Block Agent Email to External Recipients
Blocks agent-initiated Microsoft 365 email sends when any recipient address falls outside a corporate-domain allowlist.
Blocks agent-initiated Microsoft 365 email sends when any recipient address falls outside a corporate-domain allowlist.
Inspects the raw GoogleSQL string carried by BigQuery SQL tools and denies any statement that moves data out of the tenant's own project — even when the call…
bigqueryguard-warehouse-exportingresssqlexfiltrationsoc2pci-dssgdpr-ccpa
Blocks Snowflake SQL-execution tool calls whose query text moves whole tables off the Snowflake perimeter — bulk export to cloud storage or a stage, and…
snowflakeguard-warehouse-sqlexportexfiltrationingresssoc2pci-dssgdpr-ccpa
Denies Google Calendar event-write tool calls — create event / create-event, update event / update-event, and the consolidated manage event — whenever any…
google-calendarguard-external-sendingresscalendarsoc2hipaagdpr-ccpa
Inspects Notion data-source query tool calls (notion-query-data-sources on the hosted server, query-data-source on the official local server) and denies any…
Inspects the SQL text that Snowflake MCP tools carry in their query argument and denies any statement in a mutating or destructive class — DROP, TRUNCATE,…
snowflakeguard-warehouse-sqlingresssqlreadonlysoc2pci-dsssox
Inspects the raw GoogleSQL string carried by BigQuery write-capable query tools and denies any statement in a state-changing class — DML…
Every Zapier MCP tool — in both the agentic and classic modes — accepts a free-text instructions string that Zapier's server-side AI uses to fill any…
Stops a Zoom Team Chat agent from pulling external parties into the organization's chat surface.
Blocks the classic BEC/exfiltration persistence primitive: Gmail filters that can auto-forward or auto-delete mail and outlive the agent session.
Denies the irreversible destructive operations on the Docusign agent path:
Unconditionally denies any Linear tool that creates, updates, or deletes a webhook — linear createWebhook, linear deleteWebhook, and update variants.
linearguard-webhook-persistenceingresswebhookexfiltrationsoc2
Unconditionally denies the classic business-email-compromise (BEC) persistence surface in Microsoft 365: creating or updating Outlook mail rules, changing…
ms365guard-mailbox-persistenceingressbecemailfinserv-commssoc2
On Microsoft's remote Power BI MCP server (https://api.fabric.microsoft.
Denies, by default, the Dropbox tools that turn an internal file into an internet-visible resource in a single call — before the request ever reaches Dropbox:
dropboxguard-share-linkssharingexternal-sharingingresssoc2hipaagdpr-ccpa
Blocks Google Calendar create and update event calls that would expose the event to the world or hand control of it to guests.
Blocks Confluence write calls whose body looks like it contains a live credential — an API key, password, token, or PEM-formatted private key — before the…
Blocks Slack send-message tool calls whose message body looks like it contains a secret — API keys, passwords, tokens, or PEM-formatted private keys.
Blocks Zoom Team Chat send/update tool calls whose message content looks like it contains a live secret — API keys, passwords, bearer tokens, or…
Makes Box read-only by default on the MCP path.
boxrole-gate-writesaccess-controlleast-privilegeingresssoc2gdpr-ccpa
Caps the blast radius of Asana's official V2 batch write tools. At ingress it:
Clamps the bulk-export parameters on Glean search calls before they reach the Glean MCP server, so a single agent request cannot pull an entire indexed…
gleancap-bulk-exportdata-minimisationingresssoc2hipaagdpr-ccpa
Clamps the page size of Google Drive search and listing calls to a documented cap (25 results per call).
google-drivecap-bulk-exportdata-minimizationingresssoc2hipaagdpr-ccpa
caller is a CRM admin); clamp page size on everything else; allow the rest
intercomcap-bulk-exportcontact-enumerationdlpingresssoc2hipaapci-dssgdpr-ccpa
Clamps the bulk-read levers on every QuickBooks Online search tool so an agent cannot pull the entire general ledger — or a full customer, vendor, or…
quickbookscap-bulk-exportbulk-exportdlpingresssoc2pci-dssgdpr-ccpa
Airtable bases routinely hold CRM contacts, applicant-tracking pipelines, customer/financial trackers, and — on HIPAA-eligible Enterprise plans — health-ops…
An Airtable OAuth grant (or Personal Access Token) with the workspacesAndBases:read scope spans the entire workspace — every base the connected identity can…
Stops a prompt-injected or erring agent from broadcasting Confluence content org-wide or to anonymous external readers.
