text business fields that ride back in task, comment/story, and status-update responses — notes,…",
      "url": "https://www.intentbasedpolicy.com/policies/asana/redact-task-pii",
      "markdown": "https://www.intentbasedpolicy.com/policies/asana/redact-task-pii.md",
      "app": "asana",
      "apps": [
        "asana"
      ],
      "bundles": [
        "soc2",
        "gdpr-ccpa"
      ],
      "tags": [
        "asana",
        "redact-pii",
        "pii",
        "dlp",
        "redaction",
        "egress",
        "soc2",
        "gdpr-ccpa"
      ],
      "direction": "egress",
      "package": "asana.egress.redact_task_pii",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:88c779d4e795f8e2e4af4929d357f0a23626eafc11372be6233aff4f297705d6",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/asana/redact-task-pii",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/asana/redact-task-pii/policy.md"
    },
    {
      "slug": "bigquery/redact-pii-egress",
      "name": "BigQuery: Redact PII in Query Results",
      "summary": "Scans the content returned by BigQuery's result-returning tools and rewrites high-confidence PII shapes to fixed, non-recoverable redaction tokens before the…",
      "url": "https://www.intentbasedpolicy.com/policies/bigquery/redact-pii-egress",
      "markdown": "https://www.intentbasedpolicy.com/policies/bigquery/redact-pii-egress.md",
      "app": "bigquery",
      "apps": [
        "bigquery"
      ],
      "bundles": [
        "soc2",
        "hipaa",
        "gdpr-ccpa"
      ],
      "tags": [
        "bigquery",
        "redact-pii",
        "pii",
        "dlp",
        "redaction",
        "egress",
        "soc2",
        "hipaa",
        "gdpr-ccpa"
      ],
      "direction": "egress",
      "package": "bigquery.egress.redact_pii",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:b5db39d7244865397c557901f80cadac5c9daa7294c530bdb6493a41750b632b",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/bigquery/redact-pii-egress",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/bigquery/redact-pii-egress/policy.md"
    },
    {
      "slug": "ms365/guard-external-send",
      "name": "Block Agent Email to External Recipients",
      "summary": "Blocks agent-initiated Microsoft 365 email sends when any recipient address falls outside a corporate-domain allowlist.",
      "url": "https://www.intentbasedpolicy.com/policies/ms365/guard-external-send",
      "markdown": "https://www.intentbasedpolicy.com/policies/ms365/guard-external-send.md",
      "app": "ms365",
      "apps": [
        "ms365"
      ],
      "bundles": [
        "soc2",
        "hipaa",
        "gdpr-ccpa"
      ],
      "tags": [
        "ms365",
        "guard-external-send",
        "ingress",
        "email",
        "dlp",
        "soc2",
        "hipaa",
        "gdpr-ccpa"
      ],
      "direction": "ingress",
      "package": "ms365.ingress.guard_external_send",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:5d93b876f4adf8930f56e199412451d19ad27b7de1a66f3bcf28a7599f87f916",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/ms365/guard-external-send",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/ms365/guard-external-send/policy.md"
    },
    {
      "slug": "bigquery/guard-warehouse-export",
      "name": "Block BigQuery Exfiltration and Cross-Project Writes",
      "summary": "Inspects the raw GoogleSQL string carried by BigQuery SQL tools and denies any statement that moves data out of the tenant's own project — even when the call…",
      "url": "https://www.intentbasedpolicy.com/policies/bigquery/guard-warehouse-export",
      "markdown": "https://www.intentbasedpolicy.com/policies/bigquery/guard-warehouse-export.md",
      "app": "bigquery",
      "apps": [
        "bigquery"
      ],
      "bundles": [
        "soc2",
        "pci-dss",
        "gdpr-ccpa"
      ],
      "tags": [
        "bigquery",
        "guard-warehouse-export",
        "ingress",
        "sql",
        "exfiltration",
        "soc2",
        "pci-dss",
        "gdpr-ccpa"
      ],
      "direction": "ingress",
      "package": "bigquery.ingress.guard_warehouse_export",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:e5fb526cace70c61eaa20320c7666cc349ff0fb5b0cfbe41bde36723cfe1dbed",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/bigquery/guard-warehouse-export",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/bigquery/guard-warehouse-export/policy.md"
    },
    {
      "slug": "snowflake/guard-warehouse-export",
      "name": "Block Bulk Export & External Staging (Snowflake)",
      "summary": "Blocks Snowflake SQL-execution tool calls whose query text moves whole tables off the Snowflake perimeter — bulk export to cloud storage or a stage, and…",
      "url": "https://www.intentbasedpolicy.com/policies/snowflake/guard-warehouse-export",
      "markdown": "https://www.intentbasedpolicy.com/policies/snowflake/guard-warehouse-export.md",
      "app": "snowflake",
      "apps": [
        "snowflake"
      ],
      "bundles": [
        "soc2",
        "pci-dss",
        "gdpr-ccpa"
      ],
      "tags": [
        "snowflake",
        "guard-warehouse-sql",
        "export",
        "exfiltration",
        "ingress",
        "soc2",
        "pci-dss",
        "gdpr-ccpa"
      ],
      "direction": "ingress",
      "package": "snowflake.ingress.guard_warehouse_export",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:ab74fedbc153b6ae175a393a1be8bec7d675b0bd2e2d1272b5f1f3592785f94d",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/snowflake/guard-warehouse-export",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/snowflake/guard-warehouse-export/policy.md"
    },
    {
      "slug": "google-calendar/guard-external-attendees",
      "name": "Block Calendar Invites to External Attendees",
      "summary": "Denies Google Calendar event-write tool calls — create event / create-event, update event / update-event, and the consolidated manage event — whenever any…",
      "url": "https://www.intentbasedpolicy.com/policies/google-calendar/guard-external-attendees",
      "markdown": "https://www.intentbasedpolicy.com/policies/google-calendar/guard-external-attendees.md",
      "app": "google-calendar",
      "apps": [
        "google-calendar"
      ],
      "bundles": [
        "soc2",
        "hipaa",
        "gdpr-ccpa"
      ],
      "tags": [
        "google-calendar",
        "guard-external-send",
        "ingress",
        "calendar",
        "soc2",
        "hipaa",
        "gdpr-ccpa"
      ],
      "direction": "ingress",
      "package": "google_calendar.ingress.guard_external_attendees",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:8c2c26a8f6af21065976ab4bb529255ddbdd1b786db0f3b942287ee835b17aeb",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/google-calendar/guard-external-attendees",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/google-calendar/guard-external-attendees/policy.md"
    },
    {
      "slug": "notion/guard-datasource-sql",
      "name": "Block Destructive and Export SQL on Notion Data Sources",
      "summary": "Inspects Notion data-source query tool calls (notion-query-data-sources on the hosted server, query-data-source on the official local server) and denies any…",
      "url": "https://www.intentbasedpolicy.com/policies/notion/guard-datasource-sql",
      "markdown": "https://www.intentbasedpolicy.com/policies/notion/guard-datasource-sql.md",
      "app": "notion",
      "apps": [
        "notion"
      ],
      "bundles": [
        "soc2"
      ],
      "tags": [
        "notion",
        "guard-warehouse-sql",
        "ingress",
        "sql",
        "readonly",
        "soc2"
      ],
      "direction": "ingress",
      "package": "notion.ingress.guard_datasource_sql",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:064ca68f936ce996768ed384abd91bd02a25a1742961fae017de5b46e20ee812",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/notion/guard-datasource-sql",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/notion/guard-datasource-sql/policy.md"
    },
    {
      "slug": "snowflake/guard-warehouse-sql",
      "name": "Block Destructive and Mutating Snowflake SQL",
      "summary": "Inspects the SQL text that Snowflake MCP tools carry in their query argument and denies any statement in a mutating or destructive class — DROP, TRUNCATE,…",
      "url": "https://www.intentbasedpolicy.com/policies/snowflake/guard-warehouse-sql",
      "markdown": "https://www.intentbasedpolicy.com/policies/snowflake/guard-warehouse-sql.md",
      "app": "snowflake",
      "apps": [
        "snowflake"
      ],
      "bundles": [
        "soc2",
        "pci-dss",
        "sox"
      ],
      "tags": [
        "snowflake",
        "guard-warehouse-sql",
        "ingress",
        "sql",
        "readonly",
        "soc2",
        "pci-dss",
        "sox"
      ],
      "direction": "ingress",
      "package": "snowflake.ingress.guard_warehouse_sql",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:080aca455a6d649e34376608ead8f05f9d7d567a6adf672e425cc806691e6b36",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/snowflake/guard-warehouse-sql",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/snowflake/guard-warehouse-sql/policy.md"
    },
    {
      "slug": "bigquery/guard-warehouse-sql",
      "name": "Block Destructive SQL in BigQuery Queries",
      "summary": "Inspects the raw GoogleSQL string carried by BigQuery write-capable query tools and denies any statement in a state-changing class — DML…",
      "url": "https://www.intentbasedpolicy.com/policies/bigquery/guard-warehouse-sql",
      "markdown": "https://www.intentbasedpolicy.com/policies/bigquery/guard-warehouse-sql.md",
      "app": "bigquery",
      "apps": [
        "bigquery"
      ],
      "bundles": [
        "soc2",
        "pci-dss",
        "sox"
      ],
      "tags": [
        "bigquery",
        "guard-warehouse-sql",
        "ingress",
        "sql",
        "readonly",
        "soc2",
        "pci-dss",
        "sox"
      ],
      "direction": "ingress",
      "package": "bigquery.ingress.guard_warehouse_sql",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:fecb650bae4cb011aeaa1be5db3f6d09b7f438cadc0adc82725bc2b3adaf1013",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/bigquery/guard-warehouse-sql",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/bigquery/guard-warehouse-sql/policy.md"
    },
    {
      "slug": "zapier/guard-external-send",
      "name": "Block External Sends Hidden in Zapier Instructions",
      "summary": "Every Zapier MCP tool — in both the agentic and classic modes — accepts a free-text instructions string that Zapier's server-side AI uses to fill any…",
      "url": "https://www.intentbasedpolicy.com/policies/zapier/guard-external-send",
      "markdown": "https://www.intentbasedpolicy.com/policies/zapier/guard-external-send.md",
      "app": "zapier",
      "apps": [
        "zapier"
      ],
      "bundles": [
        "soc2",
        "gdpr-ccpa"
      ],
      "tags": [
        "zapier",
        "guard-external-send",
        "ingress",
        "email",
        "soc2",
        "gdpr-ccpa"
      ],
      "direction": "ingress",
      "package": "zapier.ingress.guard_external_send",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:18ea4e45b9425fe42e78c08b80421933eca80194d303f38e0900aa6670da2c2b",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/zapier/guard-external-send",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/zapier/guard-external-send/policy.md"
    },
    {
      "slug": "zoom/guard-external-chat-invites",
      "name": "Block External Team Chat Invites & Members",
      "summary": "Stops a Zoom Team Chat agent from pulling external parties into the organization's chat surface.",
      "url": "https://www.intentbasedpolicy.com/policies/zoom/guard-external-chat-invites",
      "markdown": "https://www.intentbasedpolicy.com/policies/zoom/guard-external-chat-invites.md",
      "app": "zoom",
      "apps": [
        "zoom"
      ],
      "bundles": [
        "soc2",
        "gdpr-ccpa",
        "hipaa"
      ],
      "tags": [
        "zoom",
        "guard-external-send",
        "ingress",
        "team-chat",
        "soc2",
        "gdpr-ccpa",
        "hipaa"
      ],
      "direction": "ingress",
      "package": "zoom.ingress.guard_external_chat_invites",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:caa489fb1e0b547c1f18eb5bde847dc54e555490f4d74d99c52a53df24eff91d",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/zoom/guard-external-chat-invites",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/zoom/guard-external-chat-invites/policy.md"
    },
    {
      "slug": "gmail/guard-mailbox-persistence",
      "name": "Block Gmail Filter Creation (Auto-Forward Persistence)",
      "summary": "Blocks the classic BEC/exfiltration persistence primitive: Gmail filters that can auto-forward or auto-delete mail and outlive the agent session.",
      "url": "https://www.intentbasedpolicy.com/policies/gmail/guard-mailbox-persistence",
      "markdown": "https://www.intentbasedpolicy.com/policies/gmail/guard-mailbox-persistence.md",
      "app": "gmail",
      "apps": [
        "gmail"
      ],
      "bundles": [
        "soc2"
      ],
      "tags": [
        "gmail",
        "guard-mailbox-persistence",
        "ingress",
        "bec",
        "finserv-comms",
        "soc2"
      ],
      "direction": "ingress",
      "package": "gmail.ingress.guard_mailbox_persistence",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:ecf336aec801d6c8ccec5f95d027205203782eeb4b9136186b077009ef257f05",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/gmail/guard-mailbox-persistence",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/gmail/guard-mailbox-persistence/policy.md"
    },
    {
      "slug": "docusign/freeze-destructive-ops",
      "name": "Block Irreversible Docusign Void and Workflow Kills",
      "summary": "Denies the irreversible destructive operations on the Docusign agent path:",
      "url": "https://www.intentbasedpolicy.com/policies/docusign/freeze-destructive-ops",
      "markdown": "https://www.intentbasedpolicy.com/policies/docusign/freeze-destructive-ops.md",
      "app": "docusign",
      "apps": [
        "docusign"
      ],
      "bundles": [
        "soc2"
      ],
      "tags": [
        "docusign",
        "freeze-destructive-ops",
        "ingress",
        "soc2"
      ],
      "direction": "ingress",
      "package": "docusign.ingress.freeze_destructive_ops",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:f6a8b10e38a3096a1f8dcd1b83a5d59f645b680015160eda7711e4d05effe476",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/docusign/freeze-destructive-ops",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/docusign/freeze-destructive-ops/policy.md"
    },
    {
      "slug": "linear/guard-webhook-persistence",
      "name": "Block Linear Webhook Creation",
      "summary": "Unconditionally denies any Linear tool that creates, updates, or deletes a webhook — linear createWebhook, linear deleteWebhook, and update variants.",
      "url": "https://www.intentbasedpolicy.com/policies/linear/guard-webhook-persistence",
      "markdown": "https://www.intentbasedpolicy.com/policies/linear/guard-webhook-persistence.md",
      "app": "linear",
      "apps": [
        "linear"
      ],
      "bundles": [
        "soc2"
      ],
      "tags": [
        "linear",
        "guard-webhook-persistence",
        "ingress",
        "webhook",
        "exfiltration",
        "soc2"
      ],
      "direction": "ingress",
      "package": "linear.ingress.guard_webhook_persistence",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:89952ab95c0ff7b7c54f0ea3cac2c597cd238d09e79fb485a7feb289df072856",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/linear/guard-webhook-persistence",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/linear/guard-webhook-persistence/policy.md"
    },
    {
      "slug": "ms365/guard-mailbox-persistence",
      "name": "Block Mail-Rule and Webhook Persistence",
      "summary": "Unconditionally denies the classic business-email-compromise (BEC) persistence surface in Microsoft 365: creating or updating Outlook mail rules, changing…",
      "url": "https://www.intentbasedpolicy.com/policies/ms365/guard-mailbox-persistence",
      "markdown": "https://www.intentbasedpolicy.com/policies/ms365/guard-mailbox-persistence.md",
      "app": "ms365",
      "apps": [
        "ms365"
      ],
      "bundles": [
        "soc2"
      ],
      "tags": [
        "ms365",
        "guard-mailbox-persistence",
        "ingress",
        "bec",
        "email",
        "finserv-comms",
        "soc2"
      ],
      "direction": "ingress",
      "package": "ms365.ingress.guard_mailbox_persistence",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:3307b4d034a1506135787bca00e71ce57bc7d91f601db73238dc1e32f6dd827f",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/ms365/guard-mailbox-persistence",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/ms365/guard-mailbox-persistence/policy.md"
    },
    {
      "slug": "power-bi/block-rls-bypass-service-principal",
      "name": "Block Power BI RLS-Bypass Service-Principal Queries",
      "summary": "On Microsoft's remote Power BI MCP server (https://api.fabric.microsoft.",
      "url": "https://www.intentbasedpolicy.com/policies/power-bi/block-rls-bypass-service-principal",
      "markdown": "https://www.intentbasedpolicy.com/policies/power-bi/block-rls-bypass-service-principal.md",
      "app": "power-bi",
      "apps": [
        "power-bi"
      ],
      "bundles": [
        "soc2"
      ],
      "tags": [
        "power-bi",
        "role-gate-writes",
        "rls",
        "service-principal",
        "ingress",
        "soc2"
      ],
      "direction": "ingress",
      "package": "power_bi.ingress.block_rls_bypass_service_principal",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:551a94c81e5724d5e2528feda9b780fb0d4aced2833da05a7c1e54dcae79d945",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/power-bi/block-rls-bypass-service-principal",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/power-bi/block-rls-bypass-service-principal/policy.md"
    },
    {
      "slug": "dropbox/guard-share-links-external",
      "name": "Block Public Dropbox Share, Download, and File-Request Links",
      "summary": "Denies, by default, the Dropbox tools that turn an internal file into an internet-visible resource in a single call — before the request ever reaches Dropbox:",
      "url": "https://www.intentbasedpolicy.com/policies/dropbox/guard-share-links-external",
      "markdown": "https://www.intentbasedpolicy.com/policies/dropbox/guard-share-links-external.md",
      "app": "dropbox",
      "apps": [
        "dropbox"
      ],
      "bundles": [
        "soc2",
        "hipaa",
        "gdpr-ccpa"
      ],
      "tags": [
        "dropbox",
        "guard-share-links",
        "sharing",
        "external-sharing",
        "ingress",
        "soc2",
        "hipaa",
        "gdpr-ccpa"
      ],
      "direction": "ingress",
      "package": "dropbox.ingress.guard_share_links_external",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:2ba453c01d2723e725e7a76744f21a1f2692a1e980d2ff7a477b899356f3ac70",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/dropbox/guard-share-links-external",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/dropbox/guard-share-links-external/policy.md"
    },
    {
      "slug": "google-calendar/guard-public-exposure",
      "name": "Block Public Visibility & Guest Delegation",
      "summary": "Blocks Google Calendar create and update event calls that would expose the event to the world or hand control of it to guests.",
      "url": "https://www.intentbasedpolicy.com/policies/google-calendar/guard-public-exposure",
      "markdown": "https://www.intentbasedpolicy.com/policies/google-calendar/guard-public-exposure.md",
      "app": "google-calendar",
      "apps": [
        "google-calendar"
      ],
      "bundles": [
        "soc2",
        "gdpr-ccpa"
      ],
      "tags": [
        "google-calendar",
        "guard-public-exposure",
        "ingress",
        "soc2",
        "gdpr-ccpa"
      ],
      "direction": "ingress",
      "package": "google_calendar.ingress.guard_public_exposure",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:be9e13d54d01cee61f77848f98c328060d87b94c0d809c17fe0474118a0f5159",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/google-calendar/guard-public-exposure",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/google-calendar/guard-public-exposure/policy.md"
    },
    {
      "slug": "confluence/block-secrets",
      "name": "Block Secrets in Confluence Pages and Comments",
      "summary": "Blocks Confluence write calls whose body looks like it contains a live credential — an API key, password, token, or PEM-formatted private key — before the…",
      "url": "https://www.intentbasedpolicy.com/policies/confluence/block-secrets",
      "markdown": "https://www.intentbasedpolicy.com/policies/confluence/block-secrets.md",
      "app": "confluence",
      "apps": [
        "confluence"
      ],
      "bundles": [
        "atlassian",
        "soc2"
      ],
      "tags": [
        "confluence",
        "secrets",
        "dlp",
        "ingress",
        "soc2",
        "atlassian"
      ],
      "direction": "ingress",
      "package": "confluence.ingress.block_secrets",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:86e05d9056df21bb6a29145ee141cecc2c88219fe48402d1fd8a8776acb4e36e",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/confluence/block-secrets",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/confluence/block-secrets/policy.md"
    },
    {
      "slug": "github/block-secrets-commits",
      "name": "Block Secrets in GitHub Commits & PRs",
      "summary": "Blocks GitHub write tool calls whose payload looks like it carries a live credential into a repository, gist, pull request, or comment.",
      "url": "https://www.intentbasedpolicy.com/policies/github/block-secrets-commits",
      "markdown": "https://www.intentbasedpolicy.com/policies/github/block-secrets-commits.md",
      "app": "github",
      "apps": [
        "github"
      ],
      "bundles": [
        "soc2"
      ],
      "tags": [
        "github",
        "secrets",
        "dlp",
        "ingress",
        "soc2"
      ],
      "direction": "ingress",
      "package": "github.ingress.block_secrets_commits",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:6ee3683c879325ec5d940127324281eb079a5dc2b5d7d811f538ce24c1354096",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/github/block-secrets-commits",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/github/block-secrets-commits/policy.md"
    },
    {
      "slug": "slack/block-secrets",
      "name": "Block Secrets in Slack Messages",
      "summary": "Blocks Slack send-message tool calls whose message body looks like it contains a secret — API keys, passwords, tokens, or PEM-formatted private keys.",
      "url": "https://www.intentbasedpolicy.com/policies/slack/block-secrets",
      "markdown": "https://www.intentbasedpolicy.com/policies/slack/block-secrets.md",
      "app": "slack",
      "apps": [
        "slack"
      ],
      "bundles": [
        "im-messaging",
        "soc2"
      ],
      "tags": [
        "slack",
        "secrets",
        "dlp",
        "ingress",
        "soc2",
        "iso27001-nist"
      ],
      "direction": "ingress",
      "package": "slack.ingress.block_secrets",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:c694c2624700c1dd750e33b4ba1171f03cca77009977871a01d5d7dd8a9d1d99",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/slack/block-secrets",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/slack/block-secrets/policy.md"
    },
    {
      "slug": "zoom/block-secrets-chat",
      "name": "Block Secrets in Zoom Team Chat",
      "summary": "Blocks Zoom Team Chat send/update tool calls whose message content looks like it contains a live secret — API keys, passwords, bearer tokens, or…",
      "url": "https://www.intentbasedpolicy.com/policies/zoom/block-secrets-chat",
      "markdown": "https://www.intentbasedpolicy.com/policies/zoom/block-secrets-chat.md",
      "app": "zoom",
      "apps": [
        "zoom"
      ],
      "bundles": [
        "soc2"
      ],
      "tags": [
        "zoom",
        "block-secrets",
        "dlp",
        "ingress",
        "soc2"
      ],
      "direction": "ingress",
      "package": "zoom.ingress.block_secrets_chat",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:708b3359e784c995db961d57370b7b74dc426bb1d29c9bfca83c49fef14f885f",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/zoom/block-secrets-chat",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/zoom/block-secrets-chat/policy.md"
    },
    {
      "slug": "box/redact-pii-egress",
      "name": "Box: Redact PII from File Content on Egress",
      "summary": "Scans the responses of Box content-returning tools and rewrites personally identifiable information to fixed redaction tokens before the response reaches the…",
      "url": "https://www.intentbasedpolicy.com/policies/box/redact-pii-egress",
      "markdown": "https://www.intentbasedpolicy.com/policies/box/redact-pii-egress.md",
      "app": "box",
      "apps": [
        "box"
      ],
      "bundles": [
        "soc2",
        "hipaa",
        "gdpr-ccpa"
      ],
      "tags": [
        "box",
        "redact-pii",
        "pii",
        "phi",
        "dlp",
        "redaction",
        "egress",
        "soc2",
        "hipaa",
        "gdpr-ccpa"
      ],
      "direction": "egress",
      "package": "box.egress.redact_pii",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:f54e1078b14091870e8122f18eb5a1938363bca29c5f9999a4c1492e397bf162",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/box/redact-pii-egress",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/box/redact-pii-egress/policy.md"
    },
    {
      "slug": "box/role-gate-writes",
      "name": "Box: Role-Gated Writes (Read-Only Default)",
      "summary": "Makes Box read-only by default on the MCP path.",
      "url": "https://www.intentbasedpolicy.com/policies/box/role-gate-writes",
      "markdown": "https://www.intentbasedpolicy.com/policies/box/role-gate-writes.md",
      "app": "box",
      "apps": [
        "box"
      ],
      "bundles": [
        "soc2",
        "gdpr-ccpa"
      ],
      "tags": [
        "box",
        "role-gate-writes",
        "access-control",
        "least-privilege",
        "ingress",
        "soc2",
        "gdpr-ccpa"
      ],
      "direction": "ingress",
