soc2
173 Dtwo policies tagged "soc2", including Airtable: Redact PII in Record Reads, Asana: Redact PII in Task & Comment Reads. Browse by what the control does rather than which app it targets.
On this page
Airtable
Airtable: Redact PII in Record ReadsScans the responses of the Airtable record-read tools — the calls that return row fields values — and rewrites high-confidence PII shapes to a fixed…Clamp Bulk Airtable Record ReadsAirtable bases routinely hold CRM contacts, applicant-tracking pipelines, customer/financial trackers, and — on HIPAA-eligible Enterprise plans — health-ops…Confine Airtable Agent to Allowlisted BasesAn Airtable OAuth grant (or Personal Access Token) with the workspacesAndBases:read scope spans the entire workspace — every base the connected identity can…Default-Deny Unaudited Airtable ToolsMaintains a per-tenant allowlist of audited Airtable tool-name suffixes and denies any call whose tool name does not end with an allowlisted entry.Freeze Destructive Airtable DeletesDenies every destructive Airtable tool call unless the caller's IdP token carries the placeholder group airtable-admins.
Asana
Asana: Redact PII in Task & Comment ReadsOn the Asana MCP read path, this transform scans the free-text business fields that ride back in task, comment/story, and status-update responses — notes,…Cap Asana Batch Task MutationsCaps the blast radius of Asana's official V2 batch write tools. At ingress it:Fence Writes to Sensitive Asana ProjectsAsana is routinely used for HR (hiring, performance, offboarding), legal, M&A, and incident work; those project bodies, comments, custom fields, and status…Freeze Destructive Asana OperationsDenies every destructive Asana tool call unless the caller's IdP token carries the placeholder group asana-admins.
BigQuery
BigQuery: Redact PII in Query ResultsScans the content returned by BigQuery's result-returning tools and rewrites high-confidence PII shapes to fixed, non-recoverable redaction tokens before the…Block BigQuery Exfiltration and Cross-Project WritesInspects the raw GoogleSQL string carried by BigQuery SQL tools and denies any statement that moves data out of the tenant's own project — even when the call…Block Destructive SQL in BigQuery QueriesInspects the raw GoogleSQL string carried by BigQuery write-capable query tools and denies any statement in a state-changing class — DML…Default-Deny Unaudited BigQuery ToolsMaintains a per-tenant allowlist of audited BigQuery tool-name suffixes and denies any call whose tool name does not end with an allowlisted entry.Fence Regulated BigQuery Datasets by GroupFences customer-designated regulated BigQuery data domains by data-domain IdP group, at ingress, before any statement or metadata lookup reaches BigQuery.
Box
Box: Redact PII from File Content on EgressScans the responses of Box content-returning tools and rewrites personally identifiable information to fixed redaction tokens before the response reaches the…Box: Role-Gated Writes (Read-Only Default)Makes Box read-only by default on the MCP path.Fence Sensitive Box Folders by IdP GroupFences pinned sensitive Box subtrees (HR, Finance, Legal, …) by ID.Freeze Destructive Box OperationsFreezes deletes and retention tampering on the community self-hosted Box MCP server (box-community/mcp-server-box).Guard Box Share Links and External CollaborationsBlocks the externally-visible Box sharing surface — the riskiest Box surface an agent can touch — before the call ever reaches Box:
Confluence
Block Secrets in Confluence Pages and CommentsBlocks Confluence write calls whose body looks like it contains a live credential — an API key, password, token, or PEM-formatted private key — before the…Confluence: Deny Org-Wide & Public PublicationStops a prompt-injected or erring agent from broadcasting Confluence content org-wide or to anonymous external readers.Confluence: Freeze Page & Attachment DeletionFreezes the two irreversible Confluence deletion tools on the agent channel: confluence delete page and confluence delete attachment.Confluence: Redact PII from Page & Comment ResponsesScans the responses of Confluence page, comment, and search read tools and rewrites personally identifiable information to fixed redaction tokens before the…Fence Confluence Reads & Search to Non-Restricted SpacesFences a configurable set of restricted Confluence spaces (placeholder keys: HR, LEGAL, SEC) out of the agent's read and search paths unless the caller's IdP…