confluenceatlassiandeny-public-exposurepublicationgovernanceingressfinserv-commseu-ai-actsoc2gdpr-ccpa
Freezes the two irreversible Confluence deletion tools on the agent channel: confluence delete page and confluence delete attachment.
confluenceatlassianfreeze-destructive-opsdata-protectioningresssoc2
Notion's hosted MCP server (notion-search) does not just search Notion pages — through Notion AI connectors it also searches connected Slack, Google Drive,…
Pins an allowlist of the exact Databricks tool names your team audited and denies every other tool name on the Databricks MCP server(s).
databricksdefault-deny-unknown-toolsallowlistaccess-controlingresssoc2
The community JustTryAI/databricks-mcp-server exposes cluster and job control — create cluster, start cluster, terminate cluster, run job, and export…
databricksrole-gate-writesaccess-controlleast-privilegeingresssoc2
Maintains a per-tenant allowlist of audited Airtable tool-name suffixes and denies any call whose tool name does not end with an allowlisted entry.
Maintains a per-tenant allowlist of audited BigQuery tool-name suffixes and denies any call whose tool name does not end with an allowlisted entry.
bigquerydefault-deny-unknown-toolsallowlistaccess-controlingresssoc2
Pins an allowlist of the 36 official Gusto MCP tool names and allows a call only when lower(input.resource.name) is an exact member of that list.
Pins an audited allowlist of the verified official Linear MCP tool names and allows a call only when the incoming tool name matches an allowlisted name on…
Maintains a per-tenant allowlist of audited monday tool-name suffixes and denies any call whose tool name does not end with an allowlisted entry.
Pins a per-tenant allowlist of audited Power BI tool-name suffixes and denies any call whose tool name does not end with an allowlisted entry.
power-bidefault-deny-unknown-toolsallowlistmodelingingresssoc2
Maintains an allowlist of audited ServiceNow tool-name suffixes and denies any tool call whose name does not match an allowlisted entry.
Fails closed on tool drift. The policy carries a pinned allowlist of the 39 tools in the verified official Tableau web toolset (tableau/tableau-mcp v2.24.
Maintains an allowlist of audited Zapier tool-name suffixes and denies any tool call whose name does not match an allowlisted entry, with an alert-worthy…
Denies Gmail send-class tool calls when any recipient in to, cc, or bcc falls outside a documented corporate-domain allowlist.
This policy stops a request if it contains an email address. If there's no email address, the request goes through as normal.
Blocks the Microsoft 365 MCP server's raw-Graph passthrough tool (graph-batch, observed live as ms365-graph-batch).
Denies the stripe api write meta-tool — the single raw passthrough on the official Stripe MCP server that can execute any Stripe POST, PATCH, PUT, or DELETE…
Fences a configurable set of restricted Confluence spaces (placeholder keys: HR, LEGAL, SEC) out of the agent's read and search paths unless the caller's IdP…
confluenceatlassianfence-sensitive-scopesaccess-controlingresssoc2hipaagdpr-ccpa
Denies any GitHub tool call whose arguments.owner (read from input.payload.args.
githubfence-sensitive-scopesorg-allowlistanti-exfilingresssoc2
Glean's search tool fans out across every system the tenant has indexed (Drive, Confluence, Slack, Jira, Gmail/Outlook, GitHub, Salesforce, Gong, HR…
gleanfence-sensitive-scopesaccess-controldatasourceingresssoc2hipaagdpr-ccpa
Denies the highest-sensitivity Gusto read tools unless the caller's IdP-asserted groups include the placeholder group hr-payroll-admins.
gustofence-hr-and-credit-scopecompensationpayrollingresssoc2gdpr-ccpa
Gates Intercom's structured-PII read surface — customer contact and company profiles — by IdP group.
intercomfence-sensitive-scopescontact-readspiiingresssoc2hipaapci-dssgdpr-ccpa
Fences the single biggest exfiltration surface on the NetSuite MCP server — ns runCustomSuiteQL, which runs arbitrary read-only SuiteQL across the entire ERP.