      "package": "box.ingress.role_gate_writes",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:402fdf79b6e7b9fd5df7fe444218b926ed74c5d7c7748b0b41c33c0df2be5d1a",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/box/role-gate-writes",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/box/role-gate-writes/policy.md"
    },
    {
      "slug": "asana/cap-batch-mutation",
      "name": "Cap Asana Batch Task Mutations",
      "summary": "Caps the blast radius of Asana's official V2 batch write tools. At ingress it:",
      "url": "https://www.intentbasedpolicy.com/policies/asana/cap-batch-mutation",
      "markdown": "https://www.intentbasedpolicy.com/policies/asana/cap-batch-mutation.md",
      "app": "asana",
      "apps": [
        "asana"
      ],
      "bundles": [
        "soc2"
      ],
      "tags": [
        "asana",
        "cap-bulk-export",
        "batch-mutation",
        "ingress",
        "soc2"
      ],
      "direction": "ingress",
      "package": "asana.ingress.cap_batch_mutation",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:d4d1d191072dce9a9d61794abb85e2fbe009749d6c44a2629ff577e7b1d62ede",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/asana/cap-batch-mutation",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/asana/cap-batch-mutation/policy.md"
    },
    {
      "slug": "docusign/cap-directory-and-document-egress",
      "name": "Cap Docusign Directory and Document Egress",
      "summary": "Bounds the two largest data-out channels in the Docusign MCP landscape:",
      "url": "https://www.intentbasedpolicy.com/policies/docusign/cap-directory-and-document-egress",
      "markdown": "https://www.intentbasedpolicy.com/policies/docusign/cap-directory-and-document-egress.md",
      "app": "docusign",
      "apps": [
        "docusign"
      ],
      "bundles": [
        "soc2",
        "gdpr-ccpa"
      ],
      "tags": [
        "docusign",
        "cap-bulk-export",
        "pii",
        "data-minimisation",
        "egress",
        "soc2",
        "gdpr-ccpa"
      ],
      "direction": "egress",
      "package": "docusign.egress.cap_directory_and_document_egress",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:5f9241742b7d09b674fee3f7e169acd704a79109b7a06a61d2ac11ab02b2dd8d",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/docusign/cap-directory-and-document-egress",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/docusign/cap-directory-and-document-egress/policy.md"
    },
    {
      "slug": "glean/cap-search-export",
      "name": "Cap Glean Bulk Search Export",
      "summary": "Clamps the bulk-export parameters on Glean search calls before they reach the Glean MCP server, so a single agent request cannot pull an entire indexed…",
      "url": "https://www.intentbasedpolicy.com/policies/glean/cap-search-export",
      "markdown": "https://www.intentbasedpolicy.com/policies/glean/cap-search-export.md",
      "app": "glean",
      "apps": [
        "glean"
      ],
      "bundles": [
        "soc2",
        "hipaa",
        "gdpr-ccpa"
      ],
      "tags": [
        "glean",
        "cap-bulk-export",
        "data-minimisation",
        "ingress",
        "soc2",
        "hipaa",
        "gdpr-ccpa"
      ],
      "direction": "ingress",
      "package": "glean.ingress.cap_search_export",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:bf5ad7f22ab9e693010ae9b6eccb712de9e68d662cb33db57a29d647ba086c7f",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/glean/cap-search-export",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/glean/cap-search-export/policy.md"
    },
    {
      "slug": "google-drive/cap-bulk-export",
      "name": "Cap Google Drive Search & Listing Page Sizes",
      "summary": "Clamps the page size of Google Drive search and listing calls to a documented cap (25 results per call).",
      "url": "https://www.intentbasedpolicy.com/policies/google-drive/cap-bulk-export",
      "markdown": "https://www.intentbasedpolicy.com/policies/google-drive/cap-bulk-export.md",
      "app": "google-drive",
      "apps": [
        "google-drive"
      ],
      "bundles": [
        "soc2",
        "hipaa",
        "gdpr-ccpa"
      ],
      "tags": [
        "google-drive",
        "cap-bulk-export",
        "data-minimization",
        "ingress",
        "soc2",
        "hipaa",
        "gdpr-ccpa"
      ],
      "direction": "ingress",
      "package": "google_drive.ingress.cap_bulk_export",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:2d8f86deafa5b239539f29e322abd233c66f03b1beec1b1ee201ce917f022898",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/google-drive/cap-bulk-export",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/google-drive/cap-bulk-export/policy.md"
    },
    {
      "slug": "intercom/cap-contact-enumeration",
      "name": "Cap Intercom Contact Enumeration",
      "summary": "caller is a CRM admin); clamp page size on everything else; allow the rest",
      "url": "https://www.intentbasedpolicy.com/policies/intercom/cap-contact-enumeration",
      "markdown": "https://www.intentbasedpolicy.com/policies/intercom/cap-contact-enumeration.md",
      "app": "intercom",
      "apps": [
        "intercom"
      ],
      "bundles": [
        "soc2",
        "hipaa",
        "pci-dss",
        "gdpr-ccpa"
      ],
      "tags": [
        "intercom",
        "cap-bulk-export",
        "contact-enumeration",
        "dlp",
        "ingress",
        "soc2",
        "hipaa",
        "pci-dss",
        "gdpr-ccpa"
      ],
      "direction": "ingress",
      "package": "intercom.ingress.cap_contact_enumeration",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:016343b82b92baf587d0e6349c7bd3569ee9fdb63bda2b7e36bc2628d61b3011",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/intercom/cap-contact-enumeration",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/intercom/cap-contact-enumeration/policy.md"
    },
    {
      "slug": "quickbooks/cap-bulk-export",
      "name": "Cap QuickBooks Bulk Search Exports",
      "summary": "Clamps the bulk-read levers on every QuickBooks Online search tool so an agent cannot pull the entire general ledger — or a full customer, vendor, or…",
      "url": "https://www.intentbasedpolicy.com/policies/quickbooks/cap-bulk-export",
      "markdown": "https://www.intentbasedpolicy.com/policies/quickbooks/cap-bulk-export.md",
      "app": "quickbooks",
      "apps": [
        "quickbooks"
      ],
      "bundles": [
        "gdpr-ccpa",
        "pci-dss",
        "soc2"
      ],
      "tags": [
        "quickbooks",
        "cap-bulk-export",
        "bulk-export",
        "dlp",
        "ingress",
        "soc2",
        "pci-dss",
        "gdpr-ccpa"
      ],
      "direction": "ingress",
      "package": "quickbooks.ingress.cap_bulk_export",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:fb6b6ca97595f62307f8d3a606eb375ea5e1a513eab466cf602dfa8a7b90439f",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/quickbooks/cap-bulk-export",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/quickbooks/cap-bulk-export/policy.md"
    },
    {
      "slug": "airtable/cap-bulk-record-reads",
      "name": "Clamp Bulk Airtable Record Reads",
      "summary": "Airtable bases routinely hold CRM contacts, applicant-tracking pipelines, customer/financial trackers, and — on HIPAA-eligible Enterprise plans — health-ops…",
      "url": "https://www.intentbasedpolicy.com/policies/airtable/cap-bulk-record-reads",
      "markdown": "https://www.intentbasedpolicy.com/policies/airtable/cap-bulk-record-reads.md",
      "app": "airtable",
      "apps": [
        "airtable"
      ],
      "bundles": [
        "soc2",
        "gdpr-ccpa"
      ],
      "tags": [
        "airtable",
        "cap-bulk-export",
        "ingress",
        "soc2",
        "gdpr-ccpa"
      ],
      "direction": "ingress",
      "package": "airtable.ingress.cap_bulk_record_reads",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:c2d3a53a5918a4cbec88c745c7bc69f8267688cd5d4920fd002afba346b4de86",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/airtable/cap-bulk-record-reads",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/airtable/cap-bulk-record-reads/policy.md"
    },
    {
      "slug": "airtable/fence-base-allowlist",
      "name": "Confine Airtable Agent to Allowlisted Bases",
      "summary": "An Airtable OAuth grant (or Personal Access Token) with the workspacesAndBases:read scope spans the entire workspace — every base the connected identity can…",
      "url": "https://www.intentbasedpolicy.com/policies/airtable/fence-base-allowlist",
      "markdown": "https://www.intentbasedpolicy.com/policies/airtable/fence-base-allowlist.md",
      "app": "airtable",
      "apps": [
        "airtable"
      ],
      "bundles": [
        "soc2",
        "gdpr-ccpa"
      ],
      "tags": [
        "airtable",
        "fence-sensitive-scopes",
        "ingress",
        "soc2",
        "gdpr-ccpa"
      ],
      "direction": "ingress",
      "package": "airtable.ingress.fence_base_allowlist",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:438d1a0b4a73d17af63a9d381d7d6eee643181e6ec9401461475e8f17fec9ed1",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/airtable/fence-base-allowlist",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/airtable/fence-base-allowlist/policy.md"
    },
    {
      "slug": "confluence/deny-public-publication",
      "name": "Confluence: Deny Org-Wide & Public Publication",
      "summary": "Stops a prompt-injected or erring agent from broadcasting Confluence content org-wide or to anonymous external readers.",
      "url": "https://www.intentbasedpolicy.com/policies/confluence/deny-public-publication",
      "markdown": "https://www.intentbasedpolicy.com/policies/confluence/deny-public-publication.md",
      "app": "confluence",
      "apps": [
        "confluence"
      ],
      "bundles": [
        "atlassian",
        "soc2",
        "gdpr-ccpa"
      ],
      "tags": [
        "confluence",
        "atlassian",
        "deny-public-exposure",
        "publication",
        "governance",
        "ingress",
        "finserv-comms",
        "eu-ai-act",
        "soc2",
        "gdpr-ccpa"
      ],
      "direction": "ingress",
      "package": "confluence.ingress.deny_public_publication",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:3addcf2a044394ddb4a6dcf6d1780d63f7372741ddcaa3ebc337fc076dc54854",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/confluence/deny-public-publication",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/confluence/deny-public-publication/policy.md"
    },
    {
      "slug": "confluence/freeze-page-deletion",
      "name": "Confluence: Freeze Page & Attachment Deletion",
      "summary": "Freezes the two irreversible Confluence deletion tools on the agent channel: confluence delete page and confluence delete attachment.",
      "url": "https://www.intentbasedpolicy.com/policies/confluence/freeze-page-deletion",
      "markdown": "https://www.intentbasedpolicy.com/policies/confluence/freeze-page-deletion.md",
      "app": "confluence",
      "apps": [
        "confluence"
      ],
      "bundles": [
        "atlassian",
        "soc2"
      ],
      "tags": [
        "confluence",
        "atlassian",
        "freeze-destructive-ops",
        "data-protection",
        "ingress",
        "soc2"
      ],
      "direction": "ingress",
      "package": "confluence.ingress.freeze_page_deletion",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:83c0636b7f0f1496216dd9220e12e0da1a8cd91cfb4875d981cd911d0ab97483",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/confluence/freeze-page-deletion",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/confluence/freeze-page-deletion/policy.md"
    },
    {
      "slug": "confluence/redact-pii-egress",
      "name": "Confluence: Redact PII from Page & Comment Responses",
      "summary": "Scans the responses of Confluence page, comment, and search read tools and rewrites personally identifiable information to fixed redaction tokens before the…",
      "url": "https://www.intentbasedpolicy.com/policies/confluence/redact-pii-egress",
      "markdown": "https://www.intentbasedpolicy.com/policies/confluence/redact-pii-egress.md",
      "app": "confluence",
      "apps": [
        "confluence"
      ],
      "bundles": [
        "soc2",
        "hipaa",
        "gdpr-ccpa",
        "atlassian"
      ],
      "tags": [
        "confluence",
        "atlassian",
        "redact-pii",
        "pii",
        "dlp",
        "redaction",
        "egress",
        "soc2",
        "hipaa",
        "gdpr-ccpa"
      ],
      "direction": "egress",
      "package": "confluence.egress.redact_pii",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:4b43eed8bc31dc7944a396b08690bd7bb5ad22d3097aed5f98474970ac657353",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/confluence/redact-pii-egress",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/confluence/redact-pii-egress/policy.md"
    },
    {
      "slug": "notion/constrain-connected-search",
      "name": "Constrain Notion Connected-Tool Search",
      "summary": "Notion's hosted MCP server (notion-search) does not just search Notion pages — through Notion AI connectors it also searches connected Slack, Google Drive,…",
      "url": "https://www.intentbasedpolicy.com/policies/notion/constrain-connected-search",
      "markdown": "https://www.intentbasedpolicy.com/policies/notion/constrain-connected-search.md",
      "app": "notion",
      "apps": [
        "notion"
      ],
      "bundles": [
        "soc2"
      ],
      "tags": [
        "notion",
        "constrain-aggregator",
        "ingress",
        "soc2"
      ],
      "direction": "ingress",
      "package": "notion.ingress.constrain_connected_search",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:34cb0cc763d763e7b091bfe7ef6ef636d2e14f7bb0fb877f135449f039817008",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/notion/constrain-connected-search",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/notion/constrain-connected-search/policy.md"
    },
    {
      "slug": "databricks/default-deny-unknown-tools",
      "name": "Databricks Default-Deny Unknown Tools",
      "summary": "Pins an allowlist of the exact Databricks tool names your team audited and denies every other tool name on the Databricks MCP server(s).",
      "url": "https://www.intentbasedpolicy.com/policies/databricks/default-deny-unknown-tools",
      "markdown": "https://www.intentbasedpolicy.com/policies/databricks/default-deny-unknown-tools.md",
      "app": "databricks",
      "apps": [
        "databricks"
      ],
      "bundles": [
        "soc2"
      ],
      "tags": [
        "databricks",
        "default-deny-unknown-tools",
        "allowlist",
        "access-control",
        "ingress",
        "soc2"
      ],
      "direction": "ingress",
      "package": "databricks.ingress.default_deny_unknown_tools",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:be4a48dc04ce574ccac8aac24e4ce41eba78df4e1648945fb314e3e746613180",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/databricks/default-deny-unknown-tools",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/databricks/default-deny-unknown-tools/policy.md"
    },
    {
      "slug": "databricks/mask-pan-egress",
      "name": "Databricks: Mask Cardholder PANs in Responses",
      "summary": "Masks payment-card numbers (PANs) in Databricks tool responses before the agent receives them.",
      "url": "https://www.intentbasedpolicy.com/policies/databricks/mask-pan-egress",
      "markdown": "https://www.intentbasedpolicy.com/policies/databricks/mask-pan-egress.md",
      "app": "databricks",
      "apps": [
        "databricks"
      ],
      "bundles": [
        "soc2",
        "pci-dss",
        "gdpr-ccpa"
      ],
      "tags": [
        "databricks",
        "mask-pan-egress",
        "egress",
        "cardholder-data",
        "dlp",
        "soc2",
        "pci-dss",
        "gdpr-ccpa"
      ],
      "direction": "egress",
      "package": "databricks.egress.mask_pan",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:f8e407d8c4ae888c9c851d437908c11cf66273de062d654f84459dbab81fa0a1",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/databricks/mask-pan-egress",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/databricks/mask-pan-egress/policy.md"
    },
    {
      "slug": "databricks/redact-pii-egress",
      "name": "Databricks: Redact PII in Tool Responses",
      "summary": "Scans the response payloads of the Databricks MCP tools that carry lakehouse data back to the agent and rewrites personally identifiable information to fixed…",
      "url": "https://www.intentbasedpolicy.com/policies/databricks/redact-pii-egress",
      "markdown": "https://www.intentbasedpolicy.com/policies/databricks/redact-pii-egress.md",
      "app": "databricks",
      "apps": [
        "databricks"
      ],
      "bundles": [
        "soc2",
        "hipaa",
        "gdpr-ccpa"
      ],
      "tags": [
        "databricks",
        "redact-pii",
        "pii",
        "dlp",
        "redaction",
        "egress",
        "soc2",
        "hipaa",
        "gdpr-ccpa"
      ],
      "direction": "egress",
      "package": "databricks.egress.redact_pii",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:fb121d2c224503786e3949536e21af59d24989d1ee5c29c655a2e4b4d1d48b8f",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/databricks/redact-pii-egress",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/databricks/redact-pii-egress/policy.md"
    },
    {
      "slug": "databricks/role-gate-compute-ops",
      "name": "Databricks: Role-Gate Compute & Job Control",
      "summary": "The community JustTryAI/databricks-mcp-server exposes cluster and job control — create cluster, start cluster, terminate cluster, run job, and export…",
      "url": "https://www.intentbasedpolicy.com/policies/databricks/role-gate-compute-ops",
      "markdown": "https://www.intentbasedpolicy.com/policies/databricks/role-gate-compute-ops.md",
      "app": "databricks",
      "apps": [
        "databricks"
      ],
      "bundles": [
        "soc2"
      ],
      "tags": [
        "databricks",
        "role-gate-writes",
        "access-control",
        "least-privilege",
        "ingress",
        "soc2"
      ],
      "direction": "ingress",
      "package": "databricks.ingress.role_gate_compute_ops",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:dac0eee89cff61994486275bafe6192f87bc3dd58d9ef5fc36f6a2242a2f6970",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/databricks/role-gate-compute-ops",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/databricks/role-gate-compute-ops/policy.md"
    },
    {
      "slug": "airtable/default-deny-unknown-tools",
      "name": "Default-Deny Unaudited Airtable Tools",
      "summary": "Maintains a per-tenant allowlist of audited Airtable tool-name suffixes and denies any call whose tool name does not end with an allowlisted entry.",
      "url": "https://www.intentbasedpolicy.com/policies/airtable/default-deny-unknown-tools",
      "markdown": "https://www.intentbasedpolicy.com/policies/airtable/default-deny-unknown-tools.md",
      "app": "airtable",
      "apps": [
        "airtable"
      ],
      "bundles": [
        "soc2"
      ],
      "tags": [
        "airtable",
        "default-deny-unknown-tools",
        "allowlist",
        "ingress",
        "soc2"
      ],
      "direction": "ingress",
      "package": "airtable.ingress.default_deny_unknown_tools",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:3ffaade35ac5b90afb59c43af5f65415acdf63f1d13f6ec07f7acbcad093c930",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/airtable/default-deny-unknown-tools",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/airtable/default-deny-unknown-tools/policy.md"
    },
    {
      "slug": "bigquery/default-deny-unknown-tools",
      "name": "Default-Deny Unaudited BigQuery Tools",
      "summary": "Maintains a per-tenant allowlist of audited BigQuery tool-name suffixes and denies any call whose tool name does not end with an allowlisted entry.",
      "url": "https://www.intentbasedpolicy.com/policies/bigquery/default-deny-unknown-tools",
      "markdown": "https://www.intentbasedpolicy.com/policies/bigquery/default-deny-unknown-tools.md",
      "app": "bigquery",
      "apps": [
        "bigquery"
      ],
      "bundles": [
        "soc2"
      ],
      "tags": [
        "bigquery",
        "default-deny-unknown-tools",
        "allowlist",
        "access-control",
        "ingress",
        "soc2"
      ],
      "direction": "ingress",
      "package": "bigquery.ingress.default_deny_unknown_tools",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:aef34bbc36a8c0e81ccb0db6330227cd64a1d8a47e0e9c28a9b4e98ef953376c",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/bigquery/default-deny-unknown-tools",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/bigquery/default-deny-unknown-tools/policy.md"
    },
    {
      "slug": "gusto/default-deny-unknown-tools",
      "name": "Default-Deny Unknown Gusto Tools",
      "summary": "Pins an allowlist of the 36 official Gusto MCP tool names and allows a call only when lower(input.resource.name) is an exact member of that list.",
      "url": "https://www.intentbasedpolicy.com/policies/gusto/default-deny-unknown-tools",
      "markdown": "https://www.intentbasedpolicy.com/policies/gusto/default-deny-unknown-tools.md",
      "app": "gusto",
      "apps": [
        "gusto"
      ],
      "bundles": [
        "soc2"
      ],
      "tags": [
        "gusto",
        "default-deny-unknown-tools",
        "allowlist",
        "ingress",
        "soc2"
      ],
      "direction": "ingress",
      "package": "gusto.ingress.default_deny_unknown_tools",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:1d7fc4bf42a67a650492b106de740d6052325739bdd9dc229de035ba47b65edf",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/gusto/default-deny-unknown-tools",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/gusto/default-deny-unknown-tools/policy.md"
    },
    {
      "slug": "linear/default-deny-unknown-tools",
      "name": "Default-Deny Unknown Linear Tools",
      "summary": "Pins an audited allowlist of the verified official Linear MCP tool names and allows a call only when the incoming tool name matches an allowlisted name on…",
      "url": "https://www.intentbasedpolicy.com/policies/linear/default-deny-unknown-tools",
      "markdown": "https://www.intentbasedpolicy.com/policies/linear/default-deny-unknown-tools.md",
      "app": "linear",
      "apps": [
        "linear"
      ],
      "bundles": [
        "soc2"
      ],
      "tags": [
        "linear",
        "default-deny-unknown-tools",
        "allowlist",
        "ingress",
        "soc2"
      ],
      "direction": "ingress",
      "package": "linear.ingress.default_deny_unknown_tools",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:66b2ad9c93a88aa0b0b48fbf41884f7be82b8cb212b328c3a95ad7c19e079460",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/linear/default-deny-unknown-tools",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/linear/default-deny-unknown-tools/policy.md"
    },
    {
      "slug": "monday/default-deny-unknown-tools",
      "name": "Default-Deny Unknown monday Tools",
      "summary": "Maintains a per-tenant allowlist of audited monday tool-name suffixes and denies any call whose tool name does not end with an allowlisted entry.",
      "url": "https://www.intentbasedpolicy.com/policies/monday/default-deny-unknown-tools",
      "markdown": "https://www.intentbasedpolicy.com/policies/monday/default-deny-unknown-tools.md",
      "app": "monday",
      "apps": [
        "monday"
      ],
      "bundles": [
        "soc2"
      ],
      "tags": [
        "monday",
        "default-deny-unknown-tools",
        "allowlist",
        "ingress",
        "soc2"
      ],
      "direction": "ingress",
      "package": "monday.ingress.default_deny_unknown_tools",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:d81946e7b7d1070679b2c936e47a809f74d8e2c60c62a3c543242b01d4a73ab0",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/monday/default-deny-unknown-tools",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/monday/default-deny-unknown-tools/policy.md"
    },
    {
      "slug": "power-bi/default-deny-unknown-modeling-ops",
      "name": "Default-Deny Unknown Power BI Modeling Tools",
      "summary": "Pins a per-tenant allowlist of audited Power BI tool-name suffixes and denies any call whose tool name does not end with an allowlisted entry.",
      "url": "https://www.intentbasedpolicy.com/policies/power-bi/default-deny-unknown-modeling-ops",
      "markdown": "https://www.intentbasedpolicy.com/policies/power-bi/default-deny-unknown-modeling-ops.md",
      "app": "power-bi",
      "apps": [
        "power-bi"
      ],
      "bundles": [
        "soc2"
      ],
      "tags": [
        "power-bi",
        "default-deny-unknown-tools",
        "allowlist",
        "modeling",
        "ingress",
        "soc2"
      ],
      "direction": "ingress",
      "package": "power_bi.ingress.default_deny_unknown_modeling_ops",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:ca1ad268d9225a10f6a87db32915623b9178fb4830f1618d4d84ab088b94f605",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/power-bi/default-deny-unknown-modeling-ops",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/power-bi/default-deny-unknown-modeling-ops/policy.md"
    },
    {
      "slug": "servicenow/default-deny-unknown-tools",
      "name": "Default-Deny Unknown ServiceNow Tools",
      "summary": "Maintains an allowlist of audited ServiceNow tool-name suffixes and denies any tool call whose name does not match an allowlisted entry.",
      "url": "https://www.intentbasedpolicy.com/policies/servicenow/default-deny-unknown-tools",
      "markdown": "https://www.intentbasedpolicy.com/policies/servicenow/default-deny-unknown-tools.md",
      "app": "servicenow",
      "apps": [
        "servicenow"
      ],
      "bundles": [
        "soc2"
      ],
      "tags": [
        "servicenow",
        "default-deny-unknown-tools",
        "allowlist",
        "ingress",
        "soc2"
      ],
      "direction": "ingress",
      "package": "servicenow.ingress.default_deny_unknown_tools",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:3970ae20d9456cf0a30476cdf4e857bc00733c423045129151cbcdd18e693ead",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/servicenow/default-deny-unknown-tools",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/servicenow/default-deny-unknown-tools/policy.md"
    },
    {
      "slug": "tableau/default-deny-unknown-tools",