Databricks
Databricks Default-Deny Unknown ToolsPins an allowlist of the exact Databricks tool names your team audited and denies every other tool name on the Databricks MCP server(s).Databricks: Mask Cardholder PANs in ResponsesMasks payment-card numbers (PANs) in Databricks tool responses before the agent receives them.Databricks: Redact PII in Tool ResponsesScans the response payloads of the Databricks MCP tools that carry lakehouse data back to the agent and rewrites personally identifiable information to fixed…Databricks: Role-Gate Compute & Job ControlThe community JustTryAI/databricks-mcp-server exposes cluster and job control — create cluster, start cluster, terminate cluster, run job, and export…Fence Sensitive Databricks SchemasFences off the most sensitive lakehouse namespaces from agents on the read side of Databricks.Guard Databricks SQL Against Writes and DDLInspects the SQL statement string that Databricks SQL-executing tools carry in their argument and denies any statement that performs a write, schema change,…
DocuSign
Block Irreversible Docusign Void and Workflow KillsDenies the irreversible destructive operations on the Docusign agent path:Cap Docusign Directory and Document EgressBounds the two largest data-out channels in the Docusign MCP landscape:Docusign: Redact SSN, Bank & Card Values on EgressScans the responses of Docusign envelope- and agreement-reading tools and rewrites high-confidence regulated identifiers before the response reaches the…Guard Docusign External RecipientsBlocks Docusign envelope-creation and recipient-update tool calls when any recipient email address has a domain outside the configured counterparty allowlist.
Dropbox
Block Public Dropbox Share, Download, and File-Request LinksDenies, by default, the Dropbox tools that turn an internal file into an internet-visible resource in a single call — before the request ever reaches Dropbox:Dropbox: Redact PII, PANs, and Secrets in File ContentScans the responses of the Dropbox file-content read tools and sanitises the returned text before it reaches the agent.Fence Sensitive Dropbox Paths by TeamFences protected Dropbox subtrees by path prefix . Dropbox addresses files and folders by a root-relative path (/Finance/2026/payroll.Freeze Destructive Dropbox OperationsFreezes the irreversible and bulk-mutation Dropbox tools on the agent channel, regardless of path. At ingress it denies, by tool-name suffix:Role-Gate Dropbox Writes to the Writers GroupEstablishes the per-app least-privilege write floor for Dropbox.
GitHub
Block Secrets in GitHub Commits & PRsBlocks GitHub write tool calls whose payload looks like it carries a live credential into a repository, gist, pull request, or comment.Fence GitHub Access to the Company Org AllowlistDenies any GitHub tool call whose arguments.owner (read from input.payload.args.GitHub: Redact Secrets from Read ResponsesScans the responses of GitHub's crown-jewel read tools and masks known credential shapes with a fixed [REDACTED-SECRET] marker before the text enters agent…Prevent Public Exposure of GitHub Repos, Gists & ForksStops the agent from exposing private code to the public across three GitHub write tools, at ingress — before the call reaches the GitHub MCP server, so a…Read-Only GitHub for Non-EngineersEstablishes the least-privilege baseline for the GitHub MCP connector on the agent channel.Require Human Approval: GitHub Merges & ApprovalsKeeps a human in the loop on the two GitHub actions that consummate a code change: merging a pull request and approving one .