Denies calls to the Notion member-directory tool (notion-get-users, matched by the -get-users suffix) unless the caller's IdP groups include an admin or IT…
notionfence-sensitive-scopesaccess-controlpiiingresssoc2gdpr-ccpa
Fences customer-designated regulated BigQuery data domains by data-domain IdP group, at ingress, before any statement or metadata lookup reaches BigQuery.
bigqueryfence-sensitive-scopesingressrbacsoc2hipaapci-dssgdpr-ccpa
Fences an admin-maintained denylist of restricted Google Drive file and folder IDs — HR records, M&A deal rooms, board packs, payroll — off the agent channel:
google-drivefence-restricted-folderssensitive-scopesingresssoc2hipaagdpr-ccpa
Fences pinned sensitive Box subtrees (HR, Finance, Legal, …) by ID.
Fences off the most sensitive lakehouse namespaces from agents on the read side of Databricks.
databricksfence-sensitive-scopesingresssoc2hipaapci-dssgdpr-ccpa
Fences protected Dropbox subtrees by path prefix . Dropbox addresses files and folders by a root-relative path (/Finance/2026/payroll.
monday boards are schemaless business databases: HR/recruiting boards (candidate PII), CRM/deal boards (financial), and IT/security trackers routinely live…
Fences off the most sensitive ServiceNow tables from two routes that reach them:
servicenowfence-sensitive-tablespiiingresssoc2hipaapci-dssgdpr-ccpa
Fences customer-designated sensitive data domains inside a Snowflake warehouse by inspecting the SQL text the agent is about to run — not by tool name, which…
snowflakefence-sensitive-scopesingresssoc2hipaapci-dssgdpr-ccpa
Tableau's MCP server is a warehouse proxy: query-datasource runs a VizQL Data Service (VDS) query and returns raw row-level data — PII, PHI, payroll,…
tableaufence-sensitive-scopesaccess-controldatasourceingresssoc2gdpr-ccpa
Asana is routinely used for HR (hiring, performance, offboarding), legal, M&A, and incident work; those project bodies, comments, custom fields, and status…
Constrains Zoom's agentic-search tool ( search zoom) so it can only reach Zoom-native content.
Rewrites Docusign envelope-creation calls so the envelope is staged as a (status: "sent").
Keeps agent-drafted Jira Service Management (JSM) comments off the customer-facing portal by rewriting addCommentToJiraIssue calls to carry a restrictive…
jiraforce-internal-commentscommentsjsmservice-managementingresssoc2atlassian
Keeps agent-drafted ServiceNow comments off the customer/employee-visible journal by rewriting add comment calls to internal work notes.
servicenowforce-internal-commentscommentswork-notesingresssoc2finra
Denies every destructive Airtable tool call unless the caller's IdP token carries the placeholder group airtable-admins.
Denies irreversible Google Calendar mutations on the agent channel:
Denies every destructive Asana tool call unless the caller's IdP token carries the placeholder group asana-admins.
Freezes deletes and retention tampering on the community self-hosted Box MCP server (box-community/mcp-server-box).
Freezes the irreversible and bulk-mutation Dropbox tools on the agent channel, regardless of path. At ingress it denies, by tool-name suffix:
Denies the irreversible destruction surface that community Gmail MCP servers expose — permanent email deletion, label deletion, and filter deletion — for…
Blocks Google Drive delete operations issued by agents.
Denies destructive Linear tool calls — the delete , archive , and session-logout classes — unless the caller's IdP token carries the placeholder group…
Denies every Microsoft 365 tool call whose verb segment is delete- or cancel- unless the caller's IdP token carries the placeholder group m365-admin.
Splits monday's destructive tool surface into two tiers and treats each differently at ingress, before the call ever reaches the monday MCP server:
Denies every destructive QuickBooks Online (QBO) tool call on the agent channel before it reaches the MCP server.
