dtwo Policy Store

Policies tagged "ingress"

ms365 · ingress

Block Agent Email to External Recipients

Blocks agent-initiated Microsoft 365 email sends when any recipient address falls outside a corporate-domain allowlist.

ms365guard-external-sendingressemaildlpsoc2hipaagdpr-ccpa

bigquery · ingress

Block BigQuery Exfiltration and Cross-Project Writes

Inspects the raw GoogleSQL string carried by BigQuery SQL tools and denies any statement that moves data out of the tenant's own project — even when the call…

bigqueryguard-warehouse-exportingresssqlexfiltrationsoc2pci-dssgdpr-ccpa

snowflake · ingress

Block Bulk Export & External Staging (Snowflake)

Blocks Snowflake SQL-execution tool calls whose query text moves whole tables off the Snowflake perimeter — bulk export to cloud storage or a stage, and…

snowflakeguard-warehouse-sqlexportexfiltrationingresssoc2pci-dssgdpr-ccpa

google-calendar · ingress

Block Calendar Invites to External Attendees

Denies Google Calendar event-write tool calls — create event / create-event, update event / update-event, and the consolidated manage event — whenever any…

google-calendarguard-external-sendingresscalendarsoc2hipaagdpr-ccpa

notion · ingress

Block Destructive and Export SQL on Notion Data Sources

Inspects Notion data-source query tool calls (notion-query-data-sources on the hosted server, query-data-source on the official local server) and denies any…

notionguard-warehouse-sqlingresssqlreadonlysoc2

snowflake · ingress

Block Destructive and Mutating Snowflake SQL

Inspects the SQL text that Snowflake MCP tools carry in their query argument and denies any statement in a mutating or destructive class — DROP, TRUNCATE,…

snowflakeguard-warehouse-sqlingresssqlreadonlysoc2pci-dsssox

bigquery · ingress

Block Destructive SQL in BigQuery Queries

Inspects the raw GoogleSQL string carried by BigQuery write-capable query tools and denies any statement in a state-changing class — DML…

bigqueryguard-warehouse-sqlingresssqlreadonlysoc2pci-dsssox

zapier · ingress

Block External Sends Hidden in Zapier Instructions

Every Zapier MCP tool — in both the agentic and classic modes — accepts a free-text instructions string that Zapier's server-side AI uses to fill any…

zapierguard-external-sendingressemailsoc2gdpr-ccpa

zoom · ingress

Block External Team Chat Invites & Members

Stops a Zoom Team Chat agent from pulling external parties into the organization's chat surface.

zoomguard-external-sendingressteam-chatsoc2gdpr-ccpahipaa

gmail · ingress

Block Gmail Filter Creation (Auto-Forward Persistence)

Blocks the classic BEC/exfiltration persistence primitive: Gmail filters that can auto-forward or auto-delete mail and outlive the agent session.

gmailguard-mailbox-persistenceingressbecfinserv-commssoc2

docusign · ingress

Block Irreversible Docusign Void and Workflow Kills

Denies the irreversible destructive operations on the Docusign agent path:

docusignfreeze-destructive-opsingresssoc2

linear · ingress

Block Linear Webhook Creation

Unconditionally denies any Linear tool that creates, updates, or deletes a webhook — linear createWebhook, linear deleteWebhook, and update variants.

linearguard-webhook-persistenceingresswebhookexfiltrationsoc2

ms365 · ingress

Block Mail-Rule and Webhook Persistence

Unconditionally denies the classic business-email-compromise (BEC) persistence surface in Microsoft 365: creating or updating Outlook mail rules, changing…

ms365guard-mailbox-persistenceingressbecemailfinserv-commssoc2

power-bi · ingress

Block Power BI RLS-Bypass Service-Principal Queries

On Microsoft's remote Power BI MCP server (https://api.fabric.microsoft.

power-birole-gate-writesrlsservice-principalingresssoc2

dropbox · ingress

Block Public Dropbox Share, Download, and File-Request Links

Denies, by default, the Dropbox tools that turn an internal file into an internet-visible resource in a single call — before the request ever reaches Dropbox:

dropboxguard-share-linkssharingexternal-sharingingresssoc2hipaagdpr-ccpa

google-calendar · ingress

Block Public Visibility & Guest Delegation

Blocks Google Calendar create and update event calls that would expose the event to the world or hand control of it to guests.

google-calendarguard-public-exposureingresssoc2gdpr-ccpa

confluence · ingress

Block Secrets in Confluence Pages and Comments

Blocks Confluence write calls whose body looks like it contains a live credential — an API key, password, token, or PEM-formatted private key — before the…

confluencesecretsdlpingresssoc2atlassian

github · ingress

Block Secrets in GitHub Commits & PRs

Blocks GitHub write tool calls whose payload looks like it carries a live credential into a repository, gist, pull request, or comment.