Glean
Cap Glean Bulk Search ExportClamps the bulk-export parameters on Glean search calls before they reach the Glean MCP server, so a single agent request cannot pull an entire indexed…Fence Glean Search by DatasourceGlean's search tool fans out across every system the tenant has indexed (Drive, Confluence, Slack, Jira, Gmail/Outlook, GitHub, Salesforce, Gong, HR…Glean Default-Deny Unknown ToolsPins a per-tenant allowlist of the verified built-in read tools on the Glean managed remote MCP server and denies every other tool suffix on the Glean server…Glean: Gate Memory Writes (Read-Only Default)Gates mutating calls to Glean's long-term memory surface — the built-in tool exposed as memory (and as read memory in Glean's own client guide).Glean: Redact PII from Read-Tool ResponsesScans the responses of Glean's content-returning read tools and rewrites high-confidence PII to fixed redaction tokens before the response reaches the…
Gmail
Block Gmail Filter Creation (Auto-Forward Persistence)Blocks the classic BEC/exfiltration persistence primitive: Gmail filters that can auto-forward or auto-delete mail and outlive the agent session.Deny Agent Email Sends to External RecipientsDenies Gmail send-class tool calls when any recipient in to, cc, or bcc falls outside a documented corporate-domain allowlist.Freeze Destructive Gmail OperationsDenies the irreversible destruction surface that community Gmail MCP servers expose — permanent email deletion, label deletion, and filter deletion — for…Gmail Cap Bulk ExportThrottles mass-harvesting of a mailbox by capping the per-call blast radius of the two Gmail MCP surfaces that return many full email bodies at once:Gmail: Role-Gated Writes (Read-Only Default)Makes Gmail read-only by default on the MCP path. Verified read tools pass for everyone.Mask Card Numbers in Email Content Read by AgentsMasks payment-card-number (PAN) shapes in email content returned to agents by Gmail mailbox-read tools.
Google Calendar
Block Calendar Invites to External AttendeesDenies Google Calendar event-write tool calls — create event / create-event, update event / update-event, and the consolidated manage event — whenever any…Block Public Visibility & Guest DelegationBlocks Google Calendar create and update event calls that would expose the event to the world or hand control of it to guests.Freeze Destructive and Series-Wide Calendar ChangesDenies irreversible Google Calendar mutations on the agent channel:Redact Attendee PII and Meeting Links in Calendar ReadsScrubs sensitive fields from the responses of Google Calendar read tools before they reach the agent, for callers who lack the placeholder calendar-full-read…
Google Drive
Cap Google Drive Search & Listing Page SizesClamps the page size of Google Drive search and listing calls to a documented cap (25 results per call).Fence Restricted Google Drive Files and FoldersFences an admin-maintained denylist of restricted Google Drive file and folder IDs — HR records, M&A deal rooms, board packs, payroll — off the agent channel:Freeze Destructive Google Drive OperationsBlocks Google Drive delete operations issued by agents.Gate Google Drive Writes to an Authorized IdP GroupBaseline least-privilege policy for Google Drive MCP traffic.Google Drive: Redact PII from File ContentScans the responses of the content-returning Google Drive tools — file reads, downloads, and Docs/Sheets/Slides content fetches — and rewrites personally…Guard Drive ACL ReconnaissanceDenies Google Drive get file permissions tool calls unless the caller's IdP groups claim contains infosec. All other tool calls pass through unchanged.
Gusto
Default-Deny Unknown Gusto ToolsPins an allowlist of the 36 official Gusto MCP tool names and allows a call only when lower(input.resource.name) is an exact member of that list.Fence Gusto Compensation & Payroll ReadsDenies the highest-sensitivity Gusto read tools unless the caller's IdP-asserted groups include the placeholder group hr-payroll-admins.Gusto Cap Roster ExportThrottles full-roster exfiltration on Gusto's two broad outbound list tools — list company employees and list company contractors — by rewriting their…Gusto: Redact Financial IDs in ResponsesInstantiates PF-02 (redact-pii-egress) on the Gusto read path.