Denies the irreversible content-mutation tools on the official tableau/tableau-mcp web server unless the caller's IdP token carries the placeholder group…
Freezes directory and membership mutations on the Microsoft 365 MCP surface. The policy denies, by tool-name suffix:
ms365freeze-identity-planeingressidentityentragroupsiso27001-nistsoc2
Denies notion-update-page calls whose command argument is replace content — the one edge on Notion's hosted MCP server that overwrites a page's entire body…
Freezes every write and delete operation on a Gusto pipeline.
Freezes edits to row-level-security (RLS) roles on the Power BI MCP surface.
power-bifreeze-identity-planeingressrlsidentitygroupssoc2iso27001-nist
Denies all Salesforce record-deletion capability on the agent channel unless the caller's IdP groups claim contains the placeholder group sf-admins.
Freezes the identity-and-access mutation surface of the ServiceNow MCP server. The policy denies, by tool-name suffix:
servicenowfreeze-identity-planeingressidentitygroupssoc2iso27001-nist
Denies the monday tools that install side effects which outlive the governed MCP session. Two classes of tool are blocked:
In its default agentic mode, Zapier MCP exposes meta-tools that let the agent widen its own blast radius mid-session : enable zapier action and auto…
Baseline least-privilege policy for Google Drive MCP traffic.
google-driverole-gate-writesleast-privilegeingresssoc2gdpr-ccpa
Gates the QuickBooks Online money-movement creation tools — create payment, create bill payment, create refund receipt, create transfer, and create deposit —…
Gates retrieval of Zoom meeting transcripts, AI Companion summaries, and next-steps on the connector's core egress tools, enforcing minimum-necessary access:
Pins a per-tenant allowlist of the verified built-in read tools on the Glean managed remote MCP server and denies every other tool suffix on the Glean server…
gleandefault-deny-unknown-toolsallowlistaccess-controlingresssoc2
Gates mutating calls to Glean's long-term memory surface — the built-in tool exposed as memory (and as read memory in Glean's own client guide).
gleangate-memory-writesrole-gate-writesmemoryaccess-controlleast-privilegeingresssoc2
Throttles mass-harvesting of a mailbox by capping the per-call blast radius of the two Gmail MCP surfaces that return many full email bodies at once:
gmailcap-bulk-exportdata-minimisationingresssoc2hipaagdpr-ccpa
Makes Gmail read-only by default on the MCP path. Verified read tools pass for everyone.
gmailrole-gate-writesaccess-controlleast-privilegeingresssoc2gdpr-ccpa
Blocks the externally-visible Box sharing surface — the riskiest Box surface an agent can touch — before the call ever reaches Box:
boxguard-share-linkssharingexternal-sharingingresssoc2hipaagdpr-ccpa
Inspects the structured VizQL Data Service (VDS) query carried by Tableau's query-datasource tool and denies the call for callers outside the data-analysts…
Inspects the SQL statement string that Databricks SQL-executing tools carry in their argument and denies any statement that performs a write, schema change,…
databricksguard-warehouse-sqlingresssqlreadonlypci-dsssoxsoc2
Power BI semantic models front the warehouse: a model imports or DirectQueries lakehouse/warehouse tables — finance, HR, customer PII.
power-biguard-warehouse-sqlingressdaxexfiltrationsoc2gdpr-ccpa
Blocks Docusign envelope-creation and recipient-update tool calls when any recipient email address has a domain outside the configured counterparty allowlist.
Denies Google Drive get file permissions tool calls unless the caller's IdP groups claim contains infosec. All other tool calls pass through unchanged.
Stops agents from opening OneDrive/SharePoint files to the whole internet. It guards the two Microsoft 365 sharing tools:
ms365share-linkssharingingresssoc2iso27001-nisthipaagdpr-ccpa
Blocks create vendor and update vendor calls whose arguments carry a vendor's payment coordinates — bank account number, routing / ACH branch details — or…
Throttles full-roster exfiltration on Gusto's two broad outbound list tools — list company employees and list company contractors — by rewriting their…
gustocap-bulk-exportpiidata-minimisationingressgdpr-ccpasoc2
Blocks HubSpot CRM-object calls that move a deal into a closed stage (closedwon or closedlost). Both create and update requests are inspected.