githubsecretsdlpingresssoc2

slack · ingress

Block Secrets in Slack Messages

Blocks Slack send-message tool calls whose message body looks like it contains a secret — API keys, passwords, tokens, or PEM-formatted private keys.

slacksecretsdlpingresssoc2iso27001-nist

zoom · ingress

Block Secrets in Zoom Team Chat

Blocks Zoom Team Chat send/update tool calls whose message content looks like it contains a live secret — API keys, passwords, bearer tokens, or…

zoomblock-secretsdlpingresssoc2

asana · ingress

Cap Asana Batch Task Mutations

Caps the blast radius of Asana's official V2 batch write tools. At ingress it:

asanacap-bulk-exportbatch-mutationingresssoc2

glean · ingress

Cap Glean Bulk Search Export

Clamps the bulk-export parameters on Glean search calls before they reach the Glean MCP server, so a single agent request cannot pull an entire indexed…

gleancap-bulk-exportdata-minimisationingresssoc2hipaagdpr-ccpa

google-drive · ingress

Cap Google Drive Search & Listing Page Sizes

Clamps the page size of Google Drive search and listing calls to a documented cap (25 results per call).

google-drivecap-bulk-exportdata-minimizationingresssoc2hipaagdpr-ccpa

intercom · ingress

Cap Intercom Contact Enumeration

caller is a CRM admin); clamp page size on everything else; allow the rest

intercomcap-bulk-exportcontact-enumerationdlpingresssoc2hipaapci-dssgdpr-ccpa

quickbooks · ingress

Cap QuickBooks Bulk Search Exports

Clamps the bulk-read levers on every QuickBooks Online search tool so an agent cannot pull the entire general ledger — or a full customer, vendor, or…

quickbookscap-bulk-exportbulk-exportdlpingresssoc2pci-dssgdpr-ccpa

airtable · ingress

Clamp Bulk Airtable Record Reads

Airtable bases routinely hold CRM contacts, applicant-tracking pipelines, customer/financial trackers, and — on HIPAA-eligible Enterprise plans — health-ops…

airtablecap-bulk-exportingresssoc2gdpr-ccpa

airtable · ingress

Confine Airtable Agent to Allowlisted Bases

An Airtable OAuth grant (or Personal Access Token) with the workspacesAndBases:read scope spans the entire workspace — every base the connected identity can…

airtablefence-sensitive-scopesingresssoc2gdpr-ccpa

confluence · ingress

Confluence: Deny Org-Wide & Public Publication

Stops a prompt-injected or erring agent from broadcasting Confluence content org-wide or to anonymous external readers.

confluenceatlassiandeny-public-exposurepublicationgovernanceingressfinserv-commseu-ai-actsoc2gdpr-ccpa

confluence · ingress

Confluence: Freeze Page & Attachment Deletion

Freezes the two irreversible Confluence deletion tools on the agent channel: confluence delete page and confluence delete attachment.

confluenceatlassianfreeze-destructive-opsdata-protectioningresssoc2

notion · ingress

Constrain Notion Connected-Tool Search

Notion's hosted MCP server (notion-search) does not just search Notion pages — through Notion AI connectors it also searches connected Slack, Google Drive,…

notionconstrain-aggregatoringresssoc2

databricks · ingress

Databricks Default-Deny Unknown Tools

Pins an allowlist of the exact Databricks tool names your team audited and denies every other tool name on the Databricks MCP server(s).

databricksdefault-deny-unknown-toolsallowlistaccess-controlingresssoc2

databricks · ingress

Databricks: Role-Gate Compute & Job Control

The community JustTryAI/databricks-mcp-server exposes cluster and job control — create cluster, start cluster, terminate cluster, run job, and export…

databricksrole-gate-writesaccess-controlleast-privilegeingresssoc2

airtable · ingress

Default-Deny Unaudited Airtable Tools

Maintains a per-tenant allowlist of audited Airtable tool-name suffixes and denies any call whose tool name does not end with an allowlisted entry.

airtabledefault-deny-unknown-toolsallowlistingresssoc2

bigquery · ingress

Default-Deny Unaudited BigQuery Tools

Maintains a per-tenant allowlist of audited BigQuery tool-name suffixes and denies any call whose tool name does not end with an allowlisted entry.

bigquerydefault-deny-unknown-toolsallowlistaccess-controlingresssoc2

gusto · ingress

Default-Deny Unknown Gusto Tools

Pins an allowlist of the 36 official Gusto MCP tool names and allows a call only when lower(input.resource.name) is an exact member of that list.

gustodefault-deny-unknown-toolsallowlistingresssoc2

linear · ingress

Default-Deny Unknown Linear Tools

Pins an audited allowlist of the verified official Linear MCP tool names and allows a call only when the incoming tool name matches an allowlisted name on…

lineardefault-deny-unknown-toolsallowlistingresssoc2

monday · ingress

Default-Deny Unknown monday Tools

Maintains a per-tenant allowlist of audited monday tool-name suffixes and denies any call whose tool name does not end with an allowlisted entry.

