Airtable: Redact PII in Record Reads
Scans the responses of the Airtable record-read tools — the calls that return row fields values — and rewrites high-confidence PII shapes to a fixed…
Scans the responses of the Airtable record-read tools — the calls that return row fields values — and rewrites high-confidence PII shapes to a fixed…
On the Asana MCP read path, this transform scans the free-text business fields that ride back in task, comment/story, and status-update responses — notes,…
Scans the content returned by BigQuery's result-returning tools and rewrites high-confidence PII shapes to fixed, non-recoverable redaction tokens before the…
Blocks agent-initiated Microsoft 365 email sends when any recipient address falls outside a corporate-domain allowlist.
Inspects the raw GoogleSQL string carried by BigQuery SQL tools and denies any statement that moves data out of the tenant's own project — even when the call…
bigqueryguard-warehouse-exportingresssqlexfiltrationsoc2pci-dssgdpr-ccpa
Blocks Snowflake SQL-execution tool calls whose query text moves whole tables off the Snowflake perimeter — bulk export to cloud storage or a stage, and…
snowflakeguard-warehouse-sqlexportexfiltrationingresssoc2pci-dssgdpr-ccpa
Denies Google Calendar event-write tool calls — create event / create-event, update event / update-event, and the consolidated manage event — whenever any…
google-calendarguard-external-sendingresscalendarsoc2hipaagdpr-ccpa
Every Zapier MCP tool — in both the agentic and classic modes — accepts a free-text instructions string that Zapier's server-side AI uses to fill any…
Stops a Zoom Team Chat agent from pulling external parties into the organization's chat surface.
Denies, by default, the Dropbox tools that turn an internal file into an internet-visible resource in a single call — before the request ever reaches Dropbox:
dropboxguard-share-linkssharingexternal-sharingingresssoc2hipaagdpr-ccpa
Blocks Google Calendar create and update event calls that would expose the event to the world or hand control of it to guests.
Makes Box read-only by default on the MCP path.
boxrole-gate-writesaccess-controlleast-privilegeingresssoc2gdpr-ccpa
Bounds the two largest data-out channels in the Docusign MCP landscape:
docusigncap-bulk-exportpiidata-minimisationegresssoc2gdpr-ccpa
Clamps the bulk-export parameters on Glean search calls before they reach the Glean MCP server, so a single agent request cannot pull an entire indexed…
gleancap-bulk-exportdata-minimisationingresssoc2hipaagdpr-ccpa
Clamps the page size of Google Drive search and listing calls to a documented cap (25 results per call).
google-drivecap-bulk-exportdata-minimizationingresssoc2hipaagdpr-ccpa
caller is a CRM admin); clamp page size on everything else; allow the rest
intercomcap-bulk-exportcontact-enumerationdlpingresssoc2hipaapci-dssgdpr-ccpa
Clamps the bulk-read levers on every QuickBooks Online search tool so an agent cannot pull the entire general ledger — or a full customer, vendor, or…
quickbookscap-bulk-exportbulk-exportdlpingresssoc2pci-dssgdpr-ccpa
Airtable bases routinely hold CRM contacts, applicant-tracking pipelines, customer/financial trackers, and — on HIPAA-eligible Enterprise plans — health-ops…
An Airtable OAuth grant (or Personal Access Token) with the workspacesAndBases:read scope spans the entire workspace — every base the connected identity can…
Stops a prompt-injected or erring agent from broadcasting Confluence content org-wide or to anonymous external readers.
confluenceatlassiandeny-public-exposurepublicationgovernanceingressfinserv-commseu-ai-actsoc2gdpr-ccpa
Scans the responses of Confluence page, comment, and search read tools and rewrites personally identifiable information to fixed redaction tokens before the…
confluenceatlassianredact-piipiidlpredactionegresssoc2hipaagdpr-ccpa
Masks payment-card numbers (PANs) in Databricks tool responses before the agent receives them.
databricksmask-pan-egressegresscardholder-datadlpsoc2pci-dssgdpr-ccpa
Scans the response payloads of the Databricks MCP tools that carry lakehouse data back to the agent and rewrites personally identifiable information to fixed…
Denies Gmail send-class tool calls when any recipient in to, cc, or bcc falls outside a documented corporate-domain allowlist.