Clamps the page size of HubSpot bulk-read tool calls before they reach the HubSpot MCP server, so a single agent request to a covered bulk-read tool can…
hubspotcap-bulk-exportpiidata-minimisationingresssoc2hipaapci-dssgdpr-ccpa
Blocks every archive/deletion-class HubSpot tool call, plus the consent-destroying contact unsubscribe, before it reaches the MCP server.
Blocks HubSpot CRM-object calls that create or change associations between objects (deal↔company, contact↔company, etc.).
Blocks HubSpot CRM-object update calls that set or change a deal's owner.
Blocks HubSpot CRM-object calls that set or change a contact's lifecycle stage.
Makes the HubSpot connection read-only by blocking the write tool.
hubspotaccess-controlgovernanceread-onlyingresssoc2gdpr-ccpa
Sits one privilege tier above hubspot/role-gate-writes: ordinary crm-writers can create and edit CRM records, but two higher-blast-radius write classes are…
hubspotrole-gate-schema-consentaccess-controlleast-privilegesegregation-of-dutiesconsentingresssoc2
Gates every HubSpot write tool behind an IdP group: callers whose JWT groups claim contains crm-writers may create and update CRM records; everyone else gets…
hubspotrole-gate-writesaccess-controlleast-privilegeingresssoc2gdpr-ccpa
Unconditionally denies the ServiceNow change-management control-gate tools — the ones whose names end in approve change, reject change, or submit change for…
servicenowrequire-human-approvalchange-managementseparation-of-dutiesingresssoc2
Strips the irreversible submit flag from Stripe update dispute tool calls.
striperequire-human-approvaldisputesseparation-of-dutiestransformingresssox
Keeps agent-authored Intercom Help Center articles in draft so a human reviews them before they go live on the public Help Center.
intercomdeny-public-exposureingressarticleshelp-centerpublicationgovernancesoc2
Blocks any official Jira write call — transitionJiraIssue, editJiraIssue, or createJiraIssue — that carries a historyMetadata block, before it reaches the…
jiraatlassianfreeze-destructive-opsaudit-integrityingresssoc2
Narrows the breadth of JIRA read requests before they run, on the two read surfaces that can pull large amounts of issue data into model context:
jiraatlassiancap-bulk-exportdata-minimisationingresssoc2gdpr-ccpa
Keeps issues that belong to a configurable set of "sensitive" JIRA projects out of read access through the JIRA MCP server.
jiraatlassianaccess-controldata-protectioningresssoc2gdpr-ccpaiso27001-nistfinserv-comms
Freezes the three irreversible Jira operations on the agent channel: jira delete issue, jira remove issue link, and jira remove watcher.
jiraatlassianfreeze-destructive-opsrecord-integritydata-protectioningresssoc2
Blocks write operations against issues that belong to a configurable set of "sensitive" JIRA projects.
jiraatlassianaccess-controldata-protectioningresssoc2gdpr-ccpaiso27001-nistfinserv-comms
Makes Jira read-only by default on the MCP path.
jiraatlassianrole-gate-writesaccess-controlleast-privilegeingresssoc2gdpr-ccpa
Denies the QuickBooks Online tools create journal entry and update journal entry at ingress for every caller except those whose IdP claims include the…
Instantiates the PF-08 cap-bulk-export family as a transform-only ingress policy on ns runCustomSuiteQL — the NetSuite MCP tool that runs arbitrary read-only…
netsuitecap-bulk-exportsuiteqldata-minimisationingresssoc2pci-dssgdpr-ccpa
Pins an allowlist of the audited NetSuite MCP Standard Tools and denies every other tool call before it reaches the NetSuite AI Connector.
netsuitedefault-deny-unknown-toolsallowlistaccess-controlingresssoc2
Instantiates policy family PF-10 (guard-vendor-banking) — the anti-BEC / payment-fraud control — for the Oracle NetSuite MCP Standard Tools SuiteApp.