mondaydefault-deny-unknown-toolsallowlistingresssoc2

power-bi · ingress

Default-Deny Unknown Power BI Modeling Tools

Pins a per-tenant allowlist of audited Power BI tool-name suffixes and denies any call whose tool name does not end with an allowlisted entry.

power-bidefault-deny-unknown-toolsallowlistmodelingingresssoc2

servicenow · ingress

Default-Deny Unknown ServiceNow Tools

Maintains an allowlist of audited ServiceNow tool-name suffixes and denies any tool call whose name does not match an allowlisted entry.

servicenowdefault-deny-unknown-toolsallowlistingresssoc2

tableau · ingress

Default-Deny Unknown Tableau Tools

Fails closed on tool drift. The policy carries a pinned allowlist of the 39 tools in the verified official Tableau web toolset (tableau/tableau-mcp v2.24.

tableaudefault-denyunknown-toolsallowlistingresssoc2

zapier · ingress

Default-Deny Unknown Zapier Tools

Maintains an allowlist of audited Zapier tool-name suffixes and denies any tool call whose name does not match an allowlisted entry, with an alert-worthy…

zapierdefault-deny-unknown-toolsallowlistingresssoc2

gmail · ingress

Deny Agent Email Sends to External Recipients

Denies Gmail send-class tool calls when any recipient in to, cc, or bcc falls outside a documented corporate-domain allowlist.

gmailguard-external-sendingressemailsoc2hipaagdpr-ccpa

onboarding · ingress

Deny Email PII

This policy stops a request if it contains an email address. If there's no email address, the request goes through as normal.

onboardingpiiemaildlpingress

ms365 · ingress

Deny Graph API Batch Escape Hatch

Blocks the Microsoft 365 MCP server's raw-Graph passthrough tool (graph-batch, observed live as ms365-graph-batch).

ms365deny-escape-hatchesingressiso27001-nistsoc2

stripe · ingress

Deny Stripe API-Write Escape Hatch

Denies the stripe api write meta-tool — the single raw passthrough on the official Stripe MCP server that can execute any Stripe POST, PATCH, PUT, or DELETE…

stripedeny-escape-hatchesingresssoxsoc2

onboarding · ingress

Detect Email PII (Allow with Reason)

A watch-only starter policy.

onboardingpiiemailobservabilityingress

confluence · ingress

Fence Confluence Reads & Search to Non-Restricted Spaces

Fences a configurable set of restricted Confluence spaces (placeholder keys: HR, LEGAL, SEC) out of the agent's read and search paths unless the caller's IdP…

confluenceatlassianfence-sensitive-scopesaccess-controlingresssoc2hipaagdpr-ccpa

github · ingress

Fence GitHub Access to the Company Org Allowlist

Denies any GitHub tool call whose arguments.owner (read from input.payload.args.

githubfence-sensitive-scopesorg-allowlistanti-exfilingresssoc2

glean · ingress

Fence Glean Search by Datasource

Glean's search tool fans out across every system the tenant has indexed (Drive, Confluence, Slack, Jira, Gmail/Outlook, GitHub, Salesforce, Gong, HR…

gleanfence-sensitive-scopesaccess-controldatasourceingresssoc2hipaagdpr-ccpa

gusto · ingress

Fence Gusto Compensation & Payroll Reads

Denies the highest-sensitivity Gusto read tools unless the caller's IdP-asserted groups include the placeholder group hr-payroll-admins.

gustofence-hr-and-credit-scopecompensationpayrollingresssoc2gdpr-ccpa

intercom · ingress

Fence Intercom Contact & Company PII Reads

Gates Intercom's structured-PII read surface — customer contact and company profiles — by IdP group.

intercomfence-sensitive-scopescontact-readspiiingresssoc2hipaapci-dssgdpr-ccpa

netsuite · ingress

Fence NetSuite HR & Payroll SuiteQL Queries

Fences the single biggest exfiltration surface on the NetSuite MCP server — ns runCustomSuiteQL, which runs arbitrary read-only SuiteQL across the entire ERP.

netsuitefence-sensitive-scopesingressgdpr-ccpasoc2

notion · ingress

Fence Notion Member Directory to Admin & IT

Denies calls to the Notion member-directory tool (notion-get-users, matched by the -get-users suffix) unless the caller's IdP groups include an admin or IT…

notionfence-sensitive-scopesaccess-controlpiiingresssoc2gdpr-ccpa

bigquery · ingress

Fence Regulated BigQuery Datasets by Group

Fences customer-designated regulated BigQuery data domains by data-domain IdP group, at ingress, before any statement or metadata lookup reaches BigQuery.

bigqueryfence-sensitive-scopesingressrbacsoc2hipaapci-dssgdpr-ccpa

google-drive · ingress

Fence Restricted Google Drive Files and Folders

Fences an admin-maintained denylist of restricted Google Drive file and folder IDs — HR records, M&A deal rooms, board packs, payroll — off the agent channel:

google-drivefence-restricted-folderssensitive-scopesingresssoc2hipaagdpr-ccpa

box · ingress

Fence Sensitive Box Folders by IdP Group

Fences pinned sensitive Box subtrees (HR, Finance, Legal, …) by ID.