HubSpot
HubSpot Cap Bulk ExportClamps the page size of HubSpot bulk-read tool calls before they reach the HubSpot MCP server, so a single agent request to a covered bulk-read tool can…HubSpot Freeze Destructive OpsBlocks every archive/deletion-class HubSpot tool call, plus the consent-destroying contact unsubscribe, before it reaches the MCP server.HubSpot Read-OnlyMakes the HubSpot connection read-only by blocking the write tool.HubSpot Redact PIIRedacts sensitive contact information from HubSpot tool responses before they reach the caller.HubSpot Role-Gate Schema and ConsentSits one privilege tier above hubspot/role-gate-writes: ordinary crm-writers can create and edit CRM records, but two higher-blast-radius write classes are…HubSpot Role-Gate WritesGates every HubSpot write tool behind an IdP group: callers whose JWT groups claim contains crm-writers may create and update CRM records; everyone else gets…
Intercom
Cap Intercom Contact Enumerationcaller is a CRM admin); clamp page size on everything else; allow the restFence Intercom Contact & Company PII ReadsGates Intercom's structured-PII read surface — customer contact and company profiles — by IdP group.Intercom: Keep Agent Help Center Articles in DraftKeeps agent-authored Intercom Help Center articles in draft so a human reviews them before they go live on the public Help Center.Intercom: Mask Card Numbers in Conversation ResponsesMasks payment-card numbers (PANs) in Intercom conversation content returned to agents by the conversation- and free-text-returning read tools.Intercom: Redact PII from Conversation & Contact ReadsScans the free-text returned by Intercom's conversation- and contact-read MCP tools and rewrites high-confidence personal identifiers and credential shapes…
Jira
Force Internal Visibility on JSM CommentsKeeps agent-drafted Jira Service Management (JSM) comments off the customer-facing portal by rewriting addCommentToJiraIssue calls to carry a restrictive…JIRA: Block Change-History Actor SpoofingBlocks any official Jira write call — transitionJiraIssue, editJiraIssue, or createJiraIssue — that carries a historyMetadata block, before it reaches the…JIRA: Cap Field and Result Exposure on ReadsNarrows the breadth of JIRA read requests before they run, on the two read surfaces that can pull large amounts of issue data into model context:JIRA: Deny Sensitive Project Search and ViewKeeps issues that belong to a configurable set of "sensitive" JIRA projects out of read access through the JIRA MCP server.JIRA: Freeze Destructive Issue OperationsFreezes the three irreversible Jira operations on the agent channel: jira delete issue, jira remove issue link, and jira remove watcher.JIRA: Protect Sensitive Projects from WritesBlocks write operations against issues that belong to a configurable set of "sensitive" JIRA projects.JIRA: Redact Sensitive Information from Issue ViewsRedacts sensitive content from the responses of JIRA issue-view tools before they reach the caller.JIRA: Role-Gated Writes (Read-Only Default)Makes Jira read-only by default on the MCP path.
Linear
Block Linear Webhook CreationUnconditionally denies any Linear tool that creates, updates, or deletes a webhook — linear createWebhook, linear deleteWebhook, and update variants.Default-Deny Unknown Linear ToolsPins an audited allowlist of the verified official Linear MCP tool names and allows a call only when the incoming tool name matches an allowlisted name on…Fence Roadmap and Initiative Reads (Egress)Fences the responses of Linear's roadmap, initiative, and strategy read tools.Freeze Destructive Linear OperationsDenies destructive Linear tool calls — the delete , archive , and session-logout classes — unless the caller's IdP token carries the placeholder group…Linear: Redact Customer Revenue and ContactsMasks commercial and contact identifiers in the responses of Linear's Customers read tools before they reach the agent.