      "name": "Default-Deny Unknown Tableau Tools",
      "summary": "Fails closed on tool drift. The policy carries a pinned allowlist of the 39 tools in the verified official Tableau web toolset (tableau/tableau-mcp v2.24.",
      "url": "https://www.intentbasedpolicy.com/policies/tableau/default-deny-unknown-tools",
      "markdown": "https://www.intentbasedpolicy.com/policies/tableau/default-deny-unknown-tools.md",
      "app": "tableau",
      "apps": [
        "tableau"
      ],
      "bundles": [
        "soc2"
      ],
      "tags": [
        "tableau",
        "default-deny",
        "unknown-tools",
        "allowlist",
        "ingress",
        "soc2"
      ],
      "direction": "ingress",
      "package": "tableau.ingress.default_deny_unknown_tools",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:6b9d333dc2593955153061b79c78472e08986cbcb9bf30cb2f7c26453d7c047d",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/tableau/default-deny-unknown-tools",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/tableau/default-deny-unknown-tools/policy.md"
    },
    {
      "slug": "zapier/default-deny-unknown-tools",
      "name": "Default-Deny Unknown Zapier Tools",
      "summary": "Maintains an allowlist of audited Zapier tool-name suffixes and denies any tool call whose name does not match an allowlisted entry, with an alert-worthy…",
      "url": "https://www.intentbasedpolicy.com/policies/zapier/default-deny-unknown-tools",
      "markdown": "https://www.intentbasedpolicy.com/policies/zapier/default-deny-unknown-tools.md",
      "app": "zapier",
      "apps": [
        "zapier"
      ],
      "bundles": [
        "soc2"
      ],
      "tags": [
        "zapier",
        "default-deny-unknown-tools",
        "allowlist",
        "ingress",
        "soc2"
      ],
      "direction": "ingress",
      "package": "zapier.ingress.default_deny_unknown_tools",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:02eac99cb206dca8825fa27847b1bc7ec63475983995675b08e593b2a6d74b17",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/zapier/default-deny-unknown-tools",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/zapier/default-deny-unknown-tools/policy.md"
    },
    {
      "slug": "gmail/guard-external-send",
      "name": "Deny Agent Email Sends to External Recipients",
      "summary": "Denies Gmail send-class tool calls when any recipient in to, cc, or bcc falls outside a documented corporate-domain allowlist.",
      "url": "https://www.intentbasedpolicy.com/policies/gmail/guard-external-send",
      "markdown": "https://www.intentbasedpolicy.com/policies/gmail/guard-external-send.md",
      "app": "gmail",
      "apps": [
        "gmail"
      ],
      "bundles": [
        "soc2",
        "hipaa",
        "gdpr-ccpa"
      ],
      "tags": [
        "gmail",
        "guard-external-send",
        "ingress",
        "email",
        "soc2",
        "hipaa",
        "gdpr-ccpa"
      ],
      "direction": "ingress",
      "package": "gmail.ingress.guard_external_send",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:a356452d11eebac588da98a69bdd3b885549b7eedbb466b2b9042b4b0a54e7e7",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/gmail/guard-external-send",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/gmail/guard-external-send/policy.md"
    },
    {
      "slug": "onboarding/deny-email",
      "name": "Deny Email PII",
      "summary": "This policy stops a request if it contains an email address. If there's no email address, the request goes through as normal.",
      "url": "https://www.intentbasedpolicy.com/policies/onboarding/deny-email",
      "markdown": "https://www.intentbasedpolicy.com/policies/onboarding/deny-email.md",
      "app": "onboarding",
      "apps": [
        "onboarding"
      ],
      "bundles": [],
      "tags": [
        "onboarding",
        "pii",
        "email",
        "dlp",
        "ingress"
      ],
      "direction": "ingress",
      "package": "onboarding.ingress.deny_email",
      "publishedAt": "2026-07-23",
      "policyChecksum": "sha256:777822968820adb4c61b12eb3c3410bc53bb7c6dd20f98d58687098b53b00920",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/onboarding/deny-email",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/onboarding/deny-email/policy.md"
    },
    {
      "slug": "ms365/deny-graph-batch",
      "name": "Deny Graph API Batch Escape Hatch",
      "summary": "Blocks the Microsoft 365 MCP server's raw-Graph passthrough tool (graph-batch, observed live as ms365-graph-batch).",
      "url": "https://www.intentbasedpolicy.com/policies/ms365/deny-graph-batch",
      "markdown": "https://www.intentbasedpolicy.com/policies/ms365/deny-graph-batch.md",
      "app": "ms365",
      "apps": [
        "ms365"
      ],
      "bundles": [
        "soc2"
      ],
      "tags": [
        "ms365",
        "deny-escape-hatches",
        "ingress",
        "iso27001-nist",
        "soc2"
      ],
      "direction": "ingress",
      "package": "ms365.ingress.deny_graph_batch",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:60581380494d453348b5b7bc0fbfc906a57aac7ffd645a80a6e5c4f8f4df1ba7",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/ms365/deny-graph-batch",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/ms365/deny-graph-batch/policy.md"
    },
    {
      "slug": "stripe/deny-escape-hatches-api-write",
      "name": "Deny Stripe API-Write Escape Hatch",
      "summary": "Denies the stripe api write meta-tool — the single raw passthrough on the official Stripe MCP server that can execute any Stripe POST, PATCH, PUT, or DELETE…",
      "url": "https://www.intentbasedpolicy.com/policies/stripe/deny-escape-hatches-api-write",
      "markdown": "https://www.intentbasedpolicy.com/policies/stripe/deny-escape-hatches-api-write.md",
      "app": "stripe",
      "apps": [
        "stripe"
      ],
      "bundles": [
        "sox",
        "soc2"
      ],
      "tags": [
        "stripe",
        "deny-escape-hatches",
        "ingress",
        "sox",
        "soc2"
      ],
      "direction": "ingress",
      "package": "stripe.ingress.deny_escape_hatches_api_write",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:d3c004edbb6c5f65a9f8185b2372061a12e018d9d1340d79663eb5539eecfa37",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/stripe/deny-escape-hatches-api-write",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/stripe/deny-escape-hatches-api-write/policy.md"
    },
    {
      "slug": "onboarding/detect-email-allow",
      "name": "Detect Email PII (Allow with Reason)",
      "summary": "A watch-only starter policy.",
      "url": "https://www.intentbasedpolicy.com/policies/onboarding/detect-email-allow",
      "markdown": "https://www.intentbasedpolicy.com/policies/onboarding/detect-email-allow.md",
      "app": "onboarding",
      "apps": [
        "onboarding"
      ],
      "bundles": [],
      "tags": [
        "onboarding",
        "pii",
        "email",
        "observability",
        "ingress"
      ],
      "direction": "ingress",
      "package": "onboarding.ingress.detect_email_allow",
      "publishedAt": "2026-07-23",
      "policyChecksum": "sha256:0df1b62128aadb82c9491c6fa8ce4776640b586a4cc4bf001240291b271b8617",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/onboarding/detect-email-allow",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/onboarding/detect-email-allow/policy.md"
    },
    {
      "slug": "docusign/redact-tab-values-egress",
      "name": "Docusign: Redact SSN, Bank & Card Values on Egress",
      "summary": "Scans the responses of Docusign envelope- and agreement-reading tools and rewrites high-confidence regulated identifiers before the response reaches the…",
      "url": "https://www.intentbasedpolicy.com/policies/docusign/redact-tab-values-egress",
      "markdown": "https://www.intentbasedpolicy.com/policies/docusign/redact-tab-values-egress.md",
      "app": "docusign",
      "apps": [
        "docusign"
      ],
      "bundles": [
        "soc2",
        "gdpr-ccpa"
      ],
      "tags": [
        "docusign",
        "redact-pii",
        "tab-values",
        "pii",
        "phi",
        "pan",
        "dlp",
        "redaction",
        "egress",
        "soc2",
        "gdpr-ccpa"
      ],
      "direction": "egress",
      "package": "docusign.egress.redact_tab_values",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:9df5248637c826c1335c9cdf8cbefae6a1561267fc48d8bb021fd52f6705d308",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/docusign/redact-tab-values-egress",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/docusign/redact-tab-values-egress/policy.md"
    },
    {
      "slug": "dropbox/redact-content-egress",
      "name": "Dropbox: Redact PII, PANs, and Secrets in File Content",
      "summary": "Scans the responses of the Dropbox file-content read tools and sanitises the returned text before it reaches the agent.",
      "url": "https://www.intentbasedpolicy.com/policies/dropbox/redact-content-egress",
      "markdown": "https://www.intentbasedpolicy.com/policies/dropbox/redact-content-egress.md",
      "app": "dropbox",
      "apps": [
        "dropbox"
      ],
      "bundles": [
        "soc2",
        "hipaa",
        "gdpr-ccpa"
      ],
      "tags": [
        "dropbox",
        "redact-content",
        "redact-pii",
        "mask-pan",
        "secrets",
        "pii",
        "dlp",
        "egress",
        "soc2",
        "hipaa",
        "gdpr-ccpa"
      ],
      "direction": "egress",
      "package": "dropbox.egress.redact_content",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:e86d5f2ee35b2f0cf9f6d0007eaf5321382ffe11416010e5461ee4250b25f36c",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/dropbox/redact-content-egress",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/dropbox/redact-content-egress/policy.md"
    },
    {
      "slug": "confluence/fence-restricted-spaces",
      "name": "Fence Confluence Reads & Search to Non-Restricted Spaces",
      "summary": "Fences a configurable set of restricted Confluence spaces (placeholder keys: HR, LEGAL, SEC) out of the agent's read and search paths unless the caller's IdP…",
      "url": "https://www.intentbasedpolicy.com/policies/confluence/fence-restricted-spaces",
      "markdown": "https://www.intentbasedpolicy.com/policies/confluence/fence-restricted-spaces.md",
      "app": "confluence",
      "apps": [
        "confluence"
      ],
      "bundles": [
        "atlassian",
        "soc2",
        "hipaa",
        "gdpr-ccpa"
      ],
      "tags": [
        "confluence",
        "atlassian",
        "fence-sensitive-scopes",
        "access-control",
        "ingress",
        "soc2",
        "hipaa",
        "gdpr-ccpa"
      ],
      "direction": "ingress",
      "package": "confluence.ingress.fence_restricted_spaces",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:63b7c426b63cf3c02a2057d9ebfab515c3f0e4b19c1832dc5059dd535933336c",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/confluence/fence-restricted-spaces",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/confluence/fence-restricted-spaces/policy.md"
    },
    {
      "slug": "github/fence-scopes-org-allowlist",
      "name": "Fence GitHub Access to the Company Org Allowlist",
      "summary": "Denies any GitHub tool call whose arguments.owner (read from input.payload.args.",
      "url": "https://www.intentbasedpolicy.com/policies/github/fence-scopes-org-allowlist",
      "markdown": "https://www.intentbasedpolicy.com/policies/github/fence-scopes-org-allowlist.md",
      "app": "github",
      "apps": [
        "github"
      ],
      "bundles": [
        "soc2"
      ],
      "tags": [
        "github",
        "fence-sensitive-scopes",
        "org-allowlist",
        "anti-exfil",
        "ingress",
        "soc2"
      ],
      "direction": "ingress",
      "package": "github.ingress.fence_scopes_org_allowlist",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:53fe009c913de7ae748645f9646b4cd71ce0970e35b81d5e4869dbd3537adc8f",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/github/fence-scopes-org-allowlist",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/github/fence-scopes-org-allowlist/policy.md"
    },
    {
      "slug": "glean/fence-datasource-scope",
      "name": "Fence Glean Search by Datasource",
      "summary": "Glean's search tool fans out across every system the tenant has indexed (Drive, Confluence, Slack, Jira, Gmail/Outlook, GitHub, Salesforce, Gong, HR…",
      "url": "https://www.intentbasedpolicy.com/policies/glean/fence-datasource-scope",
      "markdown": "https://www.intentbasedpolicy.com/policies/glean/fence-datasource-scope.md",
      "app": "glean",
      "apps": [
        "glean"
      ],
      "bundles": [
        "soc2",
        "hipaa",
        "gdpr-ccpa"
      ],
      "tags": [
        "glean",
        "fence-sensitive-scopes",
        "access-control",
        "datasource",
        "ingress",
        "soc2",
        "hipaa",
        "gdpr-ccpa"
      ],
      "direction": "ingress",
      "package": "glean.ingress.fence_datasource_scope",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:56e26218fcc730dcdd015c7e265a776ac7e01c2402521fae5498858ae798f324",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/glean/fence-datasource-scope",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/glean/fence-datasource-scope/policy.md"
    },
    {
      "slug": "gusto/fence-comp-payroll-reads",
      "name": "Fence Gusto Compensation & Payroll Reads",
      "summary": "Denies the highest-sensitivity Gusto read tools unless the caller's IdP-asserted groups include the placeholder group hr-payroll-admins.",
      "url": "https://www.intentbasedpolicy.com/policies/gusto/fence-comp-payroll-reads",
      "markdown": "https://www.intentbasedpolicy.com/policies/gusto/fence-comp-payroll-reads.md",
      "app": "gusto",
      "apps": [
        "gusto"
      ],
      "bundles": [
        "soc2",
        "gdpr-ccpa"
      ],
      "tags": [
        "gusto",
        "fence-hr-and-credit-scope",
        "compensation",
        "payroll",
        "ingress",
        "soc2",
        "gdpr-ccpa"
      ],
      "direction": "ingress",
      "package": "gusto.ingress.fence_comp_payroll_reads",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:15b4ad1bf1691934b530ae03c487d30184ab33c358353263ea6ba1de5b8cb42b",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/gusto/fence-comp-payroll-reads",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/gusto/fence-comp-payroll-reads/policy.md"
    },
    {
      "slug": "intercom/fence-contact-reads",
      "name": "Fence Intercom Contact & Company PII Reads",
      "summary": "Gates Intercom's structured-PII read surface — customer contact and company profiles — by IdP group.",
      "url": "https://www.intentbasedpolicy.com/policies/intercom/fence-contact-reads",
      "markdown": "https://www.intentbasedpolicy.com/policies/intercom/fence-contact-reads.md",
      "app": "intercom",
      "apps": [
        "intercom"
      ],
      "bundles": [
        "soc2",
        "hipaa",
        "pci-dss",
        "gdpr-ccpa"
      ],
      "tags": [
        "intercom",
        "fence-sensitive-scopes",
        "contact-reads",
        "pii",
        "ingress",
        "soc2",
        "hipaa",
        "pci-dss",
        "gdpr-ccpa"
      ],
      "direction": "ingress",
      "package": "intercom.ingress.fence_contact_reads",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:2691fff943eb843adf41276189cd90320e860f1c50805cf78886ae2ee0d91de2",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/intercom/fence-contact-reads",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/intercom/fence-contact-reads/policy.md"
    },
    {
      "slug": "netsuite/fence-hr-payroll-suiteql",
      "name": "Fence NetSuite HR & Payroll SuiteQL Queries",
      "summary": "Fences the single biggest exfiltration surface on the NetSuite MCP server — ns runCustomSuiteQL, which runs arbitrary read-only SuiteQL across the entire ERP.",
      "url": "https://www.intentbasedpolicy.com/policies/netsuite/fence-hr-payroll-suiteql",
      "markdown": "https://www.intentbasedpolicy.com/policies/netsuite/fence-hr-payroll-suiteql.md",
      "app": "netsuite",
      "apps": [
        "netsuite"
      ],
      "bundles": [
        "gdpr-ccpa",
        "soc2"
      ],
      "tags": [
        "netsuite",
        "fence-sensitive-scopes",
        "ingress",
        "gdpr-ccpa",
        "soc2"
      ],
      "direction": "ingress",
      "package": "netsuite.ingress.fence_hr_payroll_suiteql",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:007249f4eecebe8e735dd94ef81bc625746a2284006d149c5fce2ad52668ba18",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/netsuite/fence-hr-payroll-suiteql",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/netsuite/fence-hr-payroll-suiteql/policy.md"
    },
    {
      "slug": "notion/fence-user-directory",
      "name": "Fence Notion Member Directory to Admin & IT",
      "summary": "Denies calls to the Notion member-directory tool (notion-get-users, matched by the -get-users suffix) unless the caller's IdP groups include an admin or IT…",
      "url": "https://www.intentbasedpolicy.com/policies/notion/fence-user-directory",
      "markdown": "https://www.intentbasedpolicy.com/policies/notion/fence-user-directory.md",
      "app": "notion",
      "apps": [
        "notion"
      ],
      "bundles": [
        "soc2",
        "gdpr-ccpa"
      ],
      "tags": [
        "notion",
        "fence-sensitive-scopes",
        "access-control",
        "pii",
        "ingress",
        "soc2",
        "gdpr-ccpa"
      ],
      "direction": "ingress",
      "package": "notion.ingress.fence_user_directory",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:0a24942610fbfc2b00265763d9a15cac12f37f7d97c999c485eb44dd690a26e9",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/notion/fence-user-directory",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/notion/fence-user-directory/policy.md"
    },
    {
      "slug": "bigquery/fence-sensitive-datasets",
      "name": "Fence Regulated BigQuery Datasets by Group",
      "summary": "Fences customer-designated regulated BigQuery data domains by data-domain IdP group, at ingress, before any statement or metadata lookup reaches BigQuery.",
      "url": "https://www.intentbasedpolicy.com/policies/bigquery/fence-sensitive-datasets",
      "markdown": "https://www.intentbasedpolicy.com/policies/bigquery/fence-sensitive-datasets.md",
      "app": "bigquery",
      "apps": [
        "bigquery"
      ],
      "bundles": [
        "soc2",
        "hipaa",
        "pci-dss",
        "gdpr-ccpa"
      ],
      "tags": [
        "bigquery",
        "fence-sensitive-scopes",
        "ingress",
        "rbac",
        "soc2",
        "hipaa",
        "pci-dss",
        "gdpr-ccpa"
      ],
      "direction": "ingress",
      "package": "bigquery.ingress.fence_sensitive_datasets",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:5b131ef35203846caed781b9046d6b3969d0eae2f827cc7d4a8377cb16ba6102",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/bigquery/fence-sensitive-datasets",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/bigquery/fence-sensitive-datasets/policy.md"
    },
    {
      "slug": "google-drive/fence-restricted-folders",
      "name": "Fence Restricted Google Drive Files and Folders",
      "summary": "Fences an admin-maintained denylist of restricted Google Drive file and folder IDs — HR records, M&A deal rooms, board packs, payroll — off the agent channel:",
      "url": "https://www.intentbasedpolicy.com/policies/google-drive/fence-restricted-folders",
      "markdown": "https://www.intentbasedpolicy.com/policies/google-drive/fence-restricted-folders.md",
      "app": "google-drive",
      "apps": [
        "google-drive"
      ],
      "bundles": [
        "soc2",
        "hipaa",
        "gdpr-ccpa"
      ],
      "tags": [
        "google-drive",
        "fence-restricted-folders",
        "sensitive-scopes",
        "ingress",
        "soc2",
        "hipaa",
        "gdpr-ccpa"
      ],
      "direction": "ingress",
      "package": "google_drive.ingress.fence_restricted_folders",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:fbe9d6f0bb2f15c7bf81156fbc616118ed8c26dec68112b35f239220829040d4",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/google-drive/fence-restricted-folders",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/google-drive/fence-restricted-folders/policy.md"
    },
    {
      "slug": "linear/fence-roadmap-egress",
      "name": "Fence Roadmap and Initiative Reads (Egress)",
      "summary": "Fences the responses of Linear's roadmap, initiative, and strategy read tools.",
      "url": "https://www.intentbasedpolicy.com/policies/linear/fence-roadmap-egress",
      "markdown": "https://www.intentbasedpolicy.com/policies/linear/fence-roadmap-egress.md",
      "app": "linear",
      "apps": [
        "linear"
      ],
      "bundles": [
        "soc2"
      ],
      "tags": [
        "linear",
        "fence-sensitive-scopes",
        "roadmap",
        "egress",
        "soc2"
      ],
      "direction": "egress",
      "package": "linear.egress.fence_roadmap",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:9b1dd6be93d618079dc1bb1e167f2deafc4e08c2fc0ed3b9593b1d82d47d45e0",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/linear/fence-roadmap-egress",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/linear/fence-roadmap-egress/policy.md"
    },
    {
      "slug": "box/fence-sensitive-folders",
      "name": "Fence Sensitive Box Folders by IdP Group",
      "summary": "Fences pinned sensitive Box subtrees (HR, Finance, Legal, …) by ID.",
      "url": "https://www.intentbasedpolicy.com/policies/box/fence-sensitive-folders",
      "markdown": "https://www.intentbasedpolicy.com/policies/box/fence-sensitive-folders.md",
      "app": "box",
      "apps": [
        "box"
      ],
      "bundles": [
        "soc2",
        "hipaa",
        "gdpr-ccpa"
      ],
      "tags": [
        "box",
        "fence-sensitive-scopes",
        "ingress",
        "soc2",
        "hipaa",
        "gdpr-ccpa"
      ],
      "direction": "ingress",
      "package": "box.ingress.fence_sensitive_folders",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:44bf6f7b7b2874b2aa81637a97f8375767cd559bb8566acac8be339f6dac5ab4",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/box/fence-sensitive-folders",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/box/fence-sensitive-folders/policy.md"
    },
    {
      "slug": "databricks/fence-sensitive-schemas",
      "name": "Fence Sensitive Databricks Schemas",
      "summary": "Fences off the most sensitive lakehouse namespaces from agents on the read side of Databricks.",
      "url": "https://www.intentbasedpolicy.com/policies/databricks/fence-sensitive-schemas",
      "markdown": "https://www.intentbasedpolicy.com/policies/databricks/fence-sensitive-schemas.md",
      "app": "databricks",
      "apps": [
        "databricks"
      ],
      "bundles": [
        "soc2",
        "hipaa",
        "pci-dss",
        "gdpr-ccpa"
      ],
      "tags": [
        "databricks",
        "fence-sensitive-scopes",
        "ingress",
        "soc2",
        "hipaa",
        "pci-dss",
        "gdpr-ccpa"
      ],
      "direction": "ingress",
      "package": "databricks.ingress.fence_sensitive_schemas",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:5331f16e5edfd30686ae0dd1a0feb7526b875f660649556fc74231b1d0121036",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/databricks/fence-sensitive-schemas",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/databricks/fence-sensitive-schemas/policy.md"
    },
    {
      "slug": "dropbox/fence-sensitive-paths",
      "name": "Fence Sensitive Dropbox Paths by Team",
      "summary": "Fences protected Dropbox subtrees by path prefix . Dropbox addresses files and folders by a root-relative path (/Finance/2026/payroll.",
      "url": "https://www.intentbasedpolicy.com/policies/dropbox/fence-sensitive-paths",
      "markdown": "https://www.intentbasedpolicy.com/policies/dropbox/fence-sensitive-paths.md",
      "app": "dropbox",
      "apps": [
        "dropbox"
      ],
      "bundles": [
        "soc2",
        "hipaa",
        "gdpr-ccpa"
      ],
      "tags": [
        "dropbox",
        "fence-sensitive-scopes",
        "ingress",
        "soc2",
        "hipaa",
        "gdpr-ccpa"
      ],
      "direction": "ingress",
      "package": "dropbox.ingress.fence_sensitive_paths",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:a21a98aab34382aadfad11cf231ef36da8229ffd562ebc31200ab803061e646e",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/dropbox/fence-sensitive-paths",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/dropbox/fence-sensitive-paths/policy.md"
    },
    {
      "slug": "monday/fence-sensitive-boards",
      "name": "Fence Sensitive monday Boards by IdP Group",
      "summary": "monday boards are schemaless business databases: HR/recruiting boards (candidate PII), CRM/deal boards (financial), and IT/security trackers routinely live…",
      "url": "https://www.intentbasedpolicy.com/policies/monday/fence-sensitive-boards",
      "markdown": "https://www.intentbasedpolicy.com/policies/monday/fence-sensitive-boards.md",
      "app": "monday",
      "apps": [
        "monday"
      ],
      "bundles": [
        "soc2",
        "gdpr-ccpa"
      ],
      "tags": [
        "monday",
        "fence-sensitive-scopes",
        "ingress",
        "soc2",
        "gdpr-ccpa"
      ],
      "direction": "ingress",
      "package": "monday.ingress.fence_sensitive_boards",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:3394c5f9a68b7d5ae06b1cd66873371412b76a280c83e02ba0419c0d525659ab",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/monday/fence-sensitive-boards",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/monday/fence-sensitive-boards/policy.md"
    },
    {
      "slug": "servicenow/fence-sensitive-tables",
      "name": "Fence Sensitive ServiceNow Tables",
      "summary": "Fences off the most sensitive ServiceNow tables from two routes that reach them:",
      "url": "https://www.intentbasedpolicy.com/policies/servicenow/fence-sensitive-tables",
      "markdown": "https://www.intentbasedpolicy.com/policies/servicenow/fence-sensitive-tables.md",
      "app": "servicenow",
      "apps": [
        "servicenow"
      ],
      "bundles": [
        "soc2",
        "hipaa",
        "pci-dss",
        "gdpr-ccpa"
      ],
      "tags": [
        "servicenow",
        "fence-sensitive-tables",
        "pii",
        "ingress",
        "soc2",
        "hipaa",
        "pci-dss",
        "gdpr-ccpa"