Stops the agent from exposing private code to the public across three GitHub write tools, at ingress — before the call reaches the GitHub MCP server, so a…
githubdeny-public-exposureanti-exfilingresssoc2finserv-commseu-ai-act
Denies the NetSuite record-write tools ns createRecord and ns updateRecord when they target a financial-transaction record type — journalentry (including the…
The least-privilege baseline for Microsoft 365 through the gateway: every tool call is allowed only if it is a read , or the caller's IdP token carries the…
Establishes the least-privilege baseline for the GitHub MCP connector on the agent channel.
Establishes a read-only-by-default Stripe posture over the MCP path. The named write and destructive billing tools —
striperole-gate-writesingressleast-privilegerbacsoc2pci-dsssoxgdpr-ccpa
Keeps a human in the loop on the two GitHub actions that consummate a code change: merging a pull request and approving one .
Zapier MCP is an aggregator: one connector proxies actions across 9,000+ apps, and every create/update/delete/send funnels through a small, predictable…
Establishes the per-app least-privilege write floor for Dropbox.
dropboxrole-gate-writesrbacleast-privilegeingresssoc2gdpr-ccpa
Blocks bulk PII extraction through Salesforce query tools by inspecting the free-text query arguments that are the real policy surface for these servers.
salesforcecap-bulk-exportdata-minimizationdlpingresssoc2hipaapci-dssgdpr-ccpa
Unconditionally denies the raw-code and raw-API tools exposed by the community Salesforce MCP servers — tools that bypass every object- and argument-level…
salesforcedeny-escape-hatchesaccess-controlingresssoc2iso27001-nist
Keeps revenue-pipeline moves human-approved.
salesforceopportunitypipelinerevenuehuman-approvalaccess-controlgovernanceingress
Blocks Salesforce Contact updates that modify protected fields — ownership, account linkage, contact PII, name, and consent flags.
salesforcecontactspiiaccess-controlgovernanceingresssoc2gdpr-ccpaiso27001-nist
Restricts Salesforce SOQL queries so only Account, Contact, and Opportunity records can be retrieved.
salesforceaccess-controldata-protectiongovernanceingresssoc2pci-dssgdpr-ccpaiso27001-nist
Restricts the Salesforce MCP server to read-only access.
salesforceaccess-controlgovernanceread-onlyingresssoc2gdpr-ccpaiso27001-nist
The PF-12 least-privilege baseline for Salesforce.
salesforcerole-gate-writesaccess-controlleast-privilegeingresssoc2gdpr-ccpacrm
Scrubs the post-payment redirect from Stripe payment-link creation calls.
stripeguard-share-linksingresstransformphishingprompt-injectionsoc2
else fails closed
servicenowrole-gate-writesaccess-controlleast-privilegeingresssoc2gdpr-ccpa
Gates every Slack write-class tool behind an IdP group: callers whose JWT groups claim contains slack-writers may send and schedule messages, add or remove…
slackrole-gate-writesaccess-controlleast-privilegeingresssoc2gdpr-ccpa
Denies Slack message-write calls whose destination is an externally shared Slack Connect channel.
slackguard-external-sendslack-connectexfiltrationingresssoc2gdpr-ccpahipaa
Blocks Slack channel-creation tool calls at ingress. Every other Slack tool — and every non-Slack tool — passes through untouched.
Denies the agent read reach into Slack DMs and private conversations on the paths below — the workspace's highest concentration of PII/PHI (HR issues, health…
Blocks read, search, and summarize operations that target a configurable set of "sensitive" Slack channels.
slackaccess-controldata-protectioningresssoc2hipaagdpr-ccpaiso27001-nist
Blocks Slack message-write calls whose destination resolves to a direct conversation — a 1:1 DM, a message posted to a user ID (which Slack auto-opens as a…
slackaccess-controlgovernanceingresssoc2iso27001-nistfinserv-comms
Pins an allowlist of the exact Snowflake tool names your team audited and denies every other tool name on the Snowflake MCP server(s).
snowflakedefault-deny-unknown-toolsallowlistaccess-controlingresssoc2
Denies the opaque composite and generic passthrough tools on the Snowflake-managed MCP server whose execution the gateway cannot inspect one SQL statement at…
snowflakedeny-escape-hatchesaccess-controlcortexingresssoc2iso27001-nist
Denies Stripe refund tool calls — money out, irreversible — unless the caller's IdP groups include finance or billing-admin.