boxfence-sensitive-scopesingresssoc2hipaagdpr-ccpa

databricks · ingress

Fence Sensitive Databricks Schemas

Fences off the most sensitive lakehouse namespaces from agents on the read side of Databricks.

databricksfence-sensitive-scopesingresssoc2hipaapci-dssgdpr-ccpa

dropbox · ingress

Fence Sensitive Dropbox Paths by Team

Fences protected Dropbox subtrees by path prefix . Dropbox addresses files and folders by a root-relative path (/Finance/2026/payroll.

dropboxfence-sensitive-scopesingresssoc2hipaagdpr-ccpa

monday · ingress

Fence Sensitive monday Boards by IdP Group

monday boards are schemaless business databases: HR/recruiting boards (candidate PII), CRM/deal boards (financial), and IT/security trackers routinely live…

mondayfence-sensitive-scopesingresssoc2gdpr-ccpa

servicenow · ingress

Fence Sensitive ServiceNow Tables

Fences off the most sensitive ServiceNow tables from two routes that reach them:

servicenowfence-sensitive-tablespiiingresssoc2hipaapci-dssgdpr-ccpa

snowflake · ingress

Fence Snowflake Sensitive Schemas by Data Domain

Fences customer-designated sensitive data domains inside a Snowflake warehouse by inspecting the SQL text the agent is about to run — not by tool name, which…

snowflakefence-sensitive-scopesingresssoc2hipaapci-dssgdpr-ccpa

tableau · ingress

Fence Tableau Datasource Scope

Tableau's MCP server is a warehouse proxy: query-datasource runs a VizQL Data Service (VDS) query and returns raw row-level data — PII, PHI, payroll,…

tableaufence-sensitive-scopesaccess-controldatasourceingresssoc2gdpr-ccpa

asana · ingress

Fence Writes to Sensitive Asana Projects

Asana is routinely used for HR (hiring, performance, offboarding), legal, M&A, and incident work; those project bodies, comments, custom fields, and status…

asanafence-sensitive-scopesingresssoc2gdpr-ccpa

zoom · ingress

Fence Zoom Agentic Search to Native Corpora

Constrains Zoom's agentic-search tool ( search zoom) so it can only reach Zoom-native content.

zoomagentic-searchconstrain-aggregatoringresssoc2gdpr-ccpa

docusign · ingress

Force Docusign Envelopes to Draft

Rewrites Docusign envelope-creation calls so the envelope is staged as a (status: "sent").

docusignforce-draft-envelopesesignhuman-in-the-loopingress

jira · ingress

Force Internal Visibility on JSM Comments

Keeps agent-drafted Jira Service Management (JSM) comments off the customer-facing portal by rewriting addCommentToJiraIssue calls to carry a restrictive…

jiraforce-internal-commentscommentsjsmservice-managementingresssoc2atlassian

servicenow · ingress

Force ServiceNow Comments to Internal Work Notes

Keeps agent-drafted ServiceNow comments off the customer/employee-visible journal by rewriting add comment calls to internal work notes.

servicenowforce-internal-commentscommentswork-notesingresssoc2finra

airtable · ingress

Freeze Destructive Airtable Deletes

Denies every destructive Airtable tool call unless the caller's IdP token carries the placeholder group airtable-admins.

airtablefreeze-destructive-opsrecord-integrityingresssoc2

google-calendar · ingress

Freeze Destructive and Series-Wide Calendar Changes

Denies irreversible Google Calendar mutations on the agent channel:

google-calendarfreeze-destructive-opsingressintegritysoc2

asana · ingress

Freeze Destructive Asana Operations

Denies every destructive Asana tool call unless the caller's IdP token carries the placeholder group asana-admins.

asanafreeze-destructive-opsrecord-integrityingresssoc2

box · ingress

Freeze Destructive Box Operations

Freezes deletes and retention tampering on the community self-hosted Box MCP server (box-community/mcp-server-box).

boxfreeze-destructive-opsingresssoc2

dropbox · ingress

Freeze Destructive Dropbox Operations

Freezes the irreversible and bulk-mutation Dropbox tools on the agent channel, regardless of path. At ingress it denies, by tool-name suffix:

dropboxfreeze-destructive-opsingresssoc2

gmail · ingress

Freeze Destructive Gmail Operations

Denies the irreversible destruction surface that community Gmail MCP servers expose — permanent email deletion, label deletion, and filter deletion — for…

gmailfreeze-destructive-opsrecord-integrityingresssoc2

google-drive · ingress

Freeze Destructive Google Drive Operations

Blocks Google Drive delete operations issued by agents.