Microsoft 365
Block Agent Email to External RecipientsBlocks agent-initiated Microsoft 365 email sends when any recipient address falls outside a corporate-domain allowlist.Block Mail-Rule and Webhook PersistenceUnconditionally denies the classic business-email-compromise (BEC) persistence surface in Microsoft 365: creating or updating Outlook mail rules, changing…Deny Graph API Batch Escape HatchBlocks the Microsoft 365 MCP server's raw-Graph passthrough tool (graph-batch, observed live as ms365-graph-batch).Freeze Destructive Microsoft 365 OperationsDenies every Microsoft 365 tool call whose verb segment is delete- or cancel- unless the caller's IdP token carries the placeholder group m365-admin.Freeze M365 Identity PlaneFreezes directory and membership mutations on the Microsoft 365 MCP surface. The policy denies, by tool-name suffix:Guard OneDrive/SharePoint Share LinksStops agents from opening OneDrive/SharePoint files to the whole internet. It guards the two Microsoft 365 sharing tools:Microsoft 365: Redact PII from Mail, Files & TranscriptsScans the responses of the highest-density PII read surfaces in Microsoft 365 — mail bodies, Excel ranges, SharePoint list items, meeting transcripts, and…Read-Only Baseline: Group-Gated Microsoft 365 WritesThe least-privilege baseline for Microsoft 365 through the gateway: every tool call is allowed only if it is a read , or the caller's IdP token carries the…
Monday.com
Default-Deny Unknown monday ToolsMaintains a per-tenant allowlist of audited monday tool-name suffixes and denies any call whose tool name does not end with an allowlisted entry.Fence Sensitive monday Boards by IdP Groupmonday boards are schemaless business databases: HR/recruiting boards (candidate PII), CRM/deal boards (financial), and IT/security trackers routinely live…Freeze Destructive monday OperationsSplits monday's destructive tool surface into two tiers and treats each differently at ingress, before the call ever reaches the monday MCP server:Freeze Standing Automation & AI Agents in mondayDenies the monday tools that install side effects which outlive the governed MCP session. Two classes of tool are blocked:monday: Redact PII in Board & Doc ReadsTwo egress controls in one policy, both scoped to the monday MCP read path:
NetSuite
Fence NetSuite HR & Payroll SuiteQL QueriesFences the single biggest exfiltration surface on the NetSuite MCP server — ns runCustomSuiteQL, which runs arbitrary read-only SuiteQL across the entire ERP.NetSuite Cap SuiteQL Bulk ExportInstantiates the PF-08 cap-bulk-export family as a transform-only ingress policy on ns runCustomSuiteQL — the NetSuite MCP tool that runs arbitrary read-only…NetSuite Default-Deny Unknown MCP ToolsPins an allowlist of the audited NetSuite MCP Standard Tools and denies every other tool call before it reaches the NetSuite AI Connector.NetSuite: Redact Financial PII in ResponsesInstantiates PF-02 (redact-pii-egress) on the NetSuite read path.
Notion
Block Destructive and Export SQL on Notion Data SourcesInspects Notion data-source query tool calls (notion-query-data-sources on the hosted server, query-data-source on the official local server) and denies any…Constrain Notion Connected-Tool SearchNotion's hosted MCP server (notion-search) does not just search Notion pages — through Notion AI connectors it also searches connected Slack, Google Drive,…Fence Notion Member Directory to Admin & ITDenies calls to the Notion member-directory tool (notion-get-users, matched by the -get-users suffix) unless the caller's IdP groups include an admin or IT…Freeze Notion Full-Page Content OverwritesDenies notion-update-page calls whose command argument is replace content — the one edge on Notion's hosted MCP server that overwrites a page's entire body…Notion: Redact PII from Read ResponsesScans the responses of the Notion hosted MCP server's content-returning read tools and rewrites personally identifiable information to fixed redaction tokens…
Power BI
Block Power BI RLS-Bypass Service-Principal QueriesOn Microsoft's remote Power BI MCP server (https://api.fabric.microsoft.Default-Deny Unknown Power BI Modeling ToolsPins a per-tenant allowlist of audited Power BI tool-name suffixes and denies any call whose tool name does not end with an allowlisted entry.Freeze Power BI RLS Role EditsFreezes edits to row-level-security (RLS) roles on the Power BI MCP surface.Guard DAX Whole-Table Dumps in Power BIPower BI semantic models front the warehouse: a model imports or DirectQueries lakehouse/warehouse tables — finance, HR, customer PII.Power BI: Redact PII in Query ResultsScans the content returned by Power BI's result-returning tools and rewrites high-confidence PII shapes to fixed, non-recoverable redaction tokens before the…
QuickBooks
Cap QuickBooks Bulk Search ExportsClamps the bulk-read levers on every QuickBooks Online search tool so an agent cannot pull the entire general ledger — or a full customer, vendor, or…Freeze Destructive QuickBooks OperationsDenies every destructive QuickBooks Online (QBO) tool call on the agent channel before it reaches the MCP server.QuickBooks: Redact Employee & Vendor PII on ReadOn the read path, this policy masks sensitive identifiers in the responses of four QuickBooks Online (QBO) name-entity read tools — get employee, search…
Salesforce
Freeze Salesforce Record DeletesDenies all Salesforce record-deletion capability on the agent channel unless the caller's IdP groups claim contains the placeholder group sf-admins.Salesforce Cap Bulk Data ExportBlocks bulk PII extraction through Salesforce query tools by inspecting the free-text query arguments that are the real policy surface for these servers.Salesforce Deny API Escape HatchesUnconditionally denies the raw-code and raw-API tools exposed by the community Salesforce MCP servers — tools that bypass every object- and argument-level…Salesforce Protect Contact FieldsBlocks Salesforce Contact updates that modify protected fields — ownership, account linkage, contact PII, name, and consent flags.Salesforce Query AllowlistRestricts Salesforce SOQL queries so only Account, Contact, and Opportunity records can be retrieved.Salesforce Read-Only AccessRestricts the Salesforce MCP server to read-only access.Salesforce Redact PIIRedacts personal contact information from Salesforce tool responses before they reach the caller.Salesforce Role-Gated WritesThe PF-12 least-privilege baseline for Salesforce.