      ],
      "direction": "ingress",
      "package": "servicenow.ingress.fence_sensitive_tables",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:9eca0d4f6f3221fc2cc8c6081fb12deec811764c612ad86d883c7f2134071193",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/servicenow/fence-sensitive-tables",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/servicenow/fence-sensitive-tables/policy.md"
    },
    {
      "slug": "snowflake/fence-sensitive-schemas",
      "name": "Fence Snowflake Sensitive Schemas by Data Domain",
      "summary": "Fences customer-designated sensitive data domains inside a Snowflake warehouse by inspecting the SQL text the agent is about to run — not by tool name, which…",
      "url": "https://www.intentbasedpolicy.com/policies/snowflake/fence-sensitive-schemas",
      "markdown": "https://www.intentbasedpolicy.com/policies/snowflake/fence-sensitive-schemas.md",
      "app": "snowflake",
      "apps": [
        "snowflake"
      ],
      "bundles": [
        "soc2",
        "hipaa",
        "pci-dss",
        "gdpr-ccpa"
      ],
      "tags": [
        "snowflake",
        "fence-sensitive-scopes",
        "ingress",
        "soc2",
        "hipaa",
        "pci-dss",
        "gdpr-ccpa"
      ],
      "direction": "ingress",
      "package": "snowflake.ingress.fence_sensitive_schemas",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:1679f0033186a3e591fb29d8086f5d1203cccffb675d791e70e7d7a11545709a",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/snowflake/fence-sensitive-schemas",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/snowflake/fence-sensitive-schemas/policy.md"
    },
    {
      "slug": "tableau/fence-datasource-scope",
      "name": "Fence Tableau Datasource Scope",
      "summary": "Tableau's MCP server is a warehouse proxy: query-datasource runs a VizQL Data Service (VDS) query and returns raw row-level data — PII, PHI, payroll,…",
      "url": "https://www.intentbasedpolicy.com/policies/tableau/fence-datasource-scope",
      "markdown": "https://www.intentbasedpolicy.com/policies/tableau/fence-datasource-scope.md",
      "app": "tableau",
      "apps": [
        "tableau"
      ],
      "bundles": [
        "soc2",
        "gdpr-ccpa"
      ],
      "tags": [
        "tableau",
        "fence-sensitive-scopes",
        "access-control",
        "datasource",
        "ingress",
        "soc2",
        "gdpr-ccpa"
      ],
      "direction": "ingress",
      "package": "tableau.ingress.fence_datasource_scope",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:21a1f19606553712a3c9d296f79e427199979cbb3de679a2236a084799e310bc",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/tableau/fence-datasource-scope",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/tableau/fence-datasource-scope/policy.md"
    },
    {
      "slug": "asana/fence-sensitive-projects",
      "name": "Fence Writes to Sensitive Asana Projects",
      "summary": "Asana is routinely used for HR (hiring, performance, offboarding), legal, M&A, and incident work; those project bodies, comments, custom fields, and status…",
      "url": "https://www.intentbasedpolicy.com/policies/asana/fence-sensitive-projects",
      "markdown": "https://www.intentbasedpolicy.com/policies/asana/fence-sensitive-projects.md",
      "app": "asana",
      "apps": [
        "asana"
      ],
      "bundles": [
        "soc2",
        "gdpr-ccpa"
      ],
      "tags": [
        "asana",
        "fence-sensitive-scopes",
        "ingress",
        "soc2",
        "gdpr-ccpa"
      ],
      "direction": "ingress",
      "package": "asana.ingress.fence_sensitive_projects",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:90fa434b8f6290758ceee9e9486db7d31c48e7abdf43a9b7514c0457f688fe85",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/asana/fence-sensitive-projects",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/asana/fence-sensitive-projects/policy.md"
    },
    {
      "slug": "zoom/fence-agentic-search",
      "name": "Fence Zoom Agentic Search to Native Corpora",
      "summary": "Constrains Zoom's agentic-search tool ( search zoom) so it can only reach Zoom-native content.",
      "url": "https://www.intentbasedpolicy.com/policies/zoom/fence-agentic-search",
      "markdown": "https://www.intentbasedpolicy.com/policies/zoom/fence-agentic-search.md",
      "app": "zoom",
      "apps": [
        "zoom"
      ],
      "bundles": [
        "soc2",
        "gdpr-ccpa"
      ],
      "tags": [
        "zoom",
        "agentic-search",
        "constrain-aggregator",
        "ingress",
        "soc2",
        "gdpr-ccpa"
      ],
      "direction": "ingress",
      "package": "zoom.ingress.fence_agentic_search",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:68cd3883f4dbe40b8b7af41c8f0a5c2a3e21efe5275b67aa76abb8382a0a0d72",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/zoom/fence-agentic-search",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/zoom/fence-agentic-search/policy.md"
    },
    {
      "slug": "docusign/force-draft-envelopes",
      "name": "Force Docusign Envelopes to Draft",
      "summary": "Rewrites Docusign envelope-creation calls so the envelope is staged as a (status: \"sent\").",
      "url": "https://www.intentbasedpolicy.com/policies/docusign/force-draft-envelopes",
      "markdown": "https://www.intentbasedpolicy.com/policies/docusign/force-draft-envelopes.md",
      "app": "docusign",
      "apps": [
        "docusign"
      ],
      "bundles": [],
      "tags": [
        "docusign",
        "force-draft-envelopes",
        "esign",
        "human-in-the-loop",
        "ingress"
      ],
      "direction": "ingress",
      "package": "docusign.ingress.force_draft_envelopes",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:c1dba6662400ac826544f174979bb864b1bc3c5872db5141910e22ec6982cc2b",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/docusign/force-draft-envelopes",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/docusign/force-draft-envelopes/policy.md"
    },
    {
      "slug": "jira/force-internal-jsm-comments",
      "name": "Force Internal Visibility on JSM Comments",
      "summary": "Keeps agent-drafted Jira Service Management (JSM) comments off the customer-facing portal by rewriting addCommentToJiraIssue calls to carry a restrictive…",
      "url": "https://www.intentbasedpolicy.com/policies/jira/force-internal-jsm-comments",
      "markdown": "https://www.intentbasedpolicy.com/policies/jira/force-internal-jsm-comments.md",
      "app": "jira",
      "apps": [
        "jira"
      ],
      "bundles": [
        "soc2",
        "atlassian"
      ],
      "tags": [
        "jira",
        "force-internal-comments",
        "comments",
        "jsm",
        "service-management",
        "ingress",
        "soc2",
        "atlassian"
      ],
      "direction": "ingress",
      "package": "jira.ingress.force_internal_jsm_comments",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:896209cbb84a0cfa530e5a7f86fd623e685efab156edcb59db1d9863f85bead8",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/jira/force-internal-jsm-comments",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/jira/force-internal-jsm-comments/policy.md"
    },
    {
      "slug": "servicenow/force-internal-comments",
      "name": "Force ServiceNow Comments to Internal Work Notes",
      "summary": "Keeps agent-drafted ServiceNow comments off the customer/employee-visible journal by rewriting add comment calls to internal work notes.",
      "url": "https://www.intentbasedpolicy.com/policies/servicenow/force-internal-comments",
      "markdown": "https://www.intentbasedpolicy.com/policies/servicenow/force-internal-comments.md",
      "app": "servicenow",
      "apps": [
        "servicenow"
      ],
      "bundles": [
        "soc2"
      ],
      "tags": [
        "servicenow",
        "force-internal-comments",
        "comments",
        "work-notes",
        "ingress",
        "soc2",
        "finra"
      ],
      "direction": "ingress",
      "package": "servicenow.ingress.force_internal_comments",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:38a189825fffea11d7fd6921f02c6c47944f201426cac9d3a523c2ff0d8fd5c9",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/servicenow/force-internal-comments",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/servicenow/force-internal-comments/policy.md"
    },
    {
      "slug": "airtable/freeze-record-deletion",
      "name": "Freeze Destructive Airtable Deletes",
      "summary": "Denies every destructive Airtable tool call unless the caller's IdP token carries the placeholder group airtable-admins.",
      "url": "https://www.intentbasedpolicy.com/policies/airtable/freeze-record-deletion",
      "markdown": "https://www.intentbasedpolicy.com/policies/airtable/freeze-record-deletion.md",
      "app": "airtable",
      "apps": [
        "airtable"
      ],
      "bundles": [
        "soc2"
      ],
      "tags": [
        "airtable",
        "freeze-destructive-ops",
        "record-integrity",
        "ingress",
        "soc2"
      ],
      "direction": "ingress",
      "package": "airtable.ingress.freeze_record_deletion",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:41f703f1354dea72fc51525d9263d34ec7e78f611f6686f29bce71ed8837ae2f",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/airtable/freeze-record-deletion",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/airtable/freeze-record-deletion/policy.md"
    },
    {
      "slug": "google-calendar/freeze-destructive-events",
      "name": "Freeze Destructive and Series-Wide Calendar Changes",
      "summary": "Denies irreversible Google Calendar mutations on the agent channel:",
      "url": "https://www.intentbasedpolicy.com/policies/google-calendar/freeze-destructive-events",
      "markdown": "https://www.intentbasedpolicy.com/policies/google-calendar/freeze-destructive-events.md",
      "app": "google-calendar",
      "apps": [
        "google-calendar"
      ],
      "bundles": [
        "soc2"
      ],
      "tags": [
        "google-calendar",
        "freeze-destructive-ops",
        "ingress",
        "integrity",
        "soc2"
      ],
      "direction": "ingress",
      "package": "google_calendar.ingress.freeze_destructive_events",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:30219dff7784e6056034b2c9b69142fd9ec18b6c07a5dce22ee64af368102f74",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/google-calendar/freeze-destructive-events",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/google-calendar/freeze-destructive-events/policy.md"
    },
    {
      "slug": "asana/freeze-destructive-ops",
      "name": "Freeze Destructive Asana Operations",
      "summary": "Denies every destructive Asana tool call unless the caller's IdP token carries the placeholder group asana-admins.",
      "url": "https://www.intentbasedpolicy.com/policies/asana/freeze-destructive-ops",
      "markdown": "https://www.intentbasedpolicy.com/policies/asana/freeze-destructive-ops.md",
      "app": "asana",
      "apps": [
        "asana"
      ],
      "bundles": [
        "soc2"
      ],
      "tags": [
        "asana",
        "freeze-destructive-ops",
        "record-integrity",
        "ingress",
        "soc2"
      ],
      "direction": "ingress",
      "package": "asana.ingress.freeze_destructive_ops",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:df535e73dddeb8cbd370639a068c826c8a2fe8bbf5a744a8544e4606d2266163",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/asana/freeze-destructive-ops",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/asana/freeze-destructive-ops/policy.md"
    },
    {
      "slug": "box/freeze-destructive-ops",
      "name": "Freeze Destructive Box Operations",
      "summary": "Freezes deletes and retention tampering on the community self-hosted Box MCP server (box-community/mcp-server-box).",
      "url": "https://www.intentbasedpolicy.com/policies/box/freeze-destructive-ops",
      "markdown": "https://www.intentbasedpolicy.com/policies/box/freeze-destructive-ops.md",
      "app": "box",
      "apps": [
        "box"
      ],
      "bundles": [
        "soc2"
      ],
      "tags": [
        "box",
        "freeze-destructive-ops",
        "ingress",
        "soc2"
      ],
      "direction": "ingress",
      "package": "box.ingress.freeze_destructive_ops",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:2f911c6a177d41fb8731d90545c167eafb8328f695c7356411806cb820605978",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/box/freeze-destructive-ops",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/box/freeze-destructive-ops/policy.md"
    },
    {
      "slug": "dropbox/freeze-destructive-ops",
      "name": "Freeze Destructive Dropbox Operations",
      "summary": "Freezes the irreversible and bulk-mutation Dropbox tools on the agent channel, regardless of path. At ingress it denies, by tool-name suffix:",
      "url": "https://www.intentbasedpolicy.com/policies/dropbox/freeze-destructive-ops",
      "markdown": "https://www.intentbasedpolicy.com/policies/dropbox/freeze-destructive-ops.md",
      "app": "dropbox",
      "apps": [
        "dropbox"
      ],
      "bundles": [
        "soc2"
      ],
      "tags": [
        "dropbox",
        "freeze-destructive-ops",
        "ingress",
        "soc2"
      ],
      "direction": "ingress",
      "package": "dropbox.ingress.freeze_destructive_ops",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:f1b1b9f6bff9fb5d2f25971376588b08da43e1f5d09893a894df50cd5b5a9af9",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/dropbox/freeze-destructive-ops",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/dropbox/freeze-destructive-ops/policy.md"
    },
    {
      "slug": "gmail/freeze-destructive-ops",
      "name": "Freeze Destructive Gmail Operations",
      "summary": "Denies the irreversible destruction surface that community Gmail MCP servers expose — permanent email deletion, label deletion, and filter deletion — for…",
      "url": "https://www.intentbasedpolicy.com/policies/gmail/freeze-destructive-ops",
      "markdown": "https://www.intentbasedpolicy.com/policies/gmail/freeze-destructive-ops.md",
      "app": "gmail",
      "apps": [
        "gmail"
      ],
      "bundles": [
        "soc2"
      ],
      "tags": [
        "gmail",
        "freeze-destructive-ops",
        "record-integrity",
        "ingress",
        "soc2"
      ],
      "direction": "ingress",
      "package": "gmail.ingress.freeze_destructive_ops",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:4238b7fbabe7f23035708c0160fcd168734ee90ad4820f45372b9abb67ba801c",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/gmail/freeze-destructive-ops",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/gmail/freeze-destructive-ops/policy.md"
    },
    {
      "slug": "google-drive/freeze-destructive-ops",
      "name": "Freeze Destructive Google Drive Operations",
      "summary": "Blocks Google Drive delete operations issued by agents.",
      "url": "https://www.intentbasedpolicy.com/policies/google-drive/freeze-destructive-ops",
      "markdown": "https://www.intentbasedpolicy.com/policies/google-drive/freeze-destructive-ops.md",
      "app": "google-drive",
      "apps": [
        "google-drive"
      ],
      "bundles": [
        "soc2"
      ],
      "tags": [
        "google-drive",
        "freeze-destructive-ops",
        "integrity",
        "ingress",
        "soc2"
      ],
      "direction": "ingress",
      "package": "google_drive.ingress.freeze_destructive_ops",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:9c7975075e258bb870bd24aa2d54cd18ed0ca068457c2df6ca4dd554667d9c6e",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/google-drive/freeze-destructive-ops",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/google-drive/freeze-destructive-ops/policy.md"
    },
    {
      "slug": "linear/freeze-destructive-ops",
      "name": "Freeze Destructive Linear Operations",
      "summary": "Denies destructive Linear tool calls — the delete , archive , and session-logout classes — unless the caller's IdP token carries the placeholder group…",
      "url": "https://www.intentbasedpolicy.com/policies/linear/freeze-destructive-ops",
      "markdown": "https://www.intentbasedpolicy.com/policies/linear/freeze-destructive-ops.md",
      "app": "linear",
      "apps": [
        "linear"
      ],
      "bundles": [
        "soc2"
      ],
      "tags": [
        "linear",
        "freeze-destructive-ops",
        "record-integrity",
        "ingress",
        "soc2"
      ],
      "direction": "ingress",
      "package": "linear.ingress.freeze_destructive_ops",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:b6dd4b06a24b10707fbcb23f8d5eac4ecb8774c5317b3327e1c32c86dd235317",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/linear/freeze-destructive-ops",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/linear/freeze-destructive-ops/policy.md"
    },
    {
      "slug": "ms365/freeze-destructive-ops",
      "name": "Freeze Destructive Microsoft 365 Operations",
      "summary": "Denies every Microsoft 365 tool call whose verb segment is delete- or cancel- unless the caller's IdP token carries the placeholder group m365-admin.",
      "url": "https://www.intentbasedpolicy.com/policies/ms365/freeze-destructive-ops",
      "markdown": "https://www.intentbasedpolicy.com/policies/ms365/freeze-destructive-ops.md",
      "app": "ms365",
      "apps": [
        "ms365"
      ],
      "bundles": [
        "sox",
        "soc2"
      ],
      "tags": [
        "ms365",
        "freeze-destructive-ops",
        "record-integrity",
        "ingress",
        "sox",
        "soc2"
      ],
      "direction": "ingress",
      "package": "ms365.ingress.freeze_destructive_ops",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:a47a4fecf243ba346724284e0ee0d247bdf0d85a3d4ebfcda003e9e9a0c36b6a",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/ms365/freeze-destructive-ops",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/ms365/freeze-destructive-ops/policy.md"
    },
    {
      "slug": "monday/freeze-destructive-ops",
      "name": "Freeze Destructive monday Operations",
      "summary": "Splits monday's destructive tool surface into two tiers and treats each differently at ingress, before the call ever reaches the monday MCP server:",
      "url": "https://www.intentbasedpolicy.com/policies/monday/freeze-destructive-ops",
      "markdown": "https://www.intentbasedpolicy.com/policies/monday/freeze-destructive-ops.md",
      "app": "monday",
      "apps": [
        "monday"
      ],
      "bundles": [
        "soc2"
      ],
      "tags": [
        "monday",
        "freeze-destructive-ops",
        "record-integrity",
        "ingress",
        "soc2"
      ],
      "direction": "ingress",
      "package": "monday.ingress.freeze_destructive_ops",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:c2bbe1edc48123a0e7e01ad03fc62c819c8e5c32256a6b7b468a08864b27a335",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/monday/freeze-destructive-ops",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/monday/freeze-destructive-ops/policy.md"
    },
    {
      "slug": "quickbooks/freeze-destructive-ops",
      "name": "Freeze Destructive QuickBooks Operations",
      "summary": "Denies every destructive QuickBooks Online (QBO) tool call on the agent channel before it reaches the MCP server.",
      "url": "https://www.intentbasedpolicy.com/policies/quickbooks/freeze-destructive-ops",
      "markdown": "https://www.intentbasedpolicy.com/policies/quickbooks/freeze-destructive-ops.md",
      "app": "quickbooks",
      "apps": [
        "quickbooks"
      ],
      "bundles": [
        "sox",
        "soc2"
      ],
      "tags": [
        "quickbooks",
        "freeze-destructive-ops",
        "ingress",
        "sox",
        "soc2"
      ],
      "direction": "ingress",
      "package": "quickbooks.ingress.freeze_destructive_ops",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:99d6257087dcfe5541c12a941bbadadf32fde18bbec355c8c7fcc786e5f70040",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/quickbooks/freeze-destructive-ops",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/quickbooks/freeze-destructive-ops/policy.md"
    },
    {
      "slug": "tableau/freeze-destructive-content",
      "name": "Freeze Destructive Tableau Content Ops",
      "summary": "Denies the irreversible content-mutation tools on the official tableau/tableau-mcp web server unless the caller's IdP token carries the placeholder group…",
      "url": "https://www.intentbasedpolicy.com/policies/tableau/freeze-destructive-content",
      "markdown": "https://www.intentbasedpolicy.com/policies/tableau/freeze-destructive-content.md",
      "app": "tableau",
      "apps": [
        "tableau"
      ],
      "bundles": [
        "soc2"
      ],
      "tags": [
        "tableau",
        "freeze-destructive-ops",
        "record-integrity",
        "ingress",
        "soc2"
      ],
      "direction": "ingress",
      "package": "tableau.ingress.freeze_destructive_content",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:8d6b132ceba2fb069063ea88c98e98fe02d593d2b4d958b99b101323561c2f42",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/tableau/freeze-destructive-content",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/tableau/freeze-destructive-content/policy.md"
    },
    {
      "slug": "ms365/freeze-identity-plane",
      "name": "Freeze M365 Identity Plane",
      "summary": "Freezes directory and membership mutations on the Microsoft 365 MCP surface. The policy denies, by tool-name suffix:",
      "url": "https://www.intentbasedpolicy.com/policies/ms365/freeze-identity-plane",
      "markdown": "https://www.intentbasedpolicy.com/policies/ms365/freeze-identity-plane.md",
      "app": "ms365",
      "apps": [
        "ms365"
      ],
      "bundles": [
        "soc2"
      ],
      "tags": [
        "ms365",
        "freeze-identity-plane",
        "ingress",
        "identity",
        "entra",
        "groups",
        "iso27001-nist",
        "soc2"
      ],
      "direction": "ingress",
      "package": "ms365.ingress.freeze_identity_plane",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:d64b95081439f286552ad6a368e6d710fbf158099d6301ee3d2491797b5ef62f",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/ms365/freeze-identity-plane",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/ms365/freeze-identity-plane/policy.md"
    },
    {
      "slug": "notion/freeze-content-overwrite",
      "name": "Freeze Notion Full-Page Content Overwrites",
      "summary": "Denies notion-update-page calls whose command argument is replace content — the one edge on Notion's hosted MCP server that overwrites a page's entire body…",
      "url": "https://www.intentbasedpolicy.com/policies/notion/freeze-content-overwrite",
      "markdown": "https://www.intentbasedpolicy.com/policies/notion/freeze-content-overwrite.md",
      "app": "notion",
      "apps": [
        "notion"
      ],
      "bundles": [
        "soc2"
      ],
      "tags": [
        "notion",
        "freeze-destructive-ops",
        "record-integrity",
        "ingress",
        "soc2"
      ],
      "direction": "ingress",
      "package": "notion.ingress.freeze_content_overwrite",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:bdd14752bb4b39bd321e170e1024a0814a647479fd985b5050f1cf9697ac17e7",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/notion/freeze-content-overwrite",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/notion/freeze-content-overwrite/policy.md"
    },
    {
      "slug": "gusto/freeze-payroll-writes",
      "name": "Freeze Payroll Writes in Gusto",
      "summary": "Freezes every write and delete operation on a Gusto pipeline.",
      "url": "https://www.intentbasedpolicy.com/policies/gusto/freeze-payroll-writes",
      "markdown": "https://www.intentbasedpolicy.com/policies/gusto/freeze-payroll-writes.md",
      "app": "gusto",
      "apps": [
        "gusto"
      ],
      "bundles": [],
      "tags": [
        "gusto",
        "freeze-destructive-ops",
        "ingress"
      ],
      "direction": "ingress",
      "package": "gusto.ingress.freeze_payroll_writes",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:d03af4d3df6423483d9c51dcf2dccde53973122ad2d2fda6e8ffc2b4a64fecbe",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/gusto/freeze-payroll-writes",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/gusto/freeze-payroll-writes/policy.md"
    },
    {
      "slug": "power-bi/freeze-rls-role-edits",
      "name": "Freeze Power BI RLS Role Edits",
      "summary": "Freezes edits to row-level-security (RLS) roles on the Power BI MCP surface.",
      "url": "https://www.intentbasedpolicy.com/policies/power-bi/freeze-rls-role-edits",
      "markdown": "https://www.intentbasedpolicy.com/policies/power-bi/freeze-rls-role-edits.md",
      "app": "power-bi",
      "apps": [
        "power-bi"
      ],
      "bundles": [
        "soc2"
      ],
      "tags": [
        "power-bi",
        "freeze-identity-plane",
        "ingress",
        "rls",
        "identity",
        "groups",
        "soc2",
        "iso27001-nist"
      ],
      "direction": "ingress",
      "package": "power_bi.ingress.freeze_rls_role_edits",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:92eb428f13d7bdbc001a799ec69040f9519f9d9b6145ed47f6f1682c6e81bb24",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/power-bi/freeze-rls-role-edits",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/power-bi/freeze-rls-role-edits/policy.md"
    },
    {
      "slug": "salesforce/freeze-record-deletes",
      "name": "Freeze Salesforce Record Deletes",
      "summary": "Denies all Salesforce record-deletion capability on the agent channel unless the caller's IdP groups claim contains the placeholder group sf-admins.",
      "url": "https://www.intentbasedpolicy.com/policies/salesforce/freeze-record-deletes",
      "markdown": "https://www.intentbasedpolicy.com/policies/salesforce/freeze-record-deletes.md",
      "app": "salesforce",
      "apps": [
        "salesforce"
      ],
      "bundles": [
        "soc2",
        "crm"
      ],
      "tags": [
        "salesforce",
        "freeze-destructive-ops",
        "ingress",
        "crm",
        "soc2"
      ],
      "direction": "ingress",
      "package": "salesforce.ingress.freeze_record_deletes",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:cb4a95da71019757822fbb9f01b50110685a33a680bf7621e6cbf97036379742",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/salesforce/freeze-record-deletes",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/salesforce/freeze-record-deletes/policy.md"
