dtwo Policy Store

Policies tagged "governance"

confluence · ingress

Confluence: Deny Org-Wide & Public Publication

Stops a prompt-injected or erring agent from broadcasting Confluence content org-wide or to anonymous external readers.

confluenceatlassiandeny-public-exposurepublicationgovernanceingressfinserv-commseu-ai-actsoc2gdpr-ccpa

hubspot · ingress

HubSpot Block Deal Closure

Blocks HubSpot CRM-object calls that move a deal into a closed stage (closedwon or closedlost). Both create and update requests are inspected.

hubspotdealsaccess-controlgovernanceingress

hubspot · ingress

HubSpot Protect Associations

Blocks HubSpot CRM-object calls that create or change associations between objects (deal↔company, contact↔company, etc.).

hubspotassociationsaccess-controlgovernanceingress

hubspot · ingress

HubSpot Protect Deal Owner

Blocks HubSpot CRM-object update calls that set or change a deal's owner.

hubspotdealsaccess-controlgovernanceingress

hubspot · ingress

HubSpot Protect Lifecycle Stage

Blocks HubSpot CRM-object calls that set or change a contact's lifecycle stage.

hubspotcontactslifecycleaccess-controlgovernanceingress

hubspot · ingress

HubSpot Read-Only

Makes the HubSpot connection read-only by blocking the write tool.

hubspotaccess-controlgovernanceread-onlyingresssoc2gdpr-ccpa

intercom · ingress

Intercom: Keep Agent Help Center Articles in Draft

Keeps agent-authored Intercom Help Center articles in draft so a human reviews them before they go live on the public Help Center.

intercomdeny-public-exposureingressarticleshelp-centerpublicationgovernancesoc2

salesforce · ingress

Salesforce Protect Contact Fields

Blocks Salesforce Contact updates that modify protected fields — ownership, account linkage, contact PII, name, and consent flags.

salesforcecontactspiiaccess-controlgovernanceingresssoc2gdpr-ccpaiso27001-nist

salesforce · ingress

Salesforce Query Allowlist

Restricts Salesforce SOQL queries so only Account, Contact, and Opportunity records can be retrieved.

salesforceaccess-controldata-protectiongovernanceingresssoc2pci-dssgdpr-ccpaiso27001-nist

salesforce · ingress

Salesforce Read-Only Access

Restricts the Salesforce MCP server to read-only access.

salesforceaccess-controlgovernanceread-onlyingresssoc2gdpr-ccpaiso27001-nist

slack · ingress

Slack: Deny Channel Creation

Blocks Slack channel-creation tool calls at ingress. Every other Slack tool — and every non-Slack tool — passes through untouched.

slackaccess-controlgovernanceingresssoc2iso27001-nist

slack · ingress

Slack: Deny Sending Direct Messages

Blocks Slack message-write calls whose destination resolves to a direct conversation — a 1:1 DM, a message posted to a user ID (which Slack auto-opens as a…

slackaccess-controlgovernanceingresssoc2iso27001-nistfinserv-comms