Scans the responses of Docusign envelope- and agreement-reading tools and rewrites high-confidence regulated identifiers before the response reaches the…
docusignredact-piitab-valuespiiphipandlpredactionegresssoc2gdpr-ccpa
Scans the responses of the Dropbox file-content read tools and sanitises the returned text before it reaches the agent.
dropboxredact-contentredact-piimask-pansecretspiidlpegresssoc2hipaagdpr-ccpa
Fences a configurable set of restricted Confluence spaces (placeholder keys: HR, LEGAL, SEC) out of the agent's read and search paths unless the caller's IdP…
confluenceatlassianfence-sensitive-scopesaccess-controlingresssoc2hipaagdpr-ccpa
Glean's search tool fans out across every system the tenant has indexed (Drive, Confluence, Slack, Jira, Gmail/Outlook, GitHub, Salesforce, Gong, HR…
gleanfence-sensitive-scopesaccess-controldatasourceingresssoc2hipaagdpr-ccpa
Denies the highest-sensitivity Gusto read tools unless the caller's IdP-asserted groups include the placeholder group hr-payroll-admins.
gustofence-hr-and-credit-scopecompensationpayrollingresssoc2gdpr-ccpa
Gates Intercom's structured-PII read surface — customer contact and company profiles — by IdP group.
intercomfence-sensitive-scopescontact-readspiiingresssoc2hipaapci-dssgdpr-ccpa
Fences the single biggest exfiltration surface on the NetSuite MCP server — ns runCustomSuiteQL, which runs arbitrary read-only SuiteQL across the entire ERP.
Denies calls to the Notion member-directory tool (notion-get-users, matched by the -get-users suffix) unless the caller's IdP groups include an admin or IT…
notionfence-sensitive-scopesaccess-controlpiiingresssoc2gdpr-ccpa
Fences customer-designated regulated BigQuery data domains by data-domain IdP group, at ingress, before any statement or metadata lookup reaches BigQuery.
bigqueryfence-sensitive-scopesingressrbacsoc2hipaapci-dssgdpr-ccpa
Fences an admin-maintained denylist of restricted Google Drive file and folder IDs — HR records, M&A deal rooms, board packs, payroll — off the agent channel:
google-drivefence-restricted-folderssensitive-scopesingresssoc2hipaagdpr-ccpa
Fences pinned sensitive Box subtrees (HR, Finance, Legal, …) by ID.
Fences off the most sensitive lakehouse namespaces from agents on the read side of Databricks.
databricksfence-sensitive-scopesingresssoc2hipaapci-dssgdpr-ccpa
Fences protected Dropbox subtrees by path prefix . Dropbox addresses files and folders by a root-relative path (/Finance/2026/payroll.
monday boards are schemaless business databases: HR/recruiting boards (candidate PII), CRM/deal boards (financial), and IT/security trackers routinely live…
Fences off the most sensitive ServiceNow tables from two routes that reach them:
servicenowfence-sensitive-tablespiiingresssoc2hipaapci-dssgdpr-ccpa
Fences customer-designated sensitive data domains inside a Snowflake warehouse by inspecting the SQL text the agent is about to run — not by tool name, which…
snowflakefence-sensitive-scopesingresssoc2hipaapci-dssgdpr-ccpa
Tableau's MCP server is a warehouse proxy: query-datasource runs a VizQL Data Service (VDS) query and returns raw row-level data — PII, PHI, payroll,…
tableaufence-sensitive-scopesaccess-controldatasourceingresssoc2gdpr-ccpa
Asana is routinely used for HR (hiring, performance, offboarding), legal, M&A, and incident work; those project bodies, comments, custom fields, and status…
Constrains Zoom's agentic-search tool ( search zoom) so it can only reach Zoom-native content.