google-drivefreeze-destructive-opsintegrityingresssoc2

linear · ingress

Freeze Destructive Linear Operations

Denies destructive Linear tool calls — the delete , archive , and session-logout classes — unless the caller's IdP token carries the placeholder group…

linearfreeze-destructive-opsrecord-integrityingresssoc2

ms365 · ingress

Freeze Destructive Microsoft 365 Operations

Denies every Microsoft 365 tool call whose verb segment is delete- or cancel- unless the caller's IdP token carries the placeholder group m365-admin.

ms365freeze-destructive-opsrecord-integrityingresssoxsoc2

monday · ingress

Freeze Destructive monday Operations

Splits monday's destructive tool surface into two tiers and treats each differently at ingress, before the call ever reaches the monday MCP server:

mondayfreeze-destructive-opsrecord-integrityingresssoc2

quickbooks · ingress

Freeze Destructive QuickBooks Operations

Denies every destructive QuickBooks Online (QBO) tool call on the agent channel before it reaches the MCP server.

quickbooksfreeze-destructive-opsingresssoxsoc2

tableau · ingress

Freeze Destructive Tableau Content Ops

Denies the irreversible content-mutation tools on the official tableau/tableau-mcp web server unless the caller's IdP token carries the placeholder group…

tableaufreeze-destructive-opsrecord-integrityingresssoc2

ms365 · ingress

Freeze M365 Identity Plane

Freezes directory and membership mutations on the Microsoft 365 MCP surface. The policy denies, by tool-name suffix:

ms365freeze-identity-planeingressidentityentragroupsiso27001-nistsoc2

notion · ingress

Freeze Notion Full-Page Content Overwrites

Denies notion-update-page calls whose command argument is replace content — the one edge on Notion's hosted MCP server that overwrites a page's entire body…

notionfreeze-destructive-opsrecord-integrityingresssoc2

gusto · ingress

Freeze Payroll Writes in Gusto

Freezes every write and delete operation on a Gusto pipeline.

gustofreeze-destructive-opsingress

power-bi · ingress

Freeze Power BI RLS Role Edits

Freezes edits to row-level-security (RLS) roles on the Power BI MCP surface.

power-bifreeze-identity-planeingressrlsidentitygroupssoc2iso27001-nist

salesforce · ingress

Freeze Salesforce Record Deletes

Denies all Salesforce record-deletion capability on the agent channel unless the caller's IdP groups claim contains the placeholder group sf-admins.

salesforcefreeze-destructive-opsingresscrmsoc2

servicenow · ingress

Freeze ServiceNow Identity Plane

Freezes the identity-and-access mutation surface of the ServiceNow MCP server. The policy denies, by tool-name suffix:

servicenowfreeze-identity-planeingressidentitygroupssoc2iso27001-nist

monday · ingress

Freeze Standing Automation & AI Agents in monday

Denies the monday tools that install side effects which outlive the governed MCP session. Two classes of tool are blocked:

mondayconstrain-aggregatoringresssoc2

zapier · ingress

Freeze the Zapier Toolset (No Self-Expansion)

In its default agentic mode, Zapier MCP exposes meta-tools that let the agent widen its own blast radius mid-session : enable zapier action and auto…

zapierconstrain-aggregatoringresssoc2

google-drive · ingress

Gate Google Drive Writes to an Authorized IdP Group

Baseline least-privilege policy for Google Drive MCP traffic.

google-driverole-gate-writesleast-privilegeingresssoc2gdpr-ccpa

quickbooks · ingress

Gate QuickBooks Money-Movement by Finance Group

Gates the QuickBooks Online money-movement creation tools — create payment, create bill payment, create refund receipt, create transfer, and create deposit —…

quickbooksgate-money-movementingresssoxpci-dss

zoom · ingress

Gate Zoom Transcripts & Recordings by Group

Gates retrieval of Zoom meeting transcripts, AI Companion summaries, and next-steps on the connector's core egress tools, enforcing minimum-necessary access:

zoomguard-transcriptsingresshipaagdpr-ccpasoc2

glean · ingress

Glean Default-Deny Unknown Tools

Pins a per-tenant allowlist of the verified built-in read tools on the Glean managed remote MCP server and denies every other tool suffix on the Glean server…

gleandefault-deny-unknown-toolsallowlistaccess-controlingresssoc2

glean · ingress

Glean: Gate Memory Writes (Read-Only Default)

Gates mutating calls to Glean's long-term memory surface — the built-in tool exposed as memory (and as read memory in Glean's own client guide).

gleangate-memory-writesrole-gate-writesmemoryaccess-controlleast-privilegeingresssoc2

gmail · ingress

Gmail Cap Bulk Export

Throttles mass-harvesting of a mailbox by capping the per-call blast radius of the two Gmail MCP surfaces that return many full email bodies at once:

gmailcap-bulk-exportdata-minimisationingresssoc2hipaagdpr-ccpa

gmail · ingress

Gmail: Role-Gated Writes (Read-Only Default)