    },
    {
      "slug": "servicenow/freeze-identity-plane",
      "name": "Freeze ServiceNow Identity Plane",
      "summary": "Freezes the identity-and-access mutation surface of the ServiceNow MCP server. The policy denies, by tool-name suffix:",
      "url": "https://www.intentbasedpolicy.com/policies/servicenow/freeze-identity-plane",
      "markdown": "https://www.intentbasedpolicy.com/policies/servicenow/freeze-identity-plane.md",
      "app": "servicenow",
      "apps": [
        "servicenow"
      ],
      "bundles": [
        "soc2"
      ],
      "tags": [
        "servicenow",
        "freeze-identity-plane",
        "ingress",
        "identity",
        "groups",
        "soc2",
        "iso27001-nist"
      ],
      "direction": "ingress",
      "package": "servicenow.ingress.freeze_identity_plane",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:6990ec2afb77e7266fb9dce93d87d4ab478add739ab98a0ec1db21706d60cc15",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/servicenow/freeze-identity-plane",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/servicenow/freeze-identity-plane/policy.md"
    },
    {
      "slug": "monday/freeze-standing-automation",
      "name": "Freeze Standing Automation & AI Agents in monday",
      "summary": "Denies the monday tools that install side effects which outlive the governed MCP session. Two classes of tool are blocked:",
      "url": "https://www.intentbasedpolicy.com/policies/monday/freeze-standing-automation",
      "markdown": "https://www.intentbasedpolicy.com/policies/monday/freeze-standing-automation.md",
      "app": "monday",
      "apps": [
        "monday"
      ],
      "bundles": [
        "soc2"
      ],
      "tags": [
        "monday",
        "constrain-aggregator",
        "ingress",
        "soc2"
      ],
      "direction": "ingress",
      "package": "monday.ingress.freeze_standing_automation",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:08b9177f9aa3e60d9e719d13179c81b36802708b2407ecf9ca4be3daf9f221db",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/monday/freeze-standing-automation",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/monday/freeze-standing-automation/policy.md"
    },
    {
      "slug": "zapier/freeze-toolset",
      "name": "Freeze the Zapier Toolset (No Self-Expansion)",
      "summary": "In its default agentic mode, Zapier MCP exposes meta-tools that let the agent widen its own blast radius mid-session : enable zapier action and auto…",
      "url": "https://www.intentbasedpolicy.com/policies/zapier/freeze-toolset",
      "markdown": "https://www.intentbasedpolicy.com/policies/zapier/freeze-toolset.md",
      "app": "zapier",
      "apps": [
        "zapier"
      ],
      "bundles": [
        "soc2"
      ],
      "tags": [
        "zapier",
        "constrain-aggregator",
        "ingress",
        "soc2"
      ],
      "direction": "ingress",
      "package": "zapier.ingress.freeze_toolset",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:98e71dcc7eebd87653a9f2a62a46e7cef9640596c7dd49fa39db2934e74c9894",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/zapier/freeze-toolset",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/zapier/freeze-toolset/policy.md"
    },
    {
      "slug": "google-drive/role-gate-writes",
      "name": "Gate Google Drive Writes to an Authorized IdP Group",
      "summary": "Baseline least-privilege policy for Google Drive MCP traffic.",
      "url": "https://www.intentbasedpolicy.com/policies/google-drive/role-gate-writes",
      "markdown": "https://www.intentbasedpolicy.com/policies/google-drive/role-gate-writes.md",
      "app": "google-drive",
      "apps": [
        "google-drive"
      ],
      "bundles": [
        "soc2",
        "gdpr-ccpa"
      ],
      "tags": [
        "google-drive",
        "role-gate-writes",
        "least-privilege",
        "ingress",
        "soc2",
        "gdpr-ccpa"
      ],
      "direction": "ingress",
      "package": "google_drive.ingress.role_gate_writes",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:78e9a9a0d9f00492a266ecc50c2d2c843cd662ac5b52eb2da26a83044a36c70c",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/google-drive/role-gate-writes",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/google-drive/role-gate-writes/policy.md"
    },
    {
      "slug": "quickbooks/gate-money-movement",
      "name": "Gate QuickBooks Money-Movement by Finance Group",
      "summary": "Gates the QuickBooks Online money-movement creation tools — create payment, create bill payment, create refund receipt, create transfer, and create deposit —…",
      "url": "https://www.intentbasedpolicy.com/policies/quickbooks/gate-money-movement",
      "markdown": "https://www.intentbasedpolicy.com/policies/quickbooks/gate-money-movement.md",
      "app": "quickbooks",
      "apps": [
        "quickbooks"
      ],
      "bundles": [
        "sox",
        "pci-dss"
      ],
      "tags": [
        "quickbooks",
        "gate-money-movement",
        "ingress",
        "sox",
        "pci-dss"
      ],
      "direction": "ingress",
      "package": "quickbooks.ingress.gate_money_movement",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:81cc625d551e2bf5d26e006311471ffe6cc8d899cd65705fc59138d66269c0ce",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/quickbooks/gate-money-movement",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/quickbooks/gate-money-movement/policy.md"
    },
    {
      "slug": "zoom/guard-transcripts-by-group",
      "name": "Gate Zoom Transcripts & Recordings by Group",
      "summary": "Gates retrieval of Zoom meeting transcripts, AI Companion summaries, and next-steps on the connector's core egress tools, enforcing minimum-necessary access:",
      "url": "https://www.intentbasedpolicy.com/policies/zoom/guard-transcripts-by-group",
      "markdown": "https://www.intentbasedpolicy.com/policies/zoom/guard-transcripts-by-group.md",
      "app": "zoom",
      "apps": [
        "zoom"
      ],
      "bundles": [
        "hipaa",
        "gdpr-ccpa",
        "soc2"
      ],
      "tags": [
        "zoom",
        "guard-transcripts",
        "ingress",
        "hipaa",
        "gdpr-ccpa",
        "soc2"
      ],
      "direction": "ingress",
      "package": "zoom.ingress.guard_transcripts_by_group",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:f1d82a4c7c55e395514cf325c653336a2fe4a47b6b2553520e336db87d1f055c",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/zoom/guard-transcripts-by-group",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/zoom/guard-transcripts-by-group/policy.md"
    },
    {
      "slug": "github/redact-secrets-egress",
      "name": "GitHub: Redact Secrets from Read Responses",
      "summary": "Scans the responses of GitHub's crown-jewel read tools and masks known credential shapes with a fixed [REDACTED-SECRET] marker before the text enters agent…",
      "url": "https://www.intentbasedpolicy.com/policies/github/redact-secrets-egress",
      "markdown": "https://www.intentbasedpolicy.com/policies/github/redact-secrets-egress.md",
      "app": "github",
      "apps": [
        "github"
      ],
      "bundles": [
        "soc2"
      ],
      "tags": [
        "github",
        "redact-secrets",
        "secrets",
        "dlp",
        "redaction",
        "egress",
        "soc2"
      ],
      "direction": "egress",
      "package": "github.egress.redact_secrets",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:26bc1e1ebf9227a52389fc2a899782f2df997bef28875995cef905cdda0be9ca",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/github/redact-secrets-egress",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/github/redact-secrets-egress/policy.md"
    },
    {
      "slug": "glean/default-deny-unknown-tools",
      "name": "Glean Default-Deny Unknown Tools",
      "summary": "Pins a per-tenant allowlist of the verified built-in read tools on the Glean managed remote MCP server and denies every other tool suffix on the Glean server…",
      "url": "https://www.intentbasedpolicy.com/policies/glean/default-deny-unknown-tools",
      "markdown": "https://www.intentbasedpolicy.com/policies/glean/default-deny-unknown-tools.md",
      "app": "glean",
      "apps": [
        "glean"
      ],
      "bundles": [
        "soc2"
      ],
      "tags": [
        "glean",
        "default-deny-unknown-tools",
        "allowlist",
        "access-control",
        "ingress",
        "soc2"
      ],
      "direction": "ingress",
      "package": "glean.ingress.default_deny_unknown_tools",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:3482d8ff33089e20e8a6abd809b9a70c5494f6c4413c674cb9e7014beeeae640",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/glean/default-deny-unknown-tools",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/glean/default-deny-unknown-tools/policy.md"
    },
    {
      "slug": "glean/gate-memory-writes",
      "name": "Glean: Gate Memory Writes (Read-Only Default)",
      "summary": "Gates mutating calls to Glean's long-term memory surface — the built-in tool exposed as memory (and as read memory in Glean's own client guide).",
      "url": "https://www.intentbasedpolicy.com/policies/glean/gate-memory-writes",
      "markdown": "https://www.intentbasedpolicy.com/policies/glean/gate-memory-writes.md",
      "app": "glean",
      "apps": [
        "glean"
      ],
      "bundles": [
        "soc2"
      ],
      "tags": [
        "glean",
        "gate-memory-writes",
        "role-gate-writes",
        "memory",
        "access-control",
        "least-privilege",
        "ingress",
        "soc2"
      ],
      "direction": "ingress",
      "package": "glean.ingress.gate_memory_writes",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:3b7337cfdd6c33dd3e5c58425f66dc4ec68b4debbb40a1d3e361217c27faae07",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/glean/gate-memory-writes",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/glean/gate-memory-writes/policy.md"
    },
    {
      "slug": "glean/redact-pii-egress",
      "name": "Glean: Redact PII from Read-Tool Responses",
      "summary": "Scans the responses of Glean's content-returning read tools and rewrites high-confidence PII to fixed redaction tokens before the response reaches the…",
      "url": "https://www.intentbasedpolicy.com/policies/glean/redact-pii-egress",
      "markdown": "https://www.intentbasedpolicy.com/policies/glean/redact-pii-egress.md",
      "app": "glean",
      "apps": [
        "glean"
      ],
      "bundles": [
        "soc2",
        "hipaa",
        "gdpr-ccpa"
      ],
      "tags": [
        "glean",
        "redact-pii",
        "pii",
        "dlp",
        "redaction",
        "egress",
        "soc2",
        "hipaa",
        "gdpr-ccpa"
      ],
      "direction": "egress",
      "package": "glean.egress.redact_pii",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:e4da085ccb65113ff3cda00d4de010f996117a6e89efb8f77c143991554bf915",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/glean/redact-pii-egress",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/glean/redact-pii-egress/policy.md"
    },
    {
      "slug": "gmail/cap-bulk-export",
      "name": "Gmail Cap Bulk Export",
      "summary": "Throttles mass-harvesting of a mailbox by capping the per-call blast radius of the two Gmail MCP surfaces that return many full email bodies at once:",
      "url": "https://www.intentbasedpolicy.com/policies/gmail/cap-bulk-export",
      "markdown": "https://www.intentbasedpolicy.com/policies/gmail/cap-bulk-export.md",
      "app": "gmail",
      "apps": [
        "gmail"
      ],
      "bundles": [
        "soc2",
        "hipaa",
        "gdpr-ccpa"
      ],
      "tags": [
        "gmail",
        "cap-bulk-export",
        "data-minimisation",
        "ingress",
        "soc2",
        "hipaa",
        "gdpr-ccpa"
      ],
      "direction": "ingress",
      "package": "gmail.ingress.cap_bulk_export",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:a1d028ee37ad5c60df8ea59e6deb6aef24df041761b964182cbe8912d0fe7e26",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/gmail/cap-bulk-export",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/gmail/cap-bulk-export/policy.md"
    },
    {
      "slug": "gmail/role-gate-writes",
      "name": "Gmail: Role-Gated Writes (Read-Only Default)",
      "summary": "Makes Gmail read-only by default on the MCP path. Verified read tools pass for everyone.",
      "url": "https://www.intentbasedpolicy.com/policies/gmail/role-gate-writes",
      "markdown": "https://www.intentbasedpolicy.com/policies/gmail/role-gate-writes.md",
      "app": "gmail",
      "apps": [
        "gmail"
      ],
      "bundles": [
        "soc2",
        "gdpr-ccpa"
      ],
      "tags": [
        "gmail",
        "role-gate-writes",
        "access-control",
        "least-privilege",
        "ingress",
        "soc2",
        "gdpr-ccpa"
      ],
      "direction": "ingress",
      "package": "gmail.ingress.role_gate_writes",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:de7934ac32db6f02217c594f4b82d0264743c8892891d83135d9b96c98ab01a5",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/gmail/role-gate-writes",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/gmail/role-gate-writes/policy.md"
    },
    {
      "slug": "google-drive/redact-pii-egress",
      "name": "Google Drive: Redact PII from File Content",
      "summary": "Scans the responses of the content-returning Google Drive tools — file reads, downloads, and Docs/Sheets/Slides content fetches — and rewrites personally…",
      "url": "https://www.intentbasedpolicy.com/policies/google-drive/redact-pii-egress",
      "markdown": "https://www.intentbasedpolicy.com/policies/google-drive/redact-pii-egress.md",
      "app": "google-drive",
      "apps": [
        "google-drive"
      ],
      "bundles": [
        "soc2",
        "hipaa",
        "gdpr-ccpa"
      ],
      "tags": [
        "google-drive",
        "redact-pii",
        "pii",
        "dlp",
        "redaction",
        "egress",
        "soc2",
        "hipaa",
        "gdpr-ccpa"
      ],
      "direction": "egress",
      "package": "google_drive.egress.redact_pii",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:55e4d95ca2dd9483ce383f16cc4686f47e83affa590baa3d9d4e2033c74e09cc",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/google-drive/redact-pii-egress",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/google-drive/redact-pii-egress/policy.md"
    },
    {
      "slug": "box/guard-share-links-external",
      "name": "Guard Box Share Links and External Collaborations",
      "summary": "Blocks the externally-visible Box sharing surface — the riskiest Box surface an agent can touch — before the call ever reaches Box:",
      "url": "https://www.intentbasedpolicy.com/policies/box/guard-share-links-external",
      "markdown": "https://www.intentbasedpolicy.com/policies/box/guard-share-links-external.md",
      "app": "box",
      "apps": [
        "box"
      ],
      "bundles": [
        "soc2",
        "hipaa",
        "gdpr-ccpa"
      ],
      "tags": [
        "box",
        "guard-share-links",
        "sharing",
        "external-sharing",
        "ingress",
        "soc2",
        "hipaa",
        "gdpr-ccpa"
      ],
      "direction": "ingress",
      "package": "box.ingress.guard_share_links_external",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:c5bedabd8d1b9dc1e96a1027e4abebbf1907d703e3d53b648547d64b5c58a12a",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/box/guard-share-links-external",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/box/guard-share-links-external/policy.md"
    },
    {
      "slug": "tableau/guard-query-calculation",
      "name": "Guard Calculation Expressions in Tableau VDS Queries",
      "summary": "Inspects the structured VizQL Data Service (VDS) query carried by Tableau's query-datasource tool and denies the call for callers outside the data-analysts…",
      "url": "https://www.intentbasedpolicy.com/policies/tableau/guard-query-calculation",
      "markdown": "https://www.intentbasedpolicy.com/policies/tableau/guard-query-calculation.md",
      "app": "tableau",
      "apps": [
        "tableau"
      ],
      "bundles": [
        "soc2"
      ],
      "tags": [
        "tableau",
        "guard-warehouse-sql",
        "ingress",
        "calculation",
        "vizql",
        "soc2"
      ],
      "direction": "ingress",
      "package": "tableau.ingress.guard_query_calculation",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:54719300b40c58e8362b0f58a435d3ffaae08a8f81a5af8ca552ea63750f5a1e",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/tableau/guard-query-calculation",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/tableau/guard-query-calculation/policy.md"
    },
    {
      "slug": "databricks/guard-warehouse-sql",
      "name": "Guard Databricks SQL Against Writes and DDL",
      "summary": "Inspects the SQL statement string that Databricks SQL-executing tools carry in their argument and denies any statement that performs a write, schema change,…",
      "url": "https://www.intentbasedpolicy.com/policies/databricks/guard-warehouse-sql",
      "markdown": "https://www.intentbasedpolicy.com/policies/databricks/guard-warehouse-sql.md",
      "app": "databricks",
      "apps": [
        "databricks"
      ],
      "bundles": [
        "soc2",
        "pci-dss",
        "sox"
      ],
      "tags": [
        "databricks",
        "guard-warehouse-sql",
        "ingress",
        "sql",
        "readonly",
        "pci-dss",
        "sox",
        "soc2"
      ],
      "direction": "ingress",
      "package": "databricks.ingress.guard_warehouse_sql",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:3779448d0f1d79876d3fb8e5a777361f5553e1e60a4ac2fee9a601e05d091d97",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/databricks/guard-warehouse-sql",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/databricks/guard-warehouse-sql/policy.md"
    },
    {
      "slug": "power-bi/guard-warehouse-sql-dax",
      "name": "Guard DAX Whole-Table Dumps in Power BI",
      "summary": "Power BI semantic models front the warehouse: a model imports or DirectQueries lakehouse/warehouse tables — finance, HR, customer PII.",
      "url": "https://www.intentbasedpolicy.com/policies/power-bi/guard-warehouse-sql-dax",
      "markdown": "https://www.intentbasedpolicy.com/policies/power-bi/guard-warehouse-sql-dax.md",
      "app": "power-bi",
      "apps": [
        "power-bi"
      ],
      "bundles": [
        "soc2",
        "gdpr-ccpa"
      ],
      "tags": [
        "power-bi",
        "guard-warehouse-sql",
        "ingress",
        "dax",
        "exfiltration",
        "soc2",
        "gdpr-ccpa"
      ],
      "direction": "ingress",
      "package": "power_bi.ingress.guard_warehouse_sql_dax",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:c0b823df5cbea6f2d0716abaf093e193e4475e556d65bf28b9656c297a391ad8",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/power-bi/guard-warehouse-sql-dax",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/power-bi/guard-warehouse-sql-dax/policy.md"
    },
    {
      "slug": "docusign/guard-external-recipients",
      "name": "Guard Docusign External Recipients",
      "summary": "Blocks Docusign envelope-creation and recipient-update tool calls when any recipient email address has a domain outside the configured counterparty allowlist.",
      "url": "https://www.intentbasedpolicy.com/policies/docusign/guard-external-recipients",
      "markdown": "https://www.intentbasedpolicy.com/policies/docusign/guard-external-recipients.md",
      "app": "docusign",
      "apps": [
        "docusign"
      ],
      "bundles": [
        "soc2",
        "gdpr-ccpa"
      ],
      "tags": [
        "docusign",
        "guard-external-send",
        "ingress",
        "soc2",
        "gdpr-ccpa"
      ],
      "direction": "ingress",
      "package": "docusign.ingress.guard_external_recipients",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:598295fa866f3d9e48a78ae5ac9e7f9733c7ee2be6c639c5bcb4aaf3dce563e4",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/docusign/guard-external-recipients",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/docusign/guard-external-recipients/policy.md"
    },
    {
      "slug": "google-drive/guard-acl-recon",
      "name": "Guard Drive ACL Reconnaissance",
      "summary": "Denies Google Drive get file permissions tool calls unless the caller's IdP groups claim contains infosec. All other tool calls pass through unchanged.",
      "url": "https://www.intentbasedpolicy.com/policies/google-drive/guard-acl-recon",
      "markdown": "https://www.intentbasedpolicy.com/policies/google-drive/guard-acl-recon.md",
      "app": "google-drive",
      "apps": [
        "google-drive"
      ],
      "bundles": [
        "soc2"
      ],
      "tags": [
        "google-drive",
        "guard-share-links",
        "acl",
        "sharing",
        "ingress",
        "soc2"
      ],
      "direction": "ingress",
      "package": "google_drive.ingress.guard_acl_recon",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:e0aaeddeff19e80205a00317ffe4a616e0a4c04670c5ed05d5ce8915af54bf64",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/google-drive/guard-acl-recon",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/google-drive/guard-acl-recon/policy.md"
    },
    {
      "slug": "ms365/guard-share-links",
      "name": "Guard OneDrive/SharePoint Share Links",
      "summary": "Stops agents from opening OneDrive/SharePoint files to the whole internet. It guards the two Microsoft 365 sharing tools:",
      "url": "https://www.intentbasedpolicy.com/policies/ms365/guard-share-links",
      "markdown": "https://www.intentbasedpolicy.com/policies/ms365/guard-share-links.md",
      "app": "ms365",
      "apps": [
        "ms365"
      ],
      "bundles": [
        "soc2",
        "hipaa",
        "gdpr-ccpa"
      ],
      "tags": [
        "ms365",
        "share-links",
        "sharing",
        "ingress",
        "soc2",
        "iso27001-nist",
        "hipaa",
        "gdpr-ccpa"
      ],
      "direction": "ingress",
      "package": "ms365.ingress.guard_share_links",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:0eac06f802da18df36f260065a8ebddec91664c987624f6218087f4c5fa5715d",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/ms365/guard-share-links",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/ms365/guard-share-links/policy.md"
    },
    {
      "slug": "quickbooks/guard-vendor-banking",
      "name": "Guard Vendor Banking and Tax-ID Changes",
      "summary": "Blocks create vendor and update vendor calls whose arguments carry a vendor's payment coordinates — bank account number, routing / ACH branch details — or…",
      "url": "https://www.intentbasedpolicy.com/policies/quickbooks/guard-vendor-banking",
      "markdown": "https://www.intentbasedpolicy.com/policies/quickbooks/guard-vendor-banking.md",
      "app": "quickbooks",
      "apps": [
        "quickbooks"
      ],
      "bundles": [
        "sox"
      ],
      "tags": [
        "quickbooks",
        "vendor-banking",
        "anti-bec",
        "ingress",
        "sox"
      ],
      "direction": "ingress",
      "package": "quickbooks.ingress.guard_vendor_banking",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:ffd9a0fd618f61d9ba6efbc0727f4f73cfd95d3ae4a36915ab474314b7053134",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/quickbooks/guard-vendor-banking",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/quickbooks/guard-vendor-banking/policy.md"
    },
    {
      "slug": "gusto/cap-roster-export",
      "name": "Gusto Cap Roster Export",
      "summary": "Throttles full-roster exfiltration on Gusto's two broad outbound list tools — list company employees and list company contractors — by rewriting their…",
      "url": "https://www.intentbasedpolicy.com/policies/gusto/cap-roster-export",
      "markdown": "https://www.intentbasedpolicy.com/policies/gusto/cap-roster-export.md",
      "app": "gusto",
      "apps": [
        "gusto"
      ],
      "bundles": [
        "gdpr-ccpa",
        "soc2"
      ],
      "tags": [
        "gusto",
        "cap-bulk-export",
        "pii",
        "data-minimisation",
        "ingress",
        "gdpr-ccpa",
        "soc2"
      ],
      "direction": "ingress",
      "package": "gusto.ingress.cap_roster_export",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:0b593e25feade78662dac2f9f97a78950d241d6fa2f506fc90f6dbca004983a5",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/gusto/cap-roster-export",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/gusto/cap-roster-export/policy.md"
    },
    {
      "slug": "gusto/redact-financial-ids-egress",
      "name": "Gusto: Redact Financial IDs in Responses",
      "summary": "Instantiates PF-02 (redact-pii-egress) on the Gusto read path.",
      "url": "https://www.intentbasedpolicy.com/policies/gusto/redact-financial-ids-egress",
      "markdown": "https://www.intentbasedpolicy.com/policies/gusto/redact-financial-ids-egress.md",
      "app": "gusto",
      "apps": [
        "gusto"
      ],
      "bundles": [
        "soc2",
        "gdpr-ccpa"
      ],
      "tags": [
        "gusto",
        "redact-pii-egress",
        "redact-pii",
        "pii",
        "financial-pii",
        "dlp",
        "redaction",
        "egress",
        "soc2",
        "gdpr-ccpa"
      ],
      "direction": "egress",
      "package": "gusto.egress.redact_financial_ids",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:fd69b7151c41dac7bcb6e73201f632c84448ebe95997574f58a760891b57fcb5",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/gusto/redact-financial-ids-egress",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/gusto/redact-financial-ids-egress/policy.md"
    },
    {
      "slug": "hubspot/block-deal-closure",
      "name": "HubSpot Block Deal Closure",
      "summary": "Blocks HubSpot CRM-object calls that move a deal into a closed stage (closedwon or closedlost). Both create and update requests are inspected.",
      "url": "https://www.intentbasedpolicy.com/policies/hubspot/block-deal-closure",
      "markdown": "https://www.intentbasedpolicy.com/policies/hubspot/block-deal-closure.md",
      "app": "hubspot",
      "apps": [
        "hubspot"
      ],
      "bundles": [
        "crm"
      ],
      "tags": [
        "hubspot",
        "deals",
        "access-control",
        "governance",
        "ingress"
      ],
      "direction": "ingress",
      "package": "hubspot.ingress.no_close_deal",
      "publishedAt": "2026-06-16",