Baseline least-privilege policy for Google Drive MCP traffic.
google-driverole-gate-writesleast-privilegeingresssoc2gdpr-ccpa
Gates retrieval of Zoom meeting transcripts, AI Companion summaries, and next-steps on the connector's core egress tools, enforcing minimum-necessary access:
Scans the responses of Glean's content-returning read tools and rewrites high-confidence PII to fixed redaction tokens before the response reaches the…
Throttles mass-harvesting of a mailbox by capping the per-call blast radius of the two Gmail MCP surfaces that return many full email bodies at once:
gmailcap-bulk-exportdata-minimisationingresssoc2hipaagdpr-ccpa
Makes Gmail read-only by default on the MCP path. Verified read tools pass for everyone.
gmailrole-gate-writesaccess-controlleast-privilegeingresssoc2gdpr-ccpa
Scans the responses of the content-returning Google Drive tools — file reads, downloads, and Docs/Sheets/Slides content fetches — and rewrites personally…
google-driveredact-piipiidlpredactionegresssoc2hipaagdpr-ccpa
Blocks the externally-visible Box sharing surface — the riskiest Box surface an agent can touch — before the call ever reaches Box:
boxguard-share-linkssharingexternal-sharingingresssoc2hipaagdpr-ccpa
Power BI semantic models front the warehouse: a model imports or DirectQueries lakehouse/warehouse tables — finance, HR, customer PII.
power-biguard-warehouse-sqlingressdaxexfiltrationsoc2gdpr-ccpa
Blocks Docusign envelope-creation and recipient-update tool calls when any recipient email address has a domain outside the configured counterparty allowlist.
Stops agents from opening OneDrive/SharePoint files to the whole internet. It guards the two Microsoft 365 sharing tools:
ms365share-linkssharingingresssoc2iso27001-nisthipaagdpr-ccpa
Throttles full-roster exfiltration on Gusto's two broad outbound list tools — list company employees and list company contractors — by rewriting their…
gustocap-bulk-exportpiidata-minimisationingressgdpr-ccpasoc2
Instantiates PF-02 (redact-pii-egress) on the Gusto read path.
gustoredact-pii-egressredact-piipiifinancial-piidlpredactionegresssoc2gdpr-ccpa
Clamps the page size of HubSpot bulk-read tool calls before they reach the HubSpot MCP server, so a single agent request to a covered bulk-read tool can…
hubspotcap-bulk-exportpiidata-minimisationingresssoc2hipaapci-dssgdpr-ccpa
Makes the HubSpot connection read-only by blocking the write tool.
hubspotaccess-controlgovernanceread-onlyingresssoc2gdpr-ccpa
Gates every HubSpot write tool behind an IdP group: callers whose JWT groups claim contains crm-writers may create and update CRM records; everyone else gets…
hubspotrole-gate-writesaccess-controlleast-privilegeingresssoc2gdpr-ccpa
Masks payment-card numbers (PANs) in Intercom conversation content returned to agents by the conversation- and free-text-returning read tools.
intercommask-pan-egressegresscardholder-datadlpsoc2pci-dssgdpr-ccpa
Scans the free-text returned by Intercom's conversation- and contact-read MCP tools and rewrites high-confidence personal identifiers and credential shapes…
Narrows the breadth of JIRA read requests before they run, on the two read surfaces that can pull large amounts of issue data into model context:
jiraatlassiancap-bulk-exportdata-minimisationingresssoc2gdpr-ccpa
Keeps issues that belong to a configurable set of "sensitive" JIRA projects out of read access through the JIRA MCP server.
jiraatlassianaccess-controldata-protectioningresssoc2gdpr-ccpaiso27001-nistfinserv-comms
Blocks write operations against issues that belong to a configurable set of "sensitive" JIRA projects.
jiraatlassianaccess-controldata-protectioningresssoc2gdpr-ccpaiso27001-nistfinserv-comms
Makes Jira read-only by default on the MCP path.
jiraatlassianrole-gate-writesaccess-controlleast-privilegeingresssoc2gdpr-ccpa
Masks commercial and contact identifiers in the responses of Linear's Customers read tools before they reach the agent.
Masks payment-card-number (PAN) shapes in email content returned to agents by Gmail mailbox-read tools.
gmailmask-pan-egressegressemailcardholder-datadlpsoc2pci-dssgdpr-ccpa
Scans the responses of the highest-density PII read surfaces in Microsoft 365 — mail bodies, Excel ranges, SharePoint list items, meeting transcripts, and…
Two egress controls in one policy, both scoped to the monday MCP read path:
Instantiates the PF-08 cap-bulk-export family as a transform-only ingress policy on ns runCustomSuiteQL — the NetSuite MCP tool that runs arbitrary read-only…
netsuitecap-bulk-exportsuiteqldata-minimisationingresssoc2pci-dssgdpr-ccpa
Instantiates PF-02 (redact-pii-egress) on the NetSuite read path.