Makes Gmail read-only by default on the MCP path. Verified read tools pass for everyone.

gmailrole-gate-writesaccess-controlleast-privilegeingresssoc2gdpr-ccpa

box · ingress

Guard Box Share Links and External Collaborations

Blocks the externally-visible Box sharing surface — the riskiest Box surface an agent can touch — before the call ever reaches Box:

boxguard-share-linkssharingexternal-sharingingresssoc2hipaagdpr-ccpa

tableau · ingress

Guard Calculation Expressions in Tableau VDS Queries

Inspects the structured VizQL Data Service (VDS) query carried by Tableau's query-datasource tool and denies the call for callers outside the data-analysts…

tableauguard-warehouse-sqlingresscalculationvizqlsoc2

databricks · ingress

Guard Databricks SQL Against Writes and DDL

Inspects the SQL statement string that Databricks SQL-executing tools carry in their argument and denies any statement that performs a write, schema change,…

databricksguard-warehouse-sqlingresssqlreadonlypci-dsssoxsoc2

power-bi · ingress

Guard DAX Whole-Table Dumps in Power BI

Power BI semantic models front the warehouse: a model imports or DirectQueries lakehouse/warehouse tables — finance, HR, customer PII.

power-biguard-warehouse-sqlingressdaxexfiltrationsoc2gdpr-ccpa

docusign · ingress

Guard Docusign External Recipients

Blocks Docusign envelope-creation and recipient-update tool calls when any recipient email address has a domain outside the configured counterparty allowlist.

docusignguard-external-sendingresssoc2gdpr-ccpa

google-drive · ingress

Guard Drive ACL Reconnaissance

Denies Google Drive get file permissions tool calls unless the caller's IdP groups claim contains infosec. All other tool calls pass through unchanged.

google-driveguard-share-linksaclsharingingresssoc2

ms365 · ingress

Guard OneDrive/SharePoint Share Links

Stops agents from opening OneDrive/SharePoint files to the whole internet. It guards the two Microsoft 365 sharing tools:

ms365share-linkssharingingresssoc2iso27001-nisthipaagdpr-ccpa

quickbooks · ingress

Guard Vendor Banking and Tax-ID Changes

Blocks create vendor and update vendor calls whose arguments carry a vendor's payment coordinates — bank account number, routing / ACH branch details — or…

quickbooksvendor-bankinganti-becingresssox

gusto · ingress

Gusto Cap Roster Export

Throttles full-roster exfiltration on Gusto's two broad outbound list tools — list company employees and list company contractors — by rewriting their…

gustocap-bulk-exportpiidata-minimisationingressgdpr-ccpasoc2

hubspot · ingress

HubSpot Block Deal Closure

Blocks HubSpot CRM-object calls that move a deal into a closed stage (closedwon or closedlost). Both create and update requests are inspected.

hubspotdealsaccess-controlgovernanceingress

hubspot · ingress

HubSpot Cap Bulk Export

Clamps the page size of HubSpot bulk-read tool calls before they reach the HubSpot MCP server, so a single agent request to a covered bulk-read tool can…

hubspotcap-bulk-exportpiidata-minimisationingresssoc2hipaapci-dssgdpr-ccpa

hubspot · ingress

HubSpot Freeze Destructive Ops

Blocks every archive/deletion-class HubSpot tool call, plus the consent-destroying contact unsubscribe, before it reaches the MCP server.

hubspotfreeze-destructive-opsarchiveconsentingresssoc2

hubspot · ingress

HubSpot Protect Associations

Blocks HubSpot CRM-object calls that create or change associations between objects (deal↔company, contact↔company, etc.).

hubspotassociationsaccess-controlgovernanceingress

hubspot · ingress

HubSpot Protect Deal Owner

Blocks HubSpot CRM-object update calls that set or change a deal's owner.

hubspotdealsaccess-controlgovernanceingress

hubspot · ingress

HubSpot Protect Lifecycle Stage

Blocks HubSpot CRM-object calls that set or change a contact's lifecycle stage.

hubspotcontactslifecycleaccess-controlgovernanceingress

hubspot · ingress

HubSpot Read-Only

Makes the HubSpot connection read-only by blocking the write tool.

hubspotaccess-controlgovernanceread-onlyingresssoc2gdpr-ccpa

hubspot · ingress

HubSpot Role-Gate Schema and Consent

Sits one privilege tier above hubspot/role-gate-writes: ordinary crm-writers can create and edit CRM records, but two higher-blast-radius write classes are…

hubspotrole-gate-schema-consentaccess-controlleast-privilegesegregation-of-dutiesconsentingresssoc2

hubspot · ingress

HubSpot Role-Gate Writes

Gates every HubSpot write tool behind an IdP group: callers whose JWT groups claim contains crm-writers may create and update CRM records; everyone else gets…

hubspotrole-gate-writesaccess-controlleast-privilegeingresssoc2gdpr-ccpa

servicenow · ingress

Human-Only ServiceNow Change Approval

Unconditionally denies the ServiceNow change-management control-gate tools — the ones whose names end in approve change, reject change, or submit change for…

servicenowrequire-human-approvalchange-managementseparation-of-dutiesingresssoc2

stripe · ingress

Human-Only Stripe Dispute Submission

Strips the irreversible submit flag from Stripe update dispute tool calls.