      "policyChecksum": "sha256:610b7a15cb9dfc53c0eef487b0bd786f47de31f4528493d2697b77913e50ea5e",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/hubspot/block-deal-closure",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/hubspot/block-deal-closure/policy.md"
    },
    {
      "slug": "hubspot/cap-bulk-export",
      "name": "HubSpot Cap Bulk Export",
      "summary": "Clamps the page size of HubSpot bulk-read tool calls before they reach the HubSpot MCP server, so a single agent request to a covered bulk-read tool can…",
      "url": "https://www.intentbasedpolicy.com/policies/hubspot/cap-bulk-export",
      "markdown": "https://www.intentbasedpolicy.com/policies/hubspot/cap-bulk-export.md",
      "app": "hubspot",
      "apps": [
        "hubspot"
      ],
      "bundles": [
        "crm",
        "soc2",
        "hipaa",
        "pci-dss",
        "gdpr-ccpa"
      ],
      "tags": [
        "hubspot",
        "cap-bulk-export",
        "pii",
        "data-minimisation",
        "ingress",
        "soc2",
        "hipaa",
        "pci-dss",
        "gdpr-ccpa"
      ],
      "direction": "ingress",
      "package": "hubspot.ingress.cap_bulk_export",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:dde664fd7b43b6fe4187d2b623b2b3ada8376c469f1e45455ca5a435f3325bc2",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/hubspot/cap-bulk-export",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/hubspot/cap-bulk-export/policy.md"
    },
    {
      "slug": "hubspot/freeze-destructive-ops",
      "name": "HubSpot Freeze Destructive Ops",
      "summary": "Blocks every archive/deletion-class HubSpot tool call, plus the consent-destroying contact unsubscribe, before it reaches the MCP server.",
      "url": "https://www.intentbasedpolicy.com/policies/hubspot/freeze-destructive-ops",
      "markdown": "https://www.intentbasedpolicy.com/policies/hubspot/freeze-destructive-ops.md",
      "app": "hubspot",
      "apps": [
        "hubspot"
      ],
      "bundles": [
        "crm",
        "soc2"
      ],
      "tags": [
        "hubspot",
        "freeze-destructive-ops",
        "archive",
        "consent",
        "ingress",
        "soc2"
      ],
      "direction": "ingress",
      "package": "hubspot.ingress.freeze_destructive_ops",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:61bf268f5c76551c996d77c84cc5ca8c398f671d279c1e9bd0e08d81e2885c56",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/hubspot/freeze-destructive-ops",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/hubspot/freeze-destructive-ops/policy.md"
    },
    {
      "slug": "hubspot/protect-associations",
      "name": "HubSpot Protect Associations",
      "summary": "Blocks HubSpot CRM-object calls that create or change associations between objects (deal↔company, contact↔company, etc.).",
      "url": "https://www.intentbasedpolicy.com/policies/hubspot/protect-associations",
      "markdown": "https://www.intentbasedpolicy.com/policies/hubspot/protect-associations.md",
      "app": "hubspot",
      "apps": [
        "hubspot"
      ],
      "bundles": [
        "crm"
      ],
      "tags": [
        "hubspot",
        "associations",
        "access-control",
        "governance",
        "ingress"
      ],
      "direction": "ingress",
      "package": "hubspot.ingress.protect_associations",
      "publishedAt": "2026-06-16",
      "policyChecksum": "sha256:682a9be175d987f3cb60dfabf940b2e5bac03da616a8a3539696c080d99d5d52",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/hubspot/protect-associations",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/hubspot/protect-associations/policy.md"
    },
    {
      "slug": "hubspot/protect-deal-owner",
      "name": "HubSpot Protect Deal Owner",
      "summary": "Blocks HubSpot CRM-object update calls that set or change a deal's owner.",
      "url": "https://www.intentbasedpolicy.com/policies/hubspot/protect-deal-owner",
      "markdown": "https://www.intentbasedpolicy.com/policies/hubspot/protect-deal-owner.md",
      "app": "hubspot",
      "apps": [
        "hubspot"
      ],
      "bundles": [
        "crm"
      ],
      "tags": [
        "hubspot",
        "deals",
        "access-control",
        "governance",
        "ingress"
      ],
      "direction": "ingress",
      "package": "hubspot.ingress.protect_deal_owner",
      "publishedAt": "2026-06-16",
      "policyChecksum": "sha256:9b850e272d771fce7b98056fbe73fae4aeadb5e8b79e940b4e7f643a925a36a0",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/hubspot/protect-deal-owner",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/hubspot/protect-deal-owner/policy.md"
    },
    {
      "slug": "hubspot/protect-lifecycle-stage",
      "name": "HubSpot Protect Lifecycle Stage",
      "summary": "Blocks HubSpot CRM-object calls that set or change a contact's lifecycle stage.",
      "url": "https://www.intentbasedpolicy.com/policies/hubspot/protect-lifecycle-stage",
      "markdown": "https://www.intentbasedpolicy.com/policies/hubspot/protect-lifecycle-stage.md",
      "app": "hubspot",
      "apps": [
        "hubspot"
      ],
      "bundles": [
        "crm"
      ],
      "tags": [
        "hubspot",
        "contacts",
        "lifecycle",
        "access-control",
        "governance",
        "ingress"
      ],
      "direction": "ingress",
      "package": "hubspot.ingress.protect_lifecycle_stage",
      "publishedAt": "2026-06-16",
      "policyChecksum": "sha256:16f9e6e25e396ba938081c793f12d3bfbc0eb030440fa04e871885e6fcc3697f",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/hubspot/protect-lifecycle-stage",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/hubspot/protect-lifecycle-stage/policy.md"
    },
    {
      "slug": "hubspot/read-only",
      "name": "HubSpot Read-Only",
      "summary": "Makes the HubSpot connection read-only by blocking the write tool.",
      "url": "https://www.intentbasedpolicy.com/policies/hubspot/read-only",
      "markdown": "https://www.intentbasedpolicy.com/policies/hubspot/read-only.md",
      "app": "hubspot",
      "apps": [
        "hubspot"
      ],
      "bundles": [
        "crm",
        "soc2",
        "gdpr-ccpa"
      ],
      "tags": [
        "hubspot",
        "access-control",
        "governance",
        "read-only",
        "ingress",
        "soc2",
        "gdpr-ccpa"
      ],
      "direction": "ingress",
      "package": "hubspot.ingress.readonly",
      "publishedAt": "2026-06-16",
      "policyChecksum": "sha256:c4ef50764a959af252cfbd5474bfea02a57b207fa3d352636dc70b8f11b45de0",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/hubspot/read-only",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/hubspot/read-only/policy.md"
    },
    {
      "slug": "hubspot/redact-pii",
      "name": "HubSpot Redact PII",
      "summary": "Redacts sensitive contact information from HubSpot tool responses before they reach the caller.",
      "url": "https://www.intentbasedpolicy.com/policies/hubspot/redact-pii",
      "markdown": "https://www.intentbasedpolicy.com/policies/hubspot/redact-pii.md",
      "app": "hubspot",
      "apps": [
        "hubspot"
      ],
      "bundles": [
        "crm",
        "soc2",
        "hipaa",
        "gdpr-ccpa"
      ],
      "tags": [
        "hubspot",
        "pii",
        "dlp",
        "redaction",
        "egress",
        "soc2",
        "hipaa",
        "gdpr-ccpa"
      ],
      "direction": "egress",
      "package": "hubspot.egress.redact_pii",
      "publishedAt": "2026-06-16",
      "policyChecksum": "sha256:6d01e4aadb8ca920e3118d6be38a4ab8f5733575955170ce5f10900c01c4835f",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/hubspot/redact-pii",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/hubspot/redact-pii/policy.md"
    },
    {
      "slug": "hubspot/role-gate-schema-consent",
      "name": "HubSpot Role-Gate Schema and Consent",
      "summary": "Sits one privilege tier above hubspot/role-gate-writes: ordinary crm-writers can create and edit CRM records, but two higher-blast-radius write classes are…",
      "url": "https://www.intentbasedpolicy.com/policies/hubspot/role-gate-schema-consent",
      "markdown": "https://www.intentbasedpolicy.com/policies/hubspot/role-gate-schema-consent.md",
      "app": "hubspot",
      "apps": [
        "hubspot"
      ],
      "bundles": [
        "crm",
        "soc2"
      ],
      "tags": [
        "hubspot",
        "role-gate-schema-consent",
        "access-control",
        "least-privilege",
        "segregation-of-duties",
        "consent",
        "ingress",
        "soc2"
      ],
      "direction": "ingress",
      "package": "hubspot.ingress.role_gate_schema_consent",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:636e03d146602ca6b48ed50fa6a70bc153d8f9acbe74dfc74cc5a3fc6d8585dd",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/hubspot/role-gate-schema-consent",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/hubspot/role-gate-schema-consent/policy.md"
    },
    {
      "slug": "hubspot/role-gate-writes",
      "name": "HubSpot Role-Gate Writes",
      "summary": "Gates every HubSpot write tool behind an IdP group: callers whose JWT groups claim contains crm-writers may create and update CRM records; everyone else gets…",
      "url": "https://www.intentbasedpolicy.com/policies/hubspot/role-gate-writes",
      "markdown": "https://www.intentbasedpolicy.com/policies/hubspot/role-gate-writes.md",
      "app": "hubspot",
      "apps": [
        "hubspot"
      ],
      "bundles": [
        "crm",
        "soc2",
        "gdpr-ccpa"
      ],
      "tags": [
        "hubspot",
        "role-gate-writes",
        "access-control",
        "least-privilege",
        "ingress",
        "soc2",
        "gdpr-ccpa"
      ],
      "direction": "ingress",
      "package": "hubspot.ingress.role_gate_writes",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:d53fba0c23a2327c59fd9e19a4bc3a15c4b26b48b6e3d48ee07d2c3fa8215aba",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/hubspot/role-gate-writes",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/hubspot/role-gate-writes/policy.md"
    },
    {
      "slug": "servicenow/require-human-approval-changes",
      "name": "Human-Only ServiceNow Change Approval",
      "summary": "Unconditionally denies the ServiceNow change-management control-gate tools — the ones whose names end in approve change, reject change, or submit change for…",
      "url": "https://www.intentbasedpolicy.com/policies/servicenow/require-human-approval-changes",
      "markdown": "https://www.intentbasedpolicy.com/policies/servicenow/require-human-approval-changes.md",
      "app": "servicenow",
      "apps": [
        "servicenow"
      ],
      "bundles": [
        "soc2"
      ],
      "tags": [
        "servicenow",
        "require-human-approval",
        "change-management",
        "separation-of-duties",
        "ingress",
        "soc2"
      ],
      "direction": "ingress",
      "package": "servicenow.ingress.require_human_approval_changes",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:e1a7930d31f9d502d08d7cc21e70486fd1ea12f34c2b414333090fe178bbcf95",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/servicenow/require-human-approval-changes",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/servicenow/require-human-approval-changes/policy.md"
    },
    {
      "slug": "stripe/require-human-approval-dispute-submit",
      "name": "Human-Only Stripe Dispute Submission",
      "summary": "Strips the irreversible submit flag from Stripe update dispute tool calls.",
      "url": "https://www.intentbasedpolicy.com/policies/stripe/require-human-approval-dispute-submit",
      "markdown": "https://www.intentbasedpolicy.com/policies/stripe/require-human-approval-dispute-submit.md",
      "app": "stripe",
      "apps": [
        "stripe"
      ],
      "bundles": [
        "sox"
      ],
      "tags": [
        "stripe",
        "require-human-approval",
        "disputes",
        "separation-of-duties",
        "transform",
        "ingress",
        "sox"
      ],
      "direction": "ingress",
      "package": "stripe.ingress.require_human_approval_dispute_submit",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:f97adf30fcbb2267bb1875aff767e1b4d22820d4e210df901e64dec4c76ad081",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/stripe/require-human-approval-dispute-submit",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/stripe/require-human-approval-dispute-submit/policy.md"
    },
    {
      "slug": "intercom/deny-article-publish",
      "name": "Intercom: Keep Agent Help Center Articles in Draft",
      "summary": "Keeps agent-authored Intercom Help Center articles in draft so a human reviews them before they go live on the public Help Center.",
      "url": "https://www.intentbasedpolicy.com/policies/intercom/deny-article-publish",
      "markdown": "https://www.intentbasedpolicy.com/policies/intercom/deny-article-publish.md",
      "app": "intercom",
      "apps": [
        "intercom"
      ],
      "bundles": [
        "soc2"
      ],
      "tags": [
        "intercom",
        "deny-public-exposure",
        "ingress",
        "articles",
        "help-center",
        "publication",
        "governance",
        "soc2"
      ],
      "direction": "ingress",
      "package": "intercom.ingress.deny_article_publish",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:44188b457f7d849e6aec7c84844617e9827e6764822199b8826edfbbcba00f27",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/intercom/deny-article-publish",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/intercom/deny-article-publish/policy.md"
    },
    {
      "slug": "intercom/mask-pan-egress",
      "name": "Intercom: Mask Card Numbers in Conversation Responses",
      "summary": "Masks payment-card numbers (PANs) in Intercom conversation content returned to agents by the conversation- and free-text-returning read tools.",
      "url": "https://www.intentbasedpolicy.com/policies/intercom/mask-pan-egress",
      "markdown": "https://www.intentbasedpolicy.com/policies/intercom/mask-pan-egress.md",
      "app": "intercom",
      "apps": [
        "intercom"
      ],
      "bundles": [
        "soc2",
        "pci-dss",
        "gdpr-ccpa"
      ],
      "tags": [
        "intercom",
        "mask-pan-egress",
        "egress",
        "cardholder-data",
        "dlp",
        "soc2",
        "pci-dss",
        "gdpr-ccpa"
      ],
      "direction": "egress",
      "package": "intercom.egress.mask_pan",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:0b4b075b2bc299e37c0c3c0c9d9ba4490009be9685104d546eb6abb35b64a8c4",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/intercom/mask-pan-egress",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/intercom/mask-pan-egress/policy.md"
    },
    {
      "slug": "intercom/redact-conversation-pii",
      "name": "Intercom: Redact PII from Conversation & Contact Reads",
      "summary": "Scans the free-text returned by Intercom's conversation- and contact-read MCP tools and rewrites high-confidence personal identifiers and credential shapes…",
      "url": "https://www.intentbasedpolicy.com/policies/intercom/redact-conversation-pii",
      "markdown": "https://www.intentbasedpolicy.com/policies/intercom/redact-conversation-pii.md",
      "app": "intercom",
      "apps": [
        "intercom"
      ],
      "bundles": [
        "soc2",
        "hipaa",
        "gdpr-ccpa"
      ],
      "tags": [
        "intercom",
        "redact-pii",
        "pii",
        "dlp",
        "redaction",
        "egress",
        "soc2",
        "hipaa",
        "gdpr-ccpa"
      ],
      "direction": "egress",
      "package": "intercom.egress.redact_conversation_pii",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:e22a2015db55ffeaabe531da642d68ece1c4116e2fe1d3b59108136f532f325d",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/intercom/redact-conversation-pii",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/intercom/redact-conversation-pii/policy.md"
    },
    {
      "slug": "jira/deny-history-actor-spoofing",
      "name": "JIRA: Block Change-History Actor Spoofing",
      "summary": "Blocks any official Jira write call — transitionJiraIssue, editJiraIssue, or createJiraIssue — that carries a historyMetadata block, before it reaches the…",
      "url": "https://www.intentbasedpolicy.com/policies/jira/deny-history-actor-spoofing",
      "markdown": "https://www.intentbasedpolicy.com/policies/jira/deny-history-actor-spoofing.md",
      "app": "jira",
      "apps": [
        "jira"
      ],
      "bundles": [
        "atlassian",
        "soc2"
      ],
      "tags": [
        "jira",
        "atlassian",
        "freeze-destructive-ops",
        "audit-integrity",
        "ingress",
        "soc2"
      ],
      "direction": "ingress",
      "package": "jira.ingress.deny_history_actor_spoofing",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:4aa60fa5bf3830627bb218fe0e186c8ae959ab1b6c6ac6db2a2bcb4ee547bdec",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/jira/deny-history-actor-spoofing",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/jira/deny-history-actor-spoofing/policy.md"
    },
    {
      "slug": "jira/cap-read-field-exposure",
      "name": "JIRA: Cap Field and Result Exposure on Reads",
      "summary": "Narrows the breadth of JIRA read requests before they run, on the two read surfaces that can pull large amounts of issue data into model context:",
      "url": "https://www.intentbasedpolicy.com/policies/jira/cap-read-field-exposure",
      "markdown": "https://www.intentbasedpolicy.com/policies/jira/cap-read-field-exposure.md",
      "app": "jira",
      "apps": [
        "jira"
      ],
      "bundles": [
        "soc2",
        "gdpr-ccpa",
        "atlassian"
      ],
      "tags": [
        "jira",
        "atlassian",
        "cap-bulk-export",
        "data-minimisation",
        "ingress",
        "soc2",
        "gdpr-ccpa"
      ],
      "direction": "ingress",
      "package": "jira.ingress.cap_read_field_exposure",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:637a57a8d7b022024175ead61be45bbac0f1c2fbd2e9e9302077df36694c24ef",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/jira/cap-read-field-exposure",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/jira/cap-read-field-exposure/policy.md"
    },
    {
      "slug": "jira/deny-view-search-sensitive-projects",
      "name": "JIRA: Deny Sensitive Project Search and View",
      "summary": "Keeps issues that belong to a configurable set of \"sensitive\" JIRA projects out of read access through the JIRA MCP server.",
      "url": "https://www.intentbasedpolicy.com/policies/jira/deny-view-search-sensitive-projects",
      "markdown": "https://www.intentbasedpolicy.com/policies/jira/deny-view-search-sensitive-projects.md",
      "app": "jira",
      "apps": [
        "jira"
      ],
      "bundles": [
        "atlassian",
        "soc2",
        "gdpr-ccpa"
      ],
      "tags": [
        "jira",
        "atlassian",
        "access-control",
        "data-protection",
        "ingress",
        "soc2",
        "gdpr-ccpa",
        "iso27001-nist",
        "finserv-comms"
      ],
      "direction": "ingress",
      "package": "jira.ingress.deny_sensitive_search_and_view",
      "publishedAt": "2026-06-16",
      "policyChecksum": "sha256:3d14268530ccbaf2985ca1cfe913ded30b6f98f97c73ca8f362eb9dae8e207aa",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/jira/deny-view-search-sensitive-projects",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/jira/deny-view-search-sensitive-projects/policy.md"
    },
    {
      "slug": "jira/freeze-destructive-ops",
      "name": "JIRA: Freeze Destructive Issue Operations",
      "summary": "Freezes the three irreversible Jira operations on the agent channel: jira delete issue, jira remove issue link, and jira remove watcher.",
      "url": "https://www.intentbasedpolicy.com/policies/jira/freeze-destructive-ops",
      "markdown": "https://www.intentbasedpolicy.com/policies/jira/freeze-destructive-ops.md",
      "app": "jira",
      "apps": [
        "jira"
      ],
      "bundles": [
        "atlassian",
        "soc2"
      ],
      "tags": [
        "jira",
        "atlassian",
        "freeze-destructive-ops",
        "record-integrity",
        "data-protection",
        "ingress",
        "soc2"
      ],
      "direction": "ingress",
      "package": "jira.ingress.freeze_destructive_ops",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:a1fdaf3066fa072df7ee75cfd8b685b139f903092e0bc1fe5bc38ef92175bda3",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/jira/freeze-destructive-ops",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/jira/freeze-destructive-ops/policy.md"
    },
    {
      "slug": "jira/deny-write-sensitive-projects",
      "name": "JIRA: Protect Sensitive Projects from Writes",
      "summary": "Blocks write operations against issues that belong to a configurable set of \"sensitive\" JIRA projects.",
      "url": "https://www.intentbasedpolicy.com/policies/jira/deny-write-sensitive-projects",
      "markdown": "https://www.intentbasedpolicy.com/policies/jira/deny-write-sensitive-projects.md",
      "app": "jira",
      "apps": [
        "jira"
      ],
      "bundles": [
        "atlassian",
        "soc2",
        "gdpr-ccpa"
      ],
      "tags": [
        "jira",
        "atlassian",
        "access-control",
        "data-protection",
        "ingress",
        "soc2",
        "gdpr-ccpa",
        "iso27001-nist",
        "finserv-comms"
      ],
      "direction": "ingress",
      "package": "jira.ingress.protect_sensitive_projects",
      "publishedAt": "2026-06-16",
      "policyChecksum": "sha256:4aa9ccaf2b1a21d2535ba07f2b472a4bde1a67dadcfe21aa25c7aab8a2845bf1",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/jira/deny-write-sensitive-projects",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/jira/deny-write-sensitive-projects/policy.md"
    },
    {
      "slug": "jira/redact-sensitive-info",
      "name": "JIRA: Redact Sensitive Information from Issue Views",
      "summary": "Redacts sensitive content from the responses of JIRA issue-view tools before they reach the caller.",
      "url": "https://www.intentbasedpolicy.com/policies/jira/redact-sensitive-info",
      "markdown": "https://www.intentbasedpolicy.com/policies/jira/redact-sensitive-info.md",
      "app": "jira",
      "apps": [
        "jira"
      ],
      "bundles": [
        "atlassian",
        "soc2",
        "gdpr-ccpa"
      ],
      "tags": [
        "jira",
        "atlassian",
        "pii",
        "secrets",
        "dlp",
        "redaction",
        "egress",
        "soc2",
        "gdpr-ccpa",
        "iso27001-nist"
      ],
      "direction": "egress",
      "package": "jira.egress.redact_sensitive_info",
      "publishedAt": "2026-06-15",
      "policyChecksum": "sha256:8d1f6a48db9d9572ec3f8ef34c4afd991dd1d9bb1cd9834febdec88f3716e600",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/jira/redact-sensitive-info",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/jira/redact-sensitive-info/policy.md"
    },
    {
      "slug": "jira/role-gate-writes",
      "name": "JIRA: Role-Gated Writes (Read-Only Default)",
      "summary": "Makes Jira read-only by default on the MCP path.",
      "url": "https://www.intentbasedpolicy.com/policies/jira/role-gate-writes",
      "markdown": "https://www.intentbasedpolicy.com/policies/jira/role-gate-writes.md",
      "app": "jira",
      "apps": [
        "jira"
      ],
      "bundles": [
        "atlassian",
        "soc2",
        "gdpr-ccpa"
      ],
      "tags": [
        "jira",
        "atlassian",
        "role-gate-writes",
        "access-control",
        "least-privilege",
        "ingress",
        "soc2",
        "gdpr-ccpa"
      ],
      "direction": "ingress",
      "package": "jira.ingress.role_gate_writes",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:986e5a061ed2a667d4950e82b24909c491ea57219ebde0aa32696c54acde1ebc",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/jira/role-gate-writes",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/jira/role-gate-writes/policy.md"
    },
    {
      "slug": "linear/redact-customer-pii-egress",
      "name": "Linear: Redact Customer Revenue and Contacts",
      "summary": "Masks commercial and contact identifiers in the responses of Linear's Customers read tools before they reach the agent.",
      "url": "https://www.intentbasedpolicy.com/policies/linear/redact-customer-pii-egress",
      "markdown": "https://www.intentbasedpolicy.com/policies/linear/redact-customer-pii-egress.md",
      "app": "linear",
      "apps": [
        "linear"
      ],
      "bundles": [
        "gdpr-ccpa",
        "soc2"
      ],
      "tags": [
        "linear",
        "redact-pii",
        "pii",
        "dlp",
        "redaction",
        "egress",
        "gdpr-ccpa",
        "soc2"
      ],
      "direction": "egress",
      "package": "linear.egress.redact_customer_data",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:6d1736a372ac5e9534d04bd847cf125225eaa957c95d9f81b6dd0f1d7ab49c6a",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/linear/redact-customer-pii-egress",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/linear/redact-customer-pii-egress/policy.md"
    },
    {
      "slug": "quickbooks/protect-closed-periods-journal-entries",
      "name": "Lock Direct Journal-Entry Ledger Writes",
      "summary": "Denies the QuickBooks Online tools create journal entry and update journal entry at ingress for every caller except those whose IdP claims include the…",
      "url": "https://www.intentbasedpolicy.com/policies/quickbooks/protect-closed-periods-journal-entries",
      "markdown": "https://www.intentbasedpolicy.com/policies/quickbooks/protect-closed-periods-journal-entries.md",
      "app": "quickbooks",
      "apps": [
        "quickbooks"
      ],
      "bundles": [
        "sox"
      ],
      "tags": [
        "quickbooks",
        "protect-closed-periods",
        "ingress",
        "sox"
      ],
      "direction": "ingress",
      "package": "quickbooks.ingress.protect_closed_periods_journal_entries",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:280766f1e6668c871fc0f6f8db881276c6c3c1990bde22293de7009effedca30",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/quickbooks/protect-closed-periods-journal-entries",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/quickbooks/protect-closed-periods-journal-entries/policy.md"
    },
    {
      "slug": "gmail/mask-pan-egress",
      "name": "Mask Card Numbers in Email Content Read by Agents",
      "summary": "Masks payment-card-number (PAN) shapes in email content returned to agents by Gmail mailbox-read tools.",