ServiceNow
Default-Deny Unknown ServiceNow ToolsMaintains an allowlist of audited ServiceNow tool-name suffixes and denies any tool call whose name does not match an allowlisted entry.Fence Sensitive ServiceNow TablesFences off the most sensitive ServiceNow tables from two routes that reach them:Force ServiceNow Comments to Internal Work NotesKeeps agent-drafted ServiceNow comments off the customer/employee-visible journal by rewriting add comment calls to internal work notes.Freeze ServiceNow Identity PlaneFreezes the identity-and-access mutation surface of the ServiceNow MCP server. The policy denies, by tool-name suffix:Human-Only ServiceNow Change ApprovalUnconditionally denies the ServiceNow change-management control-gate tools — the ones whose names end in approve change, reject change, or submit change for…ServiceNow: Role-Gated Writes (Read-Only Default)else fails closed
Slack
Block Secrets in Slack MessagesBlocks Slack send-message tool calls whose message body looks like it contains a secret — API keys, passwords, tokens, or PEM-formatted private keys.Slack Role-Gate WritesGates every Slack write-class tool behind an IdP group: callers whose JWT groups claim contains slack-writers may send and schedule messages, add or remove…Slack: Block Agent Posts to External ChannelsDenies Slack message-write calls whose destination is an externally shared Slack Connect channel.Slack: Deny Channel CreationBlocks Slack channel-creation tool calls at ingress. Every other Slack tool — and every non-Slack tool — passes through untouched.Slack: Deny DM and Private-Conversation Reads and SearchDenies the agent read reach into Slack DMs and private conversations on the paths below — the workspace's highest concentration of PII/PHI (HR issues, health…Slack: Deny Read/Search/Summarize of Sensitive ChannelsBlocks read, search, and summarize operations that target a configurable set of "sensitive" Slack channels.Slack: Deny Sending Direct MessagesBlocks Slack message-write calls whose destination resolves to a direct conversation — a 1:1 DM, a message posted to a user ID (which Slack auto-opens as a…Slack: Mask Card Numbers in Message and Search ResponsesMasks payment-card numbers (PANs) in Slack content returned to agents by message-read, thread-read, canvas-read, history, and search tools.Slack: Redact Profile PII from User LookupsRedacts personally identifiable information — email addresses, phone numbers, and Slack custom profile fields (which commonly carry phone, title, and…Slack: Redact Sensitive Information from MessagesRedacts sensitive content from outgoing Slack message arguments before the call reaches Slack.