striperequire-human-approvaldisputesseparation-of-dutiestransformingresssox

intercom · ingress

Intercom: Keep Agent Help Center Articles in Draft

Keeps agent-authored Intercom Help Center articles in draft so a human reviews them before they go live on the public Help Center.

intercomdeny-public-exposureingressarticleshelp-centerpublicationgovernancesoc2

jira · ingress

JIRA: Block Change-History Actor Spoofing

Blocks any official Jira write call — transitionJiraIssue, editJiraIssue, or createJiraIssue — that carries a historyMetadata block, before it reaches the…

jiraatlassianfreeze-destructive-opsaudit-integrityingresssoc2

jira · ingress

JIRA: Cap Field and Result Exposure on Reads

Narrows the breadth of JIRA read requests before they run, on the two read surfaces that can pull large amounts of issue data into model context:

jiraatlassiancap-bulk-exportdata-minimisationingresssoc2gdpr-ccpa

jira · ingress

JIRA: Deny Sensitive Project Search and View

Keeps issues that belong to a configurable set of "sensitive" JIRA projects out of read access through the JIRA MCP server.

jiraatlassianaccess-controldata-protectioningresssoc2gdpr-ccpaiso27001-nistfinserv-comms

jira · ingress

JIRA: Freeze Destructive Issue Operations

Freezes the three irreversible Jira operations on the agent channel: jira delete issue, jira remove issue link, and jira remove watcher.

jiraatlassianfreeze-destructive-opsrecord-integritydata-protectioningresssoc2

jira · ingress

JIRA: Protect Sensitive Projects from Writes

Blocks write operations against issues that belong to a configurable set of "sensitive" JIRA projects.

jiraatlassianaccess-controldata-protectioningresssoc2gdpr-ccpaiso27001-nistfinserv-comms

quickbooks · ingress

Lock Direct Journal-Entry Ledger Writes

Denies the QuickBooks Online tools create journal entry and update journal entry at ingress for every caller except those whose IdP claims include the…

quickbooksprotect-closed-periodsingresssox

netsuite · ingress

NetSuite Cap SuiteQL Bulk Export

Instantiates the PF-08 cap-bulk-export family as a transform-only ingress policy on ns runCustomSuiteQL — the NetSuite MCP tool that runs arbitrary read-only…

netsuitecap-bulk-exportsuiteqldata-minimisationingresssoc2pci-dssgdpr-ccpa

netsuite · ingress

NetSuite Default-Deny Unknown MCP Tools

Pins an allowlist of the audited NetSuite MCP Standard Tools and denies every other tool call before it reaches the NetSuite AI Connector.

netsuitedefault-deny-unknown-toolsallowlistaccess-controlingresssoc2

netsuite · ingress

NetSuite Guard Vendor Banking Edits (Anti-BEC)

Instantiates policy family PF-10 (guard-vendor-banking) — the anti-BEC / payment-fraud control — for the Oracle NetSuite MCP Standard Tools SuiteApp.

netsuiteguard-vendor-bankingingresssox

github · ingress

Prevent Public Exposure of GitHub Repos, Gists & Forks

Stops the agent from exposing private code to the public across three GitHub write tools, at ingress — before the call reaches the GitHub MCP server, so a…

githubdeny-public-exposureanti-exfilingresssoc2finserv-commseu-ai-act

netsuite · ingress

Protect Financial Postings by Role

Denies the NetSuite record-write tools ns createRecord and ns updateRecord when they target a financial-transaction record type — journalentry (including the…

netsuiteprotect-closed-periodsingresssox

ms365 · ingress

Read-Only Baseline: Group-Gated Microsoft 365 Writes

The least-privilege baseline for Microsoft 365 through the gateway: every tool call is allowed only if it is a read , or the caller's IdP token carries the…

ms365role-gate-writesingressleast-privilegesoc2gdpr-ccpasox

github · ingress

Read-Only GitHub for Non-Engineers

Establishes the least-privilege baseline for the GitHub MCP connector on the agent channel.

githubrole-gate-writesingresssoc2sox

stripe · ingress

Read-Only Stripe by Default (Role-Gate Billing Writes)

Establishes a read-only-by-default Stripe posture over the MCP path. The named write and destructive billing tools —

striperole-gate-writesingressleast-privilegerbacsoc2pci-dsssoxgdpr-ccpa

github · ingress

Require Human Approval: GitHub Merges & Approvals

Keeps a human in the loop on the two GitHub actions that consummate a code change: merging a pull request and approving one .