      "url": "https://www.intentbasedpolicy.com/policies/gmail/mask-pan-egress",
      "markdown": "https://www.intentbasedpolicy.com/policies/gmail/mask-pan-egress.md",
      "app": "gmail",
      "apps": [
        "gmail"
      ],
      "bundles": [
        "soc2",
        "pci-dss",
        "gdpr-ccpa"
      ],
      "tags": [
        "gmail",
        "mask-pan-egress",
        "egress",
        "email",
        "cardholder-data",
        "dlp",
        "soc2",
        "pci-dss",
        "gdpr-ccpa"
      ],
      "direction": "egress",
      "package": "gmail.egress.mask_pan",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:879ee13a0594096f178508fd7569014f342d1e43e87ef96a86818554b85cbc7e",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/gmail/mask-pan-egress",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/gmail/mask-pan-egress/policy.md"
    },
    {
      "slug": "ms365/redact-pii-egress",
      "name": "Microsoft 365: Redact PII from Mail, Files & Transcripts",
      "summary": "Scans the responses of the highest-density PII read surfaces in Microsoft 365 — mail bodies, Excel ranges, SharePoint list items, meeting transcripts, and…",
      "url": "https://www.intentbasedpolicy.com/policies/ms365/redact-pii-egress",
      "markdown": "https://www.intentbasedpolicy.com/policies/ms365/redact-pii-egress.md",
      "app": "ms365",
      "apps": [
        "ms365"
      ],
      "bundles": [
        "soc2",
        "hipaa",
        "gdpr-ccpa"
      ],
      "tags": [
        "ms365",
        "redact-pii",
        "pii",
        "dlp",
        "redaction",
        "egress",
        "soc2",
        "hipaa",
        "gdpr-ccpa"
      ],
      "direction": "egress",
      "package": "ms365.egress.redact_pii",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:b7943f1cac7e84a7bc6e99b39091c9ca82a80ccbaab58b92659aab888b2d6947",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/ms365/redact-pii-egress",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/ms365/redact-pii-egress/policy.md"
    },
    {
      "slug": "monday/redact-board-pii-egress",
      "name": "monday: Redact PII in Board & Doc Reads",
      "summary": "Two egress controls in one policy, both scoped to the monday MCP read path:",
      "url": "https://www.intentbasedpolicy.com/policies/monday/redact-board-pii-egress",
      "markdown": "https://www.intentbasedpolicy.com/policies/monday/redact-board-pii-egress.md",
      "app": "monday",
      "apps": [
        "monday"
      ],
      "bundles": [
        "soc2",
        "gdpr-ccpa"
      ],
      "tags": [
        "monday",
        "redact-pii",
        "pii",
        "dlp",
        "redaction",
        "egress",
        "soc2",
        "gdpr-ccpa"
      ],
      "direction": "egress",
      "package": "monday.egress.redact_board_pii",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:932aa9e48640c77c66fc2fe297cdd827c3fa6df976eb211a5ce2abe33322f072",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/monday/redact-board-pii-egress",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/monday/redact-board-pii-egress/policy.md"
    },
    {
      "slug": "netsuite/cap-bulk-export",
      "name": "NetSuite Cap SuiteQL Bulk Export",
      "summary": "Instantiates the PF-08 cap-bulk-export family as a transform-only ingress policy on ns runCustomSuiteQL — the NetSuite MCP tool that runs arbitrary read-only…",
      "url": "https://www.intentbasedpolicy.com/policies/netsuite/cap-bulk-export",
      "markdown": "https://www.intentbasedpolicy.com/policies/netsuite/cap-bulk-export.md",
      "app": "netsuite",
      "apps": [
        "netsuite"
      ],
      "bundles": [
        "soc2",
        "pci-dss",
        "gdpr-ccpa"
      ],
      "tags": [
        "netsuite",
        "cap-bulk-export",
        "suiteql",
        "data-minimisation",
        "ingress",
        "soc2",
        "pci-dss",
        "gdpr-ccpa"
      ],
      "direction": "ingress",
      "package": "netsuite.ingress.cap_bulk_export",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:bdb0847d6ea9c76e69492383905cdace646d3ec4c427c97322be9e42dbe0aeb9",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/netsuite/cap-bulk-export",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/netsuite/cap-bulk-export/policy.md"
    },
    {
      "slug": "netsuite/default-deny-unknown-tools",
      "name": "NetSuite Default-Deny Unknown MCP Tools",
      "summary": "Pins an allowlist of the audited NetSuite MCP Standard Tools and denies every other tool call before it reaches the NetSuite AI Connector.",
      "url": "https://www.intentbasedpolicy.com/policies/netsuite/default-deny-unknown-tools",
      "markdown": "https://www.intentbasedpolicy.com/policies/netsuite/default-deny-unknown-tools.md",
      "app": "netsuite",
      "apps": [
        "netsuite"
      ],
      "bundles": [
        "soc2"
      ],
      "tags": [
        "netsuite",
        "default-deny-unknown-tools",
        "allowlist",
        "access-control",
        "ingress",
        "soc2"
      ],
      "direction": "ingress",
      "package": "netsuite.ingress.default_deny_unknown_tools",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:9b92fe238a5ea4518b7e9a3c430ee3c82651d92a46e6191c97c06c198187a5e7",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/netsuite/default-deny-unknown-tools",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/netsuite/default-deny-unknown-tools/policy.md"
    },
    {
      "slug": "netsuite/guard-vendor-banking",
      "name": "NetSuite Guard Vendor Banking Edits (Anti-BEC)",
      "summary": "Instantiates policy family PF-10 (guard-vendor-banking) — the anti-BEC / payment-fraud control — for the Oracle NetSuite MCP Standard Tools SuiteApp.",
      "url": "https://www.intentbasedpolicy.com/policies/netsuite/guard-vendor-banking",
      "markdown": "https://www.intentbasedpolicy.com/policies/netsuite/guard-vendor-banking.md",
      "app": "netsuite",
      "apps": [
        "netsuite"
      ],
      "bundles": [
        "sox"
      ],
      "tags": [
        "netsuite",
        "guard-vendor-banking",
        "ingress",
        "sox"
      ],
      "direction": "ingress",
      "package": "netsuite.ingress.guard_vendor_banking",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:e57b283c5527c15d415e8dde5d895e90eacc21f8f696c3847f2fa46c24f02773",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/netsuite/guard-vendor-banking",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/netsuite/guard-vendor-banking/policy.md"
    },
    {
      "slug": "netsuite/redact-financial-pii",
      "name": "NetSuite: Redact Financial PII in Responses",
      "summary": "Instantiates PF-02 (redact-pii-egress) on the NetSuite read path.",
      "url": "https://www.intentbasedpolicy.com/policies/netsuite/redact-financial-pii",
      "markdown": "https://www.intentbasedpolicy.com/policies/netsuite/redact-financial-pii.md",
      "app": "netsuite",
      "apps": [
        "netsuite"
      ],
      "bundles": [
        "gdpr-ccpa",
        "soc2"
      ],
      "tags": [
        "netsuite",
        "redact-pii",
        "pii",
        "financial-pii",
        "dlp",
        "redaction",
        "egress",
        "gdpr-ccpa",
        "soc2"
      ],
      "direction": "egress",
      "package": "netsuite.egress.redact_financial_pii",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:c06ff13ad8013810410e74dbf7bd7c335fc0696e4c4a5ad71fec7f365b50e2ec",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/netsuite/redact-financial-pii",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/netsuite/redact-financial-pii/policy.md"
    },
    {
      "slug": "notion/redact-pii-egress",
      "name": "Notion: Redact PII from Read Responses",
      "summary": "Scans the responses of the Notion hosted MCP server's content-returning read tools and rewrites personally identifiable information to fixed redaction tokens…",
      "url": "https://www.intentbasedpolicy.com/policies/notion/redact-pii-egress",
      "markdown": "https://www.intentbasedpolicy.com/policies/notion/redact-pii-egress.md",
      "app": "notion",
      "apps": [
        "notion"
      ],
      "bundles": [
        "soc2",
        "hipaa",
        "gdpr-ccpa"
      ],
      "tags": [
        "notion",
        "redact-pii",
        "pii",
        "dlp",
        "redaction",
        "egress",
        "soc2",
        "hipaa",
        "gdpr-ccpa"
      ],
      "direction": "egress",
      "package": "notion.egress.redact_pii",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:740c4d7b4e0dd9bf1ed71b4fb9a13b5e8baebe1d2d9a32eea7e26519a16e60f4",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/notion/redact-pii-egress",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/notion/redact-pii-egress/policy.md"
    },
    {
      "slug": "power-bi/redact-pii-dax-results",
      "name": "Power BI: Redact PII in Query Results",
      "summary": "Scans the content returned by Power BI's result-returning tools and rewrites high-confidence PII shapes to fixed, non-recoverable redaction tokens before the…",
      "url": "https://www.intentbasedpolicy.com/policies/power-bi/redact-pii-dax-results",
      "markdown": "https://www.intentbasedpolicy.com/policies/power-bi/redact-pii-dax-results.md",
      "app": "power-bi",
      "apps": [
        "power-bi"
      ],
      "bundles": [
        "soc2",
        "gdpr-ccpa"
      ],
      "tags": [
        "power-bi",
        "redact-pii",
        "pii",
        "dlp",
        "dax",
        "redaction",
        "egress",
        "soc2",
        "gdpr-ccpa"
      ],
      "direction": "egress",
      "package": "power_bi.egress.redact_pii_dax_results",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:f68601dc08830d14a8c7f9062bbc9d802062e6fafaf92a1fe0eab9724ddea616",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/power-bi/redact-pii-dax-results",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/power-bi/redact-pii-dax-results/policy.md"
    },
    {
      "slug": "github/deny-public-exposure-repos",
      "name": "Prevent Public Exposure of GitHub Repos, Gists & Forks",
      "summary": "Stops the agent from exposing private code to the public across three GitHub write tools, at ingress — before the call reaches the GitHub MCP server, so a…",
      "url": "https://www.intentbasedpolicy.com/policies/github/deny-public-exposure-repos",
      "markdown": "https://www.intentbasedpolicy.com/policies/github/deny-public-exposure-repos.md",
      "app": "github",
      "apps": [
        "github"
      ],
      "bundles": [
        "soc2"
      ],
      "tags": [
        "github",
        "deny-public-exposure",
        "anti-exfil",
        "ingress",
        "soc2",
        "finserv-comms",
        "eu-ai-act"
      ],
      "direction": "ingress",
      "package": "github.ingress.deny_public_exposure_repos",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:7de86c061b5fe9c21fb3c8f21cabcb58ebf6722626bb94e7ed1625b1ce955722",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/github/deny-public-exposure-repos",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/github/deny-public-exposure-repos/policy.md"
    },
    {
      "slug": "netsuite/protect-closed-periods",
      "name": "Protect Financial Postings by Role",
      "summary": "Denies the NetSuite record-write tools ns createRecord and ns updateRecord when they target a financial-transaction record type — journalentry (including the…",
      "url": "https://www.intentbasedpolicy.com/policies/netsuite/protect-closed-periods",
      "markdown": "https://www.intentbasedpolicy.com/policies/netsuite/protect-closed-periods.md",
      "app": "netsuite",
      "apps": [
        "netsuite"
      ],
      "bundles": [
        "sox"
      ],
      "tags": [
        "netsuite",
        "protect-closed-periods",
        "ingress",
        "sox"
      ],
      "direction": "ingress",
      "package": "netsuite.ingress.protect_closed_periods",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:4010ae3f1f5bafaeda7f856b089797c98ab25c71ce356481506c305aef54dfa8",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/netsuite/protect-closed-periods",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/netsuite/protect-closed-periods/policy.md"
    },
    {
      "slug": "quickbooks/redact-pii-egress-employee",
      "name": "QuickBooks: Redact Employee & Vendor PII on Read",
      "summary": "On the read path, this policy masks sensitive identifiers in the responses of four QuickBooks Online (QBO) name-entity read tools — get employee, search…",
      "url": "https://www.intentbasedpolicy.com/policies/quickbooks/redact-pii-egress-employee",
      "markdown": "https://www.intentbasedpolicy.com/policies/quickbooks/redact-pii-egress-employee.md",
      "app": "quickbooks",
      "apps": [
        "quickbooks"
      ],
      "bundles": [
        "gdpr-ccpa",
        "soc2"
      ],
      "tags": [
        "quickbooks",
        "redact-pii",
        "pii",
        "redaction",
        "dlp",
        "egress",
        "gdpr-ccpa",
        "soc2"
      ],
      "direction": "egress",
      "package": "quickbooks.egress.redact_pii_employee",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:c230342974dea58a06eeb8ae97b238179521b1a3ce59c2c22e9867dd9a793b2f",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/quickbooks/redact-pii-egress-employee",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/quickbooks/redact-pii-egress-employee/policy.md"
    },
    {
      "slug": "ms365/role-gate-writes",
      "name": "Read-Only Baseline: Group-Gated Microsoft 365 Writes",
      "summary": "The least-privilege baseline for Microsoft 365 through the gateway: every tool call is allowed only if it is a read , or the caller's IdP token carries the…",
      "url": "https://www.intentbasedpolicy.com/policies/ms365/role-gate-writes",
      "markdown": "https://www.intentbasedpolicy.com/policies/ms365/role-gate-writes.md",
      "app": "ms365",
      "apps": [
        "ms365"
      ],
      "bundles": [
        "soc2",
        "gdpr-ccpa",
        "sox"
      ],
      "tags": [
        "ms365",
        "role-gate-writes",
        "ingress",
        "least-privilege",
        "soc2",
        "gdpr-ccpa",
        "sox"
      ],
      "direction": "ingress",
      "package": "ms365.ingress.role_gate_writes",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:020cb78240c9e17de27002cd9d2d1147f9822645550709d9ff2bd494a2f67c78",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/ms365/role-gate-writes",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/ms365/role-gate-writes/policy.md"
    },
    {
      "slug": "github/role-gate-writes-engineering",
      "name": "Read-Only GitHub for Non-Engineers",
      "summary": "Establishes the least-privilege baseline for the GitHub MCP connector on the agent channel.",
      "url": "https://www.intentbasedpolicy.com/policies/github/role-gate-writes-engineering",
      "markdown": "https://www.intentbasedpolicy.com/policies/github/role-gate-writes-engineering.md",
      "app": "github",
      "apps": [
        "github"
      ],
      "bundles": [
        "soc2",
        "sox"
      ],
      "tags": [
        "github",
        "role-gate-writes",
        "ingress",
        "soc2",
        "sox"
      ],
      "direction": "ingress",
      "package": "github.ingress.role_gate_writes_engineering",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:298231c9480137bc89f70d5708ca8650a20bd01da91a16475c2d6c73c880f425",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/github/role-gate-writes-engineering",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/github/role-gate-writes-engineering/policy.md"
    },
    {
      "slug": "stripe/role-gate-writes-billing",
      "name": "Read-Only Stripe by Default (Role-Gate Billing Writes)",
      "summary": "Establishes a read-only-by-default Stripe posture over the MCP path. The named write and destructive billing tools —",
      "url": "https://www.intentbasedpolicy.com/policies/stripe/role-gate-writes-billing",
      "markdown": "https://www.intentbasedpolicy.com/policies/stripe/role-gate-writes-billing.md",
      "app": "stripe",
      "apps": [
        "stripe"
      ],
      "bundles": [
        "soc2",
        "pci-dss",
        "sox",
        "gdpr-ccpa"
      ],
      "tags": [
        "stripe",
        "role-gate-writes",
        "ingress",
        "least-privilege",
        "rbac",
        "soc2",
        "pci-dss",
        "sox",
        "gdpr-ccpa"
      ],
      "direction": "ingress",
      "package": "stripe.ingress.role_gate_writes",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:39f42427691ac49396db200c521de055b6091fe155b8d33c1e0b8ea83e20125b",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/stripe/role-gate-writes-billing",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/stripe/role-gate-writes-billing/policy.md"
    },
    {
      "slug": "google-calendar/redact-attendee-pii",
      "name": "Redact Attendee PII and Meeting Links in Calendar Reads",
      "summary": "Scrubs sensitive fields from the responses of Google Calendar read tools before they reach the agent, for callers who lack the placeholder calendar-full-read…",
      "url": "https://www.intentbasedpolicy.com/policies/google-calendar/redact-attendee-pii",
      "markdown": "https://www.intentbasedpolicy.com/policies/google-calendar/redact-attendee-pii.md",
      "app": "google-calendar",
      "apps": [
        "google-calendar"
      ],
      "bundles": [
        "soc2",
        "hipaa",
        "gdpr-ccpa"
      ],
      "tags": [
        "google-calendar",
        "redact-pii",
        "pii",
        "phi",
        "dlp",
        "redaction",
        "egress",
        "soc2",
        "hipaa",
        "gdpr-ccpa"
      ],
      "direction": "egress",
      "package": "google_calendar.egress.redact_attendee_pii",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:915129cd94fef27c4fc7a88e9ebc024996de582aa6d4639bab2f6be3a2ad7a33",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/google-calendar/redact-attendee-pii",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/google-calendar/redact-attendee-pii/policy.md"
    },
    {
      "slug": "onboarding/redact-email",
      "name": "Redact Email PII",
      "summary": "This policy automatically masks email addresses in what a tool sends back, replacing each one with [REDACTED] before your agent ever sees it.",
      "url": "https://www.intentbasedpolicy.com/policies/onboarding/redact-email",
      "markdown": "https://www.intentbasedpolicy.com/policies/onboarding/redact-email.md",
      "app": "onboarding",
      "apps": [
        "onboarding"
      ],
      "bundles": [],
      "tags": [
        "onboarding",
        "pii",
        "email",
        "dlp",
        "redaction",
        "egress"
      ],
      "direction": "egress",
      "package": "onboarding.egress.redact_email",
      "publishedAt": "2026-07-23",
      "policyChecksum": "sha256:fba1ca0fb65b6922cf51c1eacfb707b69129e565302ac4763d3806d9f7750c3e",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/onboarding/redact-email",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/onboarding/redact-email/policy.md"
    },
    {
      "slug": "github/require-human-approval-merge",
      "name": "Require Human Approval: GitHub Merges & Approvals",
      "summary": "Keeps a human in the loop on the two GitHub actions that consummate a code change: merging a pull request and approving one .",
      "url": "https://www.intentbasedpolicy.com/policies/github/require-human-approval-merge",
      "markdown": "https://www.intentbasedpolicy.com/policies/github/require-human-approval-merge.md",
      "app": "github",
      "apps": [
        "github"
      ],
      "bundles": [
        "soc2",
        "sox"
      ],
      "tags": [
        "github",
        "require-human-approval",
        "ingress",
        "soc2",
        "sox"
      ],
      "direction": "ingress",
      "package": "github.ingress.require_human_approval_merge",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:3e04fb6019dbed04d17cb58263e0a49d8b01a509798e055ff6877bc558ac0a37",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/github/require-human-approval-merge",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/github/require-human-approval-merge/policy.md"
    },
    {
      "slug": "zapier/role-gate-writes",
      "name": "Role-Gate All Zapier Writes",
      "summary": "Zapier MCP is an aggregator: one connector proxies actions across 9,000+ apps, and every create/update/delete/send funnels through a small, predictable…",
      "url": "https://www.intentbasedpolicy.com/policies/zapier/role-gate-writes",
      "markdown": "https://www.intentbasedpolicy.com/policies/zapier/role-gate-writes.md",
      "app": "zapier",
      "apps": [
        "zapier"
      ],
      "bundles": [
        "soc2",
        "gdpr-ccpa"
      ],
      "tags": [
        "zapier",
        "role-gate-writes",
        "ingress",
        "soc2",
        "gdpr-ccpa"
      ],
      "direction": "ingress",
      "package": "zapier.ingress.role_gate_writes",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:0657060c12f34db60b571c536cbb01c3687297054dda09015fc9d7c175e8aece",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/zapier/role-gate-writes",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/zapier/role-gate-writes/policy.md"
    },
    {
      "slug": "dropbox/role-gate-writes",
      "name": "Role-Gate Dropbox Writes to the Writers Group",
      "summary": "Establishes the per-app least-privilege write floor for Dropbox.",
      "url": "https://www.intentbasedpolicy.com/policies/dropbox/role-gate-writes",
      "markdown": "https://www.intentbasedpolicy.com/policies/dropbox/role-gate-writes.md",
      "app": "dropbox",
      "apps": [
        "dropbox"
      ],
      "bundles": [
        "soc2",
        "gdpr-ccpa"
      ],
      "tags": [
        "dropbox",
        "role-gate-writes",
        "rbac",
        "least-privilege",
        "ingress",
        "soc2",
        "gdpr-ccpa"
      ],
      "direction": "ingress",
      "package": "dropbox.ingress.role_gate_writes",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:44b33582ffce15781a7162dbd4e365dc45a16c43e986adea9363546bb9fc858f",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/dropbox/role-gate-writes",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/dropbox/role-gate-writes/policy.md"
    },
    {
      "slug": "salesforce/cap-bulk-export",
      "name": "Salesforce Cap Bulk Data Export",
      "summary": "Blocks bulk PII extraction through Salesforce query tools by inspecting the free-text query arguments that are the real policy surface for these servers.",
      "url": "https://www.intentbasedpolicy.com/policies/salesforce/cap-bulk-export",
      "markdown": "https://www.intentbasedpolicy.com/policies/salesforce/cap-bulk-export.md",
      "app": "salesforce",
      "apps": [
        "salesforce"
      ],
      "bundles": [
        "crm",
        "soc2",
        "hipaa",
        "pci-dss",
        "gdpr-ccpa"
      ],
      "tags": [
        "salesforce",
        "cap-bulk-export",
        "data-minimization",
        "dlp",
        "ingress",
        "soc2",
        "hipaa",
        "pci-dss",
        "gdpr-ccpa"
      ],
      "direction": "ingress",
      "package": "salesforce.ingress.cap_bulk_export",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:753cf879feab22a8813df3861a2c69f898289c594370b2d06457d2e73c09f1cc",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/salesforce/cap-bulk-export",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/salesforce/cap-bulk-export/policy.md"
    },
    {
      "slug": "salesforce/deny-escape-hatches",
      "name": "Salesforce Deny API Escape Hatches",
      "summary": "Unconditionally denies the raw-code and raw-API tools exposed by the community Salesforce MCP servers — tools that bypass every object- and argument-level…",
      "url": "https://www.intentbasedpolicy.com/policies/salesforce/deny-escape-hatches",
      "markdown": "https://www.intentbasedpolicy.com/policies/salesforce/deny-escape-hatches.md",
      "app": "salesforce",
      "apps": [
        "salesforce"
      ],
      "bundles": [
        "crm",
        "soc2"
      ],
      "tags": [
        "salesforce",
        "deny-escape-hatches",
        "access-control",
        "ingress",
        "soc2",
        "iso27001-nist"
      ],
      "direction": "ingress",
      "package": "salesforce.ingress.deny_escape_hatches",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:630222fe3a10df15f5f4e62cbb8f0e820a4a311c6a70924ff17686078d0d6f3d",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/salesforce/deny-escape-hatches",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/salesforce/deny-escape-hatches/policy.md"
    },
    {
      "slug": "salesforce/guard-opportunity-pipeline",
      "name": "Salesforce Guard Opportunity Pipeline Fields",
      "summary": "Keeps revenue-pipeline moves human-approved.",
      "url": "https://www.intentbasedpolicy.com/policies/salesforce/guard-opportunity-pipeline",
      "markdown": "https://www.intentbasedpolicy.com/policies/salesforce/guard-opportunity-pipeline.md",
      "app": "salesforce",
      "apps": [
        "salesforce"
      ],
      "bundles": [
        "crm"
      ],
      "tags": [
        "salesforce",
        "opportunity",
        "pipeline",
        "revenue",
        "human-approval",
        "access-control",
        "governance",
        "ingress"
      ],
      "direction": "ingress",
      "package": "salesforce.ingress.guard_opportunity_pipeline",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:92b4111bcfd5fade1e78e5600bffbebaccb0d78b7f7dcd3f3c431a98fd895721",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/salesforce/guard-opportunity-pipeline",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/salesforce/guard-opportunity-pipeline/policy.md"
    },
    {
      "slug": "salesforce/protect-contact-fields",
      "name": "Salesforce Protect Contact Fields",
      "summary": "Blocks Salesforce Contact updates that modify protected fields — ownership, account linkage, contact PII, name, and consent flags.",
      "url": "https://www.intentbasedpolicy.com/policies/salesforce/protect-contact-fields",
      "markdown": "https://www.intentbasedpolicy.com/policies/salesforce/protect-contact-fields.md",
      "app": "salesforce",
      "apps": [
        "salesforce"
      ],
      "bundles": [
        "crm",
        "soc2",
        "gdpr-ccpa"
      ],
      "tags": [
        "salesforce",
        "contacts",
        "pii",
        "access-control",
        "governance",
        "ingress",
        "soc2",
        "gdpr-ccpa",
        "iso27001-nist"