netsuiteredact-piipiifinancial-piidlpredactionegressgdpr-ccpasoc2
Scans the responses of the Notion hosted MCP server's content-returning read tools and rewrites personally identifiable information to fixed redaction tokens…
Scans the content returned by Power BI's result-returning tools and rewrites high-confidence PII shapes to fixed, non-recoverable redaction tokens before the…
On the read path, this policy masks sensitive identifiers in the responses of four QuickBooks Online (QBO) name-entity read tools — get employee, search…
The least-privilege baseline for Microsoft 365 through the gateway: every tool call is allowed only if it is a read , or the caller's IdP token carries the…
Establishes a read-only-by-default Stripe posture over the MCP path. The named write and destructive billing tools —
striperole-gate-writesingressleast-privilegerbacsoc2pci-dsssoxgdpr-ccpa
Scrubs sensitive fields from the responses of Google Calendar read tools before they reach the agent, for callers who lack the placeholder calendar-full-read…
google-calendarredact-piipiiphidlpredactionegresssoc2hipaagdpr-ccpa
Zapier MCP is an aggregator: one connector proxies actions across 9,000+ apps, and every create/update/delete/send funnels through a small, predictable…
Establishes the per-app least-privilege write floor for Dropbox.
dropboxrole-gate-writesrbacleast-privilegeingresssoc2gdpr-ccpa
Blocks bulk PII extraction through Salesforce query tools by inspecting the free-text query arguments that are the real policy surface for these servers.
salesforcecap-bulk-exportdata-minimizationdlpingresssoc2hipaapci-dssgdpr-ccpa
Blocks Salesforce Contact updates that modify protected fields — ownership, account linkage, contact PII, name, and consent flags.
salesforcecontactspiiaccess-controlgovernanceingresssoc2gdpr-ccpaiso27001-nist
Restricts Salesforce SOQL queries so only Account, Contact, and Opportunity records can be retrieved.
salesforceaccess-controldata-protectiongovernanceingresssoc2pci-dssgdpr-ccpaiso27001-nist
Restricts the Salesforce MCP server to read-only access.
salesforceaccess-controlgovernanceread-onlyingresssoc2gdpr-ccpaiso27001-nist
Redacts personal contact information from Salesforce tool responses before they reach the caller.
salesforcepiidlpredactionegresssoc2hipaagdpr-ccpaiso27001-nist
The PF-12 least-privilege baseline for Salesforce.
salesforcerole-gate-writesaccess-controlleast-privilegeingresssoc2gdpr-ccpacrm
else fails closed
servicenowrole-gate-writesaccess-controlleast-privilegeingresssoc2gdpr-ccpa
Gates every Slack write-class tool behind an IdP group: callers whose JWT groups claim contains slack-writers may send and schedule messages, add or remove…
slackrole-gate-writesaccess-controlleast-privilegeingresssoc2gdpr-ccpa
Denies Slack message-write calls whose destination is an externally shared Slack Connect channel.
slackguard-external-sendslack-connectexfiltrationingresssoc2gdpr-ccpahipaa
Denies the agent read reach into Slack DMs and private conversations on the paths below — the workspace's highest concentration of PII/PHI (HR issues, health…
Blocks read, search, and summarize operations that target a configurable set of "sensitive" Slack channels.
slackaccess-controldata-protectioningresssoc2hipaagdpr-ccpaiso27001-nist
Masks payment-card numbers (PANs) in Slack content returned to agents by message-read, thread-read, canvas-read, history, and search tools.
slackmask-pan-egressegresscardholder-datadlppci-dsssoc2gdpr-ccpa
Scans the row content returned by the result-returning Snowflake MCP tools and rewrites personally identifiable information to fixed redaction tokens before…
Masks customer PII in the responses of Stripe's bulk PII egress channels before they reach the agent.