githubrequire-human-approvalingresssoc2sox

zapier · ingress

Role-Gate All Zapier Writes

Zapier MCP is an aggregator: one connector proxies actions across 9,000+ apps, and every create/update/delete/send funnels through a small, predictable…

zapierrole-gate-writesingresssoc2gdpr-ccpa

dropbox · ingress

Role-Gate Dropbox Writes to the Writers Group

Establishes the per-app least-privilege write floor for Dropbox.

dropboxrole-gate-writesrbacleast-privilegeingresssoc2gdpr-ccpa

salesforce · ingress

Salesforce Cap Bulk Data Export

Blocks bulk PII extraction through Salesforce query tools by inspecting the free-text query arguments that are the real policy surface for these servers.

salesforcecap-bulk-exportdata-minimizationdlpingresssoc2hipaapci-dssgdpr-ccpa

salesforce · ingress

Salesforce Deny API Escape Hatches

Unconditionally denies the raw-code and raw-API tools exposed by the community Salesforce MCP servers — tools that bypass every object- and argument-level…

salesforcedeny-escape-hatchesaccess-controlingresssoc2iso27001-nist

salesforce · ingress

Salesforce Protect Contact Fields

Blocks Salesforce Contact updates that modify protected fields — ownership, account linkage, contact PII, name, and consent flags.

salesforcecontactspiiaccess-controlgovernanceingresssoc2gdpr-ccpaiso27001-nist

salesforce · ingress

Salesforce Query Allowlist

Restricts Salesforce SOQL queries so only Account, Contact, and Opportunity records can be retrieved.

salesforceaccess-controldata-protectiongovernanceingresssoc2pci-dssgdpr-ccpaiso27001-nist

salesforce · ingress

Salesforce Read-Only Access

Restricts the Salesforce MCP server to read-only access.

salesforceaccess-controlgovernanceread-onlyingresssoc2gdpr-ccpaiso27001-nist

salesforce · ingress

Salesforce Role-Gated Writes

The PF-12 least-privilege baseline for Salesforce.

salesforcerole-gate-writesaccess-controlleast-privilegeingresssoc2gdpr-ccpacrm

stripe · ingress

Scrub Unapproved Stripe Payment-Link Redirects

Scrubs the post-payment redirect from Stripe payment-link creation calls.

stripeguard-share-linksingresstransformphishingprompt-injectionsoc2

slack · ingress

Slack Role-Gate Writes

Gates every Slack write-class tool behind an IdP group: callers whose JWT groups claim contains slack-writers may send and schedule messages, add or remove…

slackrole-gate-writesaccess-controlleast-privilegeingresssoc2gdpr-ccpa

slack · ingress

Slack: Block Agent Posts to External Channels

Denies Slack message-write calls whose destination is an externally shared Slack Connect channel.

slackguard-external-sendslack-connectexfiltrationingresssoc2gdpr-ccpahipaa

slack · ingress

Slack: Deny Channel Creation

Blocks Slack channel-creation tool calls at ingress. Every other Slack tool — and every non-Slack tool — passes through untouched.

slackaccess-controlgovernanceingresssoc2iso27001-nist

slack · ingress

Slack: Deny DM and Private-Conversation Reads and Search

Denies the agent read reach into Slack DMs and private conversations on the paths below — the workspace's highest concentration of PII/PHI (HR issues, health…

slackprivacydmaccess-controlingresssoc2gdpr-ccpa

slack · ingress

Slack: Deny Read/Search/Summarize of Sensitive Channels

Blocks read, search, and summarize operations that target a configurable set of "sensitive" Slack channels.

slackaccess-controldata-protectioningresssoc2hipaagdpr-ccpaiso27001-nist

slack · ingress

Slack: Deny Sending Direct Messages

Blocks Slack message-write calls whose destination resolves to a direct conversation — a 1:1 DM, a message posted to a user ID (which Slack auto-opens as a…

slackaccess-controlgovernanceingresssoc2iso27001-nistfinserv-comms

slack · ingress

Slack: Redact Sensitive Information from Messages

Redacts sensitive content from outgoing Slack message arguments before the call reaches Slack.

slackpiisecretsdlpredactioningresssoc2hipaagdpr-ccpaiso27001-nist

snowflake · ingress

Snowflake Default-Deny Unknown Tools

Pins an allowlist of the exact Snowflake tool names your team audited and denies every other tool name on the Snowflake MCP server(s).

snowflakedefault-deny-unknown-toolsallowlistaccess-controlingresssoc2

snowflake · ingress

Snowflake Deny Composite & Generic Tools

Denies the opaque composite and generic passthrough tools on the Snowflake-managed MCP server whose execution the gateway cannot inspect one SQL statement at…

snowflakedeny-escape-hatchesaccess-controlcortexingresssoc2iso27001-nist

stripe · ingress

Stripe Refund Group Gate and Amount Cap

Denies Stripe refund tool calls — money out, irreversible — unless the caller's IdP groups include finance or billing-admin.

stripegate-money-movementingresspci-dsssox