Snowflake
Block Bulk Export & External Staging (Snowflake)Blocks Snowflake SQL-execution tool calls whose query text moves whole tables off the Snowflake perimeter — bulk export to cloud storage or a stage, and…Block Destructive and Mutating Snowflake SQLInspects the SQL text that Snowflake MCP tools carry in their query argument and denies any statement in a mutating or destructive class — DROP, TRUNCATE,…Fence Snowflake Sensitive Schemas by Data DomainFences customer-designated sensitive data domains inside a Snowflake warehouse by inspecting the SQL text the agent is about to run — not by tool name, which…Snowflake Default-Deny Unknown ToolsPins an allowlist of the exact Snowflake tool names your team audited and denies every other tool name on the Snowflake MCP server(s).Snowflake Deny Composite & Generic ToolsDenies the opaque composite and generic passthrough tools on the Snowflake-managed MCP server whose execution the gateway cannot inspect one SQL statement at…Snowflake: Redact PII from Query Result SetsScans the row content returned by the result-returning Snowflake MCP tools and rewrites personally identifiable information to fixed redaction tokens before…
Stripe
Deny Stripe API-Write Escape HatchDenies the stripe api write meta-tool — the single raw passthrough on the official Stripe MCP server that can execute any Stripe POST, PATCH, PUT, or DELETE…Read-Only Stripe by Default (Role-Gate Billing Writes)Establishes a read-only-by-default Stripe posture over the MCP path. The named write and destructive billing tools —Scrub Unapproved Stripe Payment-Link RedirectsScrubs the post-payment redirect from Stripe payment-link creation calls.Stripe: Redact Customer PII from Bulk ReadsMasks customer PII in the responses of Stripe's bulk PII egress channels before they reach the agent.
Tableau
Default-Deny Unknown Tableau ToolsFails closed on tool drift. The policy carries a pinned allowlist of the 39 tools in the verified official Tableau web toolset (tableau/tableau-mcp v2.24.Fence Tableau Datasource ScopeTableau's MCP server is a warehouse proxy: query-datasource runs a VizQL Data Service (VDS) query and returns raw row-level data — PII, PHI, payroll,…Freeze Destructive Tableau Content OpsDenies the irreversible content-mutation tools on the official tableau/tableau-mcp web server unless the caller's IdP token carries the placeholder group…Guard Calculation Expressions in Tableau VDS QueriesInspects the structured VizQL Data Service (VDS) query carried by Tableau's query-datasource tool and denies the call for callers outside the data-analysts…Tableau: Redact PII & Mask PANs in Query ResultsTableau is a warehouse proxy: the data-returning tools stream raw row-level content out of whatever the published datasource connects to — PII, PHI, payroll,…
Zapier
Block External Sends Hidden in Zapier InstructionsEvery Zapier MCP tool — in both the agentic and classic modes — accepts a free-text instructions string that Zapier's server-side AI uses to fill any…Default-Deny Unknown Zapier ToolsMaintains an allowlist of audited Zapier tool-name suffixes and denies any tool call whose name does not match an allowlisted entry, with an alert-worthy…Freeze the Zapier Toolset (No Self-Expansion)In its default agentic mode, Zapier MCP exposes meta-tools that let the agent widen its own blast radius mid-session : enable zapier action and auto…Role-Gate All Zapier WritesZapier MCP is an aggregator: one connector proxies actions across 9,000+ apps, and every create/update/delete/send funnels through a small, predictable…Zapier: Mask Card Numbers in Read ResponsesMasks payment-card numbers (PANs) in Zapier MCP read responses before they reach the agent.
Zoom
Block External Team Chat Invites & MembersStops a Zoom Team Chat agent from pulling external parties into the organization's chat surface.Block Secrets in Zoom Team ChatBlocks Zoom Team Chat send/update tool calls whose message content looks like it contains a live secret — API keys, passwords, bearer tokens, or…Fence Zoom Agentic Search to Native CorporaConstrains Zoom's agentic-search tool ( search zoom) so it can only reach Zoom-native content.Gate Zoom Transcripts & Recordings by GroupGates retrieval of Zoom meeting transcripts, AI Companion summaries, and next-steps on the connector's core egress tools, enforcing minimum-necessary access:Zoom: Redact PII in Meeting IntelligenceScans the responses of Zoom's meeting-intelligence read surfaces — AI summaries, verbatim transcripts, recording resources, and Zoom Docs content — and…