Tableau is a warehouse proxy: the data-returning tools stream raw row-level content out of whatever the published datasource connects to — PII, PHI, payroll,…
tableauredact-pii-egresspiipandlpredactionegresssoc2gdpr-ccpa
Masks payment-card numbers (PANs) in Zapier MCP read responses before they reach the agent.
zapiermask-pan-egressegresscardholder-datadlpsoc2pci-dssgdpr-ccpa
Scans the responses of Zoom's meeting-intelligence read surfaces — AI summaries, verbatim transcripts, recording resources, and Zoom Docs content — and…
The General Data Protection Regulation (Regulation (EU) 2016/679) governs any processing of EU personal data; the California Consumer Privacy Act, as amended by the CPRA (Cal. Civ. Code §1798.100 et seq.) governs California consumers' personal information — including employees' and B2B contacts' — with a distinct category of sensitive personal information and new rules on automated decision-making. When an AI agent reads and writes customer, employee, and prospect data across connected SaaS apps, that is processing attributable to the controller under GDPR and collection, use, and disclosure by the business under CCPA. Every over-broad query, every field returned to the model, every agent-initiated disclosure is a compliance event on that path. This bundle is a starting posture for it: scope each tool call, gate it by identity, minimise what comes back, and block the disclosures the frameworks care about.
These policies support alignment with GDPR & CCPA/CPRA on the MCP path only. They act on the tool calls an AI agent makes through the DTwo gateway; web-UI logins, native-API integrations, and in-app activity are outside their reach by design, and no policy or bundle makes an organization GDPR- or CCPA-compliant. Both frameworks impose obligations — legal bases, contracts, notices, data-subject-request fulfilment, retention, encryption at rest, residency — that no gateway can satisfy. Compliance is a property of your whole program.
100 policies across 31 apps, grouped below by the GDPR/CCPA control they support. Every policy is single-purpose and composes with the others on the same pipeline direction. Policy bodies live under apps/; this page only links to them.
The per-decision audit log that records every one of these calls — principal, action, resource, context, decision — is a property of the gateway beneath the bundle, not a policy in it. That record is what supports the accountability and records duties for the agent-mediated slice of traffic: GDPR Art. 5(2)/24 (demonstrability), Art. 30 (records of processing activities), Arts. 33/34 (breach forensics), and the "reasonable security" and audit expectations under CCPA §1798.100(e) and 11 CCR §§7120–7124.
Clamp bulk reads, exports, and search fan-out, and hold agents to read-only or allowlisted queries, so a single call can't harvest a table, a mailbox, or a roster. Personal data must be adequate, relevant, and limited to what is necessary — enforced per call.
| Policy | App | Direction | Purpose |
|---|---|---|---|
| cap-bulk-export | gmail | ingress | Cap batch content reads and clamp search maxResults to throttle mass mailbox harvesting. |
| cap-bulk-export | google-drive | ingress | Clamp Drive search/listing page sizes to a ceiling (transform-only, never denies). |
| cap-bulk-export | salesforce | ingress | Cap SOQL row limits and gate org-wide SOSL search by IdP group. |
| query-allowlist | salesforce | ingress | Restrict the SOQL FROM object to an allowlist (Account/Contact/Opportunity). |
| read-only | salesforce | ingress | Allowlist-based read-only posture; all write tools fail closed. |
| cap-bulk-export | hubspot | ingress | Clamp bulk-read page sizes and batch-read arrays to 50 records. |
| read-only | hubspot | ingress | Deny the write tool to enforce a read-only HubSpot posture. |
| cap-read-field-exposure | jira | ingress | Strip over-broad field tokens and clamp search maxResults to 50. |
| cap-directory-and-document-egress | docusign | egress | Truncate account-wide user-directory listings for non-admins and gate signed-document downloads. |
| cap-bulk-export | netsuite | ingress | Clamp SuiteQL pageSize to bound per-call ERP bulk export. |
| cap-search-export | glean | ingress | Clamp bulk-export params (result ceiling, strip exhaustive) on Glean search. |
| cap-contact-enumeration | intercom | ingress | Deny bulk-enumeration query shapes on contact search and clamp page size. |
| cap-bulk-export | quickbooks | ingress | Clamp fetchAll/limit on QBO search tools to prevent whole-ledger/roster export. |
| cap-roster-export | gusto | ingress | Clamp per and strip include=custom_fields on employee/contractor listings for non-admins. |
| cap-bulk-record-reads | airtable | ingress | Cap maxRecords to 50 and strip raw filterByFormula for non-analysts. |
| guard-warehouse-sql-dax | power-bi | ingress | Deny bare full-table EVALUATE DAX (whole-table dumps) to prevent wholesale read-back. |
Egress redaction strips personal data, special-category and sensitive-PI patterns (SSNs, financial-account and card numbers, national IDs), and live credentials from responses