Box: Role-Gated Writes (Read-Only Default)
Makes Box read-only by default on the MCP path.
boxrole-gate-writesaccess-controlleast-privilegeingresssoc2gdpr-ccpa
Makes Box read-only by default on the MCP path.
boxrole-gate-writesaccess-controlleast-privilegeingresssoc2gdpr-ccpa
Pins an allowlist of the exact Databricks tool names your team audited and denies every other tool name on the Databricks MCP server(s).
databricksdefault-deny-unknown-toolsallowlistaccess-controlingresssoc2
The community JustTryAI/databricks-mcp-server exposes cluster and job control — create cluster, start cluster, terminate cluster, run job, and export…
databricksrole-gate-writesaccess-controlleast-privilegeingresssoc2
Maintains a per-tenant allowlist of audited BigQuery tool-name suffixes and denies any call whose tool name does not end with an allowlisted entry.
bigquerydefault-deny-unknown-toolsallowlistaccess-controlingresssoc2
Fences a configurable set of restricted Confluence spaces (placeholder keys: HR, LEGAL, SEC) out of the agent's read and search paths unless the caller's IdP…
confluenceatlassianfence-sensitive-scopesaccess-controlingresssoc2hipaagdpr-ccpa
Glean's search tool fans out across every system the tenant has indexed (Drive, Confluence, Slack, Jira, Gmail/Outlook, GitHub, Salesforce, Gong, HR…
gleanfence-sensitive-scopesaccess-controldatasourceingresssoc2hipaagdpr-ccpa
Denies calls to the Notion member-directory tool (notion-get-users, matched by the -get-users suffix) unless the caller's IdP groups include an admin or IT…
notionfence-sensitive-scopesaccess-controlpiiingresssoc2gdpr-ccpa
Tableau's MCP server is a warehouse proxy: query-datasource runs a VizQL Data Service (VDS) query and returns raw row-level data — PII, PHI, payroll,…
tableaufence-sensitive-scopesaccess-controldatasourceingresssoc2gdpr-ccpa
Pins a per-tenant allowlist of the verified built-in read tools on the Glean managed remote MCP server and denies every other tool suffix on the Glean server…
gleandefault-deny-unknown-toolsallowlistaccess-controlingresssoc2
Gates mutating calls to Glean's long-term memory surface — the built-in tool exposed as memory (and as read memory in Glean's own client guide).
gleangate-memory-writesrole-gate-writesmemoryaccess-controlleast-privilegeingresssoc2
Makes Gmail read-only by default on the MCP path. Verified read tools pass for everyone.
gmailrole-gate-writesaccess-controlleast-privilegeingresssoc2gdpr-ccpa
Blocks HubSpot CRM-object calls that move a deal into a closed stage (closedwon or closedlost). Both create and update requests are inspected.
Blocks HubSpot CRM-object calls that create or change associations between objects (deal↔company, contact↔company, etc.).
Blocks HubSpot CRM-object update calls that set or change a deal's owner.
Blocks HubSpot CRM-object calls that set or change a contact's lifecycle stage.
Makes the HubSpot connection read-only by blocking the write tool.
hubspotaccess-controlgovernanceread-onlyingresssoc2gdpr-ccpa
Sits one privilege tier above hubspot/role-gate-writes: ordinary crm-writers can create and edit CRM records, but two higher-blast-radius write classes are…
hubspotrole-gate-schema-consentaccess-controlleast-privilegesegregation-of-dutiesconsentingresssoc2
Gates every HubSpot write tool behind an IdP group: callers whose JWT groups claim contains crm-writers may create and update CRM records; everyone else gets…
hubspotrole-gate-writesaccess-controlleast-privilegeingresssoc2gdpr-ccpa
Keeps issues that belong to a configurable set of "sensitive" JIRA projects out of read access through the JIRA MCP server.
jiraatlassianaccess-controldata-protectioningresssoc2gdpr-ccpaiso27001-nistfinserv-comms
Blocks write operations against issues that belong to a configurable set of "sensitive" JIRA projects.
jiraatlassianaccess-controldata-protectioningresssoc2gdpr-ccpaiso27001-nistfinserv-comms
Makes Jira read-only by default on the MCP path.
jiraatlassianrole-gate-writesaccess-controlleast-privilegeingresssoc2gdpr-ccpa
Pins an allowlist of the audited NetSuite MCP Standard Tools and denies every other tool call before it reaches the NetSuite AI Connector.
netsuitedefault-deny-unknown-toolsallowlistaccess-controlingresssoc2
Unconditionally denies the raw-code and raw-API tools exposed by the community Salesforce MCP servers — tools that bypass every object- and argument-level…
salesforcedeny-escape-hatchesaccess-controlingresssoc2iso27001-nist
Keeps revenue-pipeline moves human-approved.
salesforceopportunitypipelinerevenuehuman-approvalaccess-controlgovernanceingress
Blocks Salesforce Contact updates that modify protected fields — ownership, account linkage, contact PII, name, and consent flags.
salesforcecontactspiiaccess-controlgovernanceingresssoc2gdpr-ccpaiso27001-nist
Restricts Salesforce SOQL queries so only Account, Contact, and Opportunity records can be retrieved.
salesforceaccess-controldata-protectiongovernanceingresssoc2pci-dssgdpr-ccpaiso27001-nist
Restricts the Salesforce MCP server to read-only access.
salesforceaccess-controlgovernanceread-onlyingresssoc2gdpr-ccpaiso27001-nist
The PF-12 least-privilege baseline for Salesforce.
salesforcerole-gate-writesaccess-controlleast-privilegeingresssoc2gdpr-ccpacrm
else fails closed
servicenowrole-gate-writesaccess-controlleast-privilegeingresssoc2gdpr-ccpa
Gates every Slack write-class tool behind an IdP group: callers whose JWT groups claim contains slack-writers may send and schedule messages, add or remove…
slackrole-gate-writesaccess-controlleast-privilegeingresssoc2gdpr-ccpa
Blocks Slack channel-creation tool calls at ingress. Every other Slack tool — and every non-Slack tool — passes through untouched.
Denies the agent read reach into Slack DMs and private conversations on the paths below — the workspace's highest concentration of PII/PHI (HR issues, health…
Blocks read, search, and summarize operations that target a configurable set of "sensitive" Slack channels.
slackaccess-controldata-protectioningresssoc2hipaagdpr-ccpaiso27001-nist
Blocks Slack message-write calls whose destination resolves to a direct conversation — a 1:1 DM, a message posted to a user ID (which Slack auto-opens as a…
slackaccess-controlgovernanceingresssoc2iso27001-nistfinserv-comms
Pins an allowlist of the exact Snowflake tool names your team audited and denies every other tool name on the Snowflake MCP server(s).
snowflakedefault-deny-unknown-toolsallowlistaccess-controlingresssoc2
Denies the opaque composite and generic passthrough tools on the Snowflake-managed MCP server whose execution the gateway cannot inspect one SQL statement at…
snowflakedeny-escape-hatchesaccess-controlcortexingresssoc2iso27001-nist