      ],
      "direction": "ingress",
      "package": "salesforce.ingress.protect_contact_fields",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:79693cf553dae7659bbe8832bab9932b5d07f693437d06c7433d396c3a5b053f",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/salesforce/protect-contact-fields",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/salesforce/protect-contact-fields/policy.md"
    },
    {
      "slug": "salesforce/query-allowlist",
      "name": "Salesforce Query Allowlist",
      "summary": "Restricts Salesforce SOQL queries so only Account, Contact, and Opportunity records can be retrieved.",
      "url": "https://www.intentbasedpolicy.com/policies/salesforce/query-allowlist",
      "markdown": "https://www.intentbasedpolicy.com/policies/salesforce/query-allowlist.md",
      "app": "salesforce",
      "apps": [
        "salesforce"
      ],
      "bundles": [
        "crm",
        "soc2",
        "pci-dss",
        "gdpr-ccpa"
      ],
      "tags": [
        "salesforce",
        "access-control",
        "data-protection",
        "governance",
        "ingress",
        "soc2",
        "pci-dss",
        "gdpr-ccpa",
        "iso27001-nist"
      ],
      "direction": "ingress",
      "package": "salesforce.ingress.query_allowlist",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:ff472238e1c75b0a9ecb1fd117ec46f104765f2b6c9b180755de142db1385c36",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/salesforce/query-allowlist",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/salesforce/query-allowlist/policy.md"
    },
    {
      "slug": "salesforce/read-only",
      "name": "Salesforce Read-Only Access",
      "summary": "Restricts the Salesforce MCP server to read-only access.",
      "url": "https://www.intentbasedpolicy.com/policies/salesforce/read-only",
      "markdown": "https://www.intentbasedpolicy.com/policies/salesforce/read-only.md",
      "app": "salesforce",
      "apps": [
        "salesforce"
      ],
      "bundles": [
        "crm",
        "soc2",
        "gdpr-ccpa"
      ],
      "tags": [
        "salesforce",
        "access-control",
        "governance",
        "read-only",
        "ingress",
        "soc2",
        "gdpr-ccpa",
        "iso27001-nist"
      ],
      "direction": "ingress",
      "package": "salesforce.ingress.readonly",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:e66f0db4e835bc2684182230aea05bed5200658e4db8b81f27ffaa8134e5e696",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/salesforce/read-only",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/salesforce/read-only/policy.md"
    },
    {
      "slug": "salesforce/redact-pii",
      "name": "Salesforce Redact PII",
      "summary": "Redacts personal contact information from Salesforce tool responses before they reach the caller.",
      "url": "https://www.intentbasedpolicy.com/policies/salesforce/redact-pii",
      "markdown": "https://www.intentbasedpolicy.com/policies/salesforce/redact-pii.md",
      "app": "salesforce",
      "apps": [
        "salesforce"
      ],
      "bundles": [
        "crm",
        "soc2",
        "hipaa",
        "gdpr-ccpa"
      ],
      "tags": [
        "salesforce",
        "pii",
        "dlp",
        "redaction",
        "egress",
        "soc2",
        "hipaa",
        "gdpr-ccpa",
        "iso27001-nist"
      ],
      "direction": "egress",
      "package": "salesforce.egress.pii_redaction",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:c3aa10e98fcac51fcdab8d099177f8e0d2275eb0251313d68e7fb992d091bed3",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/salesforce/redact-pii",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/salesforce/redact-pii/policy.md"
    },
    {
      "slug": "salesforce/role-gate-writes",
      "name": "Salesforce Role-Gated Writes",
      "summary": "The PF-12 least-privilege baseline for Salesforce.",
      "url": "https://www.intentbasedpolicy.com/policies/salesforce/role-gate-writes",
      "markdown": "https://www.intentbasedpolicy.com/policies/salesforce/role-gate-writes.md",
      "app": "salesforce",
      "apps": [
        "salesforce"
      ],
      "bundles": [
        "crm",
        "soc2",
        "gdpr-ccpa"
      ],
      "tags": [
        "salesforce",
        "role-gate-writes",
        "access-control",
        "least-privilege",
        "ingress",
        "soc2",
        "gdpr-ccpa",
        "crm"
      ],
      "direction": "ingress",
      "package": "salesforce.ingress.role_gate_writes",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:f6a3629281e1c6de82ae9db52a2fb2d03943a6df4fb4659529823c3a6552545b",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/salesforce/role-gate-writes",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/salesforce/role-gate-writes/policy.md"
    },
    {
      "slug": "stripe/guard-share-links-payment-redirect",
      "name": "Scrub Unapproved Stripe Payment-Link Redirects",
      "summary": "Scrubs the post-payment redirect from Stripe payment-link creation calls.",
      "url": "https://www.intentbasedpolicy.com/policies/stripe/guard-share-links-payment-redirect",
      "markdown": "https://www.intentbasedpolicy.com/policies/stripe/guard-share-links-payment-redirect.md",
      "app": "stripe",
      "apps": [
        "stripe"
      ],
      "bundles": [
        "soc2"
      ],
      "tags": [
        "stripe",
        "guard-share-links",
        "ingress",
        "transform",
        "phishing",
        "prompt-injection",
        "soc2"
      ],
      "direction": "ingress",
      "package": "stripe.ingress.guard_share_links_payment_redirect",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:0df7ad01ffa897fded9286af4728915b8c638d499ab8f0378b7319cac2fae8e1",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/stripe/guard-share-links-payment-redirect",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/stripe/guard-share-links-payment-redirect/policy.md"
    },
    {
      "slug": "servicenow/role-gate-writes",
      "name": "ServiceNow: Role-Gated Writes (Read-Only Default)",
      "summary": "else fails closed",
      "url": "https://www.intentbasedpolicy.com/policies/servicenow/role-gate-writes",
      "markdown": "https://www.intentbasedpolicy.com/policies/servicenow/role-gate-writes.md",
      "app": "servicenow",
      "apps": [
        "servicenow"
      ],
      "bundles": [
        "soc2",
        "gdpr-ccpa"
      ],
      "tags": [
        "servicenow",
        "role-gate-writes",
        "access-control",
        "least-privilege",
        "ingress",
        "soc2",
        "gdpr-ccpa"
      ],
      "direction": "ingress",
      "package": "servicenow.ingress.role_gate_writes",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:ac9628e829a7ad715c2727faa87da59d15a8be121c2f3d400495a512fa4bca08",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/servicenow/role-gate-writes",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/servicenow/role-gate-writes/policy.md"
    },
    {
      "slug": "slack/role-gate-writes",
      "name": "Slack Role-Gate Writes",
      "summary": "Gates every Slack write-class tool behind an IdP group: callers whose JWT groups claim contains slack-writers may send and schedule messages, add or remove…",
      "url": "https://www.intentbasedpolicy.com/policies/slack/role-gate-writes",
      "markdown": "https://www.intentbasedpolicy.com/policies/slack/role-gate-writes.md",
      "app": "slack",
      "apps": [
        "slack"
      ],
      "bundles": [
        "slack",
        "im-messaging",
        "soc2",
        "gdpr-ccpa"
      ],
      "tags": [
        "slack",
        "role-gate-writes",
        "access-control",
        "least-privilege",
        "ingress",
        "soc2",
        "gdpr-ccpa"
      ],
      "direction": "ingress",
      "package": "slack.ingress.role_gate_writes",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:bb893589a6e31ab1f70160613c91bd3563e3f9d340abf3342ff94d559fa7332c",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/slack/role-gate-writes",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/slack/role-gate-writes/policy.md"
    },
    {
      "slug": "slack/guard-external-send",
      "name": "Slack: Block Agent Posts to External Channels",
      "summary": "Denies Slack message-write calls whose destination is an externally shared Slack Connect channel.",
      "url": "https://www.intentbasedpolicy.com/policies/slack/guard-external-send",
      "markdown": "https://www.intentbasedpolicy.com/policies/slack/guard-external-send.md",
      "app": "slack",
      "apps": [
        "slack"
      ],
      "bundles": [
        "slack",
        "im-messaging",
        "soc2",
        "gdpr-ccpa",
        "hipaa"
      ],
      "tags": [
        "slack",
        "guard-external-send",
        "slack-connect",
        "exfiltration",
        "ingress",
        "soc2",
        "gdpr-ccpa",
        "hipaa"
      ],
      "direction": "ingress",
      "package": "slack.ingress.guard_external_send",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:20bb4016d45d71e715bcae9d6a676755e87039d26fcca827c1fc14e451b6a5a2",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/slack/guard-external-send",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/slack/guard-external-send/policy.md"
    },
    {
      "slug": "slack/deny-channel-creation",
      "name": "Slack: Deny Channel Creation",
      "summary": "Blocks Slack channel-creation tool calls at ingress. Every other Slack tool — and every non-Slack tool — passes through untouched.",
      "url": "https://www.intentbasedpolicy.com/policies/slack/deny-channel-creation",
      "markdown": "https://www.intentbasedpolicy.com/policies/slack/deny-channel-creation.md",
      "app": "slack",
      "apps": [
        "slack"
      ],
      "bundles": [
        "slack",
        "soc2"
      ],
      "tags": [
        "slack",
        "access-control",
        "governance",
        "ingress",
        "soc2",
        "iso27001-nist"
      ],
      "direction": "ingress",
      "package": "slack.ingress.deny_channel_create",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:613c04806d02f35c3cf0f7aa2d2223c5cc91504186e14d62332a1cb019b72f2b",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/slack/deny-channel-creation",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/slack/deny-channel-creation/policy.md"
    },
    {
      "slug": "slack/guard-dm-privacy",
      "name": "Slack: Deny DM and Private-Conversation Reads and Search",
      "summary": "Denies the agent read reach into Slack DMs and private conversations on the paths below — the workspace's highest concentration of PII/PHI (HR issues, health…",
      "url": "https://www.intentbasedpolicy.com/policies/slack/guard-dm-privacy",
      "markdown": "https://www.intentbasedpolicy.com/policies/slack/guard-dm-privacy.md",
      "app": "slack",
      "apps": [
        "slack"
      ],
      "bundles": [
        "soc2",
        "gdpr-ccpa"
      ],
      "tags": [
        "slack",
        "privacy",
        "dm",
        "access-control",
        "ingress",
        "soc2",
        "gdpr-ccpa"
      ],
      "direction": "ingress",
      "package": "slack.ingress.guard_dm_privacy",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:0c759aa4beabbeace568b66ab311bf1e1d5b305ceb521e898868e53035d25397",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/slack/guard-dm-privacy",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/slack/guard-dm-privacy/policy.md"
    },
    {
      "slug": "slack/deny-read-search-summarize-sensitive-channels",
      "name": "Slack: Deny Read/Search/Summarize of Sensitive Channels",
      "summary": "Blocks read, search, and summarize operations that target a configurable set of \"sensitive\" Slack channels.",
      "url": "https://www.intentbasedpolicy.com/policies/slack/deny-read-search-summarize-sensitive-channels",
      "markdown": "https://www.intentbasedpolicy.com/policies/slack/deny-read-search-summarize-sensitive-channels.md",
      "app": "slack",
      "apps": [
        "slack"
      ],
      "bundles": [
        "slack",
        "soc2",
        "hipaa",
        "gdpr-ccpa"
      ],
      "tags": [
        "slack",
        "access-control",
        "data-protection",
        "ingress",
        "soc2",
        "hipaa",
        "gdpr-ccpa",
        "iso27001-nist"
      ],
      "direction": "ingress",
      "package": "slack.ingress.deny_sensitive_channel_read",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:be0ecf31a6f6908191cd28f537364984fc5771a0c39a9990d141094155b8e47b",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/slack/deny-read-search-summarize-sensitive-channels",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/slack/deny-read-search-summarize-sensitive-channels/policy.md"
    },
    {
      "slug": "slack/deny-direct-messages",
      "name": "Slack: Deny Sending Direct Messages",
      "summary": "Blocks Slack message-write calls whose destination resolves to a direct conversation — a 1:1 DM, a message posted to a user ID (which Slack auto-opens as a…",
      "url": "https://www.intentbasedpolicy.com/policies/slack/deny-direct-messages",
      "markdown": "https://www.intentbasedpolicy.com/policies/slack/deny-direct-messages.md",
      "app": "slack",
      "apps": [
        "slack"
      ],
      "bundles": [
        "slack",
        "soc2"
      ],
      "tags": [
        "slack",
        "access-control",
        "governance",
        "ingress",
        "soc2",
        "iso27001-nist",
        "finserv-comms"
      ],
      "direction": "ingress",
      "package": "slack.ingress.deny_direct_messages",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:3bfcfdee14c1d8409123990b850b96ce507d93079e026b7c7d179b161c353910",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/slack/deny-direct-messages",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/slack/deny-direct-messages/policy.md"
    },
    {
      "slug": "slack/mask-pan-egress",
      "name": "Slack: Mask Card Numbers in Message and Search Responses",
      "summary": "Masks payment-card numbers (PANs) in Slack content returned to agents by message-read, thread-read, canvas-read, history, and search tools.",
      "url": "https://www.intentbasedpolicy.com/policies/slack/mask-pan-egress",
      "markdown": "https://www.intentbasedpolicy.com/policies/slack/mask-pan-egress.md",
      "app": "slack",
      "apps": [
        "slack"
      ],
      "bundles": [
        "pci-dss",
        "soc2",
        "gdpr-ccpa"
      ],
      "tags": [
        "slack",
        "mask-pan-egress",
        "egress",
        "cardholder-data",
        "dlp",
        "pci-dss",
        "soc2",
        "gdpr-ccpa"
      ],
      "direction": "egress",
      "package": "slack.egress.mask_pan",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:c4fae168cd7ce400dbbd42fdb66e17f2eb4c80ce9bc6af8eb502502ab8a417fd",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/slack/mask-pan-egress",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/slack/mask-pan-egress/policy.md"
    },
    {
      "slug": "slack/redact-profile-pii",
      "name": "Slack: Redact Profile PII from User Lookups",
      "summary": "Redacts personally identifiable information — email addresses, phone numbers, and Slack custom profile fields (which commonly carry phone, title, and…",
      "url": "https://www.intentbasedpolicy.com/policies/slack/redact-profile-pii",
      "markdown": "https://www.intentbasedpolicy.com/policies/slack/redact-profile-pii.md",
      "app": "slack",
      "apps": [
        "slack"
      ],
      "bundles": [
        "slack",
        "soc2",
        "gdpr-ccpa"
      ],
      "tags": [
        "slack",
        "pii",
        "redaction",
        "privacy",
        "egress",
        "soc2",
        "gdpr-ccpa"
      ],
      "direction": "egress",
      "package": "slack.egress.redact_profile_pii",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:bd0befc2d1cabab7a7758095cedce3349e10bdf79e7a59b069fc9c2a7877c3ce",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/slack/redact-profile-pii",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/slack/redact-profile-pii/policy.md"
    },
    {
      "slug": "slack/redact-sensitive-info",
      "name": "Slack: Redact Sensitive Information from Messages",
      "summary": "Redacts sensitive content from outgoing Slack message arguments before the call reaches Slack.",
      "url": "https://www.intentbasedpolicy.com/policies/slack/redact-sensitive-info",
      "markdown": "https://www.intentbasedpolicy.com/policies/slack/redact-sensitive-info.md",
      "app": "slack",
      "apps": [
        "slack"
      ],
      "bundles": [
        "slack",
        "soc2",
        "hipaa",
        "gdpr-ccpa"
      ],
      "tags": [
        "slack",
        "pii",
        "secrets",
        "dlp",
        "redaction",
        "ingress",
        "soc2",
        "hipaa",
        "gdpr-ccpa",
        "iso27001-nist"
      ],
      "direction": "ingress",
      "package": "slack.ingress.redact_sensitive_info",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:77ad4d9fd33a830df6c976a3dbcb351e9774b652e48deaf1dd8b84727786679e",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/slack/redact-sensitive-info",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/slack/redact-sensitive-info/policy.md"
    },
    {
      "slug": "snowflake/default-deny-unknown-tools",
      "name": "Snowflake Default-Deny Unknown Tools",
      "summary": "Pins an allowlist of the exact Snowflake tool names your team audited and denies every other tool name on the Snowflake MCP server(s).",
      "url": "https://www.intentbasedpolicy.com/policies/snowflake/default-deny-unknown-tools",
      "markdown": "https://www.intentbasedpolicy.com/policies/snowflake/default-deny-unknown-tools.md",
      "app": "snowflake",
      "apps": [
        "snowflake"
      ],
      "bundles": [
        "soc2"
      ],
      "tags": [
        "snowflake",
        "default-deny-unknown-tools",
        "allowlist",
        "access-control",
        "ingress",
        "soc2"
      ],
      "direction": "ingress",
      "package": "snowflake.ingress.default_deny_unknown_tools",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:ff272d6c69a9a9852b60e3a41193943b46bdf5b682d08ee3df9415f35c06f57b",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/snowflake/default-deny-unknown-tools",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/snowflake/default-deny-unknown-tools/policy.md"
    },
    {
      "slug": "snowflake/deny-composite-cortex-tools",
      "name": "Snowflake Deny Composite & Generic Tools",
      "summary": "Denies the opaque composite and generic passthrough tools on the Snowflake-managed MCP server whose execution the gateway cannot inspect one SQL statement at…",
      "url": "https://www.intentbasedpolicy.com/policies/snowflake/deny-composite-cortex-tools",
      "markdown": "https://www.intentbasedpolicy.com/policies/snowflake/deny-composite-cortex-tools.md",
      "app": "snowflake",
      "apps": [
        "snowflake"
      ],
      "bundles": [
        "soc2"
      ],
      "tags": [
        "snowflake",
        "deny-escape-hatches",
        "access-control",
        "cortex",
        "ingress",
        "soc2",
        "iso27001-nist"
      ],
      "direction": "ingress",
      "package": "snowflake.ingress.deny_composite_cortex_tools",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:965a2a47eacbde0b05c7b5877447a1c46009d02440a91f445586562e70c0cc93",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/snowflake/deny-composite-cortex-tools",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/snowflake/deny-composite-cortex-tools/policy.md"
    },
    {
      "slug": "snowflake/redact-pii-egress",
      "name": "Snowflake: Redact PII from Query Result Sets",
      "summary": "Scans the row content returned by the result-returning Snowflake MCP tools and rewrites personally identifiable information to fixed redaction tokens before…",
      "url": "https://www.intentbasedpolicy.com/policies/snowflake/redact-pii-egress",
      "markdown": "https://www.intentbasedpolicy.com/policies/snowflake/redact-pii-egress.md",
      "app": "snowflake",
      "apps": [
        "snowflake"
      ],
      "bundles": [
        "soc2",
        "hipaa",
        "gdpr-ccpa"
      ],
      "tags": [
        "snowflake",
        "redact-pii",
        "pii",
        "dlp",
        "redaction",
        "egress",
        "soc2",
        "hipaa",
        "gdpr-ccpa"
      ],
      "direction": "egress",
      "package": "snowflake.egress.redact_pii",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:9b4f812a96166fad6d9aa9543a5cbe61f03dbd080de385fa5596e0e91232f8b6",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/snowflake/redact-pii-egress",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/snowflake/redact-pii-egress/policy.md"
    },
    {
      "slug": "stripe/gate-money-movement-refund-cap",
      "name": "Stripe Refund Group Gate and Amount Cap",
      "summary": "Denies Stripe refund tool calls — money out, irreversible — unless the caller's IdP groups include finance or billing-admin.",
      "url": "https://www.intentbasedpolicy.com/policies/stripe/gate-money-movement-refund-cap",
      "markdown": "https://www.intentbasedpolicy.com/policies/stripe/gate-money-movement-refund-cap.md",
      "app": "stripe",
      "apps": [
        "stripe"
      ],
      "bundles": [
        "pci-dss",
        "sox"
      ],
      "tags": [
        "stripe",
        "gate-money-movement",
        "ingress",
        "pci-dss",
        "sox"
      ],
      "direction": "ingress",
      "package": "stripe.ingress.gate_money_movement_refund_cap",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:13424f63b4b306879d531cf7825b3c8b4930965d9d24a4b3889a2310f4277540",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/stripe/gate-money-movement-refund-cap",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/stripe/gate-money-movement-refund-cap/policy.md"
    },
    {
      "slug": "stripe/redact-pii-egress-customer",
      "name": "Stripe: Redact Customer PII from Bulk Reads",
      "summary": "Masks customer PII in the responses of Stripe's bulk PII egress channels before they reach the agent.",
      "url": "https://www.intentbasedpolicy.com/policies/stripe/redact-pii-egress-customer",
      "markdown": "https://www.intentbasedpolicy.com/policies/stripe/redact-pii-egress-customer.md",
      "app": "stripe",
      "apps": [
        "stripe"
      ],
      "bundles": [
        "soc2",
        "gdpr-ccpa"
      ],
      "tags": [
        "stripe",
        "redact-pii",
        "pii",
        "dlp",
        "redaction",
        "egress",
        "soc2",
        "gdpr-ccpa"
      ],
      "direction": "egress",
      "package": "stripe.egress.redact_pii_customer",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:6b7b47948dab7d6f274c4c8060234b1b6b47d4f62e8de7118651649518a05919",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/stripe/redact-pii-egress-customer",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/stripe/redact-pii-egress-customer/policy.md"
    },
    {
      "slug": "tableau/redact-pii-query-results",
      "name": "Tableau: Redact PII & Mask PANs in Query Results",
      "summary": "Tableau is a warehouse proxy: the data-returning tools stream raw row-level content out of whatever the published datasource connects to — PII, PHI, payroll,…",
      "url": "https://www.intentbasedpolicy.com/policies/tableau/redact-pii-query-results",
      "markdown": "https://www.intentbasedpolicy.com/policies/tableau/redact-pii-query-results.md",
      "app": "tableau",
      "apps": [
        "tableau"
      ],
      "bundles": [
        "soc2",
        "gdpr-ccpa"
      ],
      "tags": [
        "tableau",
        "redact-pii-egress",
        "pii",
        "pan",
        "dlp",
        "redaction",
        "egress",
        "soc2",
        "gdpr-ccpa"
      ],
      "direction": "egress",
      "package": "tableau.egress.redact_pii_query_results",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:b7ef7bd78e5b1bfaa4ad6beb548ad4e0ec16af7901b918b1fddfd118adcc12b8",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/tableau/redact-pii-query-results",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/tableau/redact-pii-query-results/policy.md"
    },
    {
      "slug": "zapier/mask-pan-egress",
      "name": "Zapier: Mask Card Numbers in Read Responses",
      "summary": "Masks payment-card numbers (PANs) in Zapier MCP read responses before they reach the agent.",
      "url": "https://www.intentbasedpolicy.com/policies/zapier/mask-pan-egress",
      "markdown": "https://www.intentbasedpolicy.com/policies/zapier/mask-pan-egress.md",
      "app": "zapier",
      "apps": [
        "zapier"
      ],
      "bundles": [
        "soc2",
        "pci-dss",
        "gdpr-ccpa"
      ],
      "tags": [
        "zapier",
        "mask-pan-egress",
        "egress",
        "cardholder-data",
        "dlp",
        "soc2",
        "pci-dss",
        "gdpr-ccpa"
      ],
      "direction": "egress",
      "package": "zapier.egress.mask_pan",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:3bbdf8be613466767f4826a268a3eac6cbee33de02de1da55e80f11ce2c117bd",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/zapier/mask-pan-egress",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/zapier/mask-pan-egress/policy.md"
    },
    {
      "slug": "zoom/redact-pii-meeting-intelligence",
      "name": "Zoom: Redact PII in Meeting Intelligence",
      "summary": "Scans the responses of Zoom's meeting-intelligence read surfaces — AI summaries, verbatim transcripts, recording resources, and Zoom Docs content — and…",
      "url": "https://www.intentbasedpolicy.com/policies/zoom/redact-pii-meeting-intelligence",
      "markdown": "https://www.intentbasedpolicy.com/policies/zoom/redact-pii-meeting-intelligence.md",
      "app": "zoom",
      "apps": [
        "zoom"
      ],
      "bundles": [
        "hipaa",
        "gdpr-ccpa",
        "soc2"
      ],
      "tags": [
        "zoom",
        "redact-pii",
        "pii",
        "dlp",
        "redaction",
        "egress",
        "hipaa",
        "gdpr-ccpa",
        "soc2"
      ],
      "direction": "egress",
      "package": "zoom.egress.redact_pii_meeting_intelligence",
      "publishedAt": "2026-07-12",
      "policyChecksum": "sha256:b770b21e23915717892b25fa6761c49464ca375ac89689f0e456eae6a410ab84",
      "schemaVersion": "1.0.0",
      "minimumGatewayVersion": "1.0.0b24",
      "repoPath": "apps/zoom/redact-pii-meeting-intelligence",
      "github": "https://github.com/dtwoai/policy-store/blob/main/apps/zoom/redact-pii-meeting-intelligence/policy.md"
    }
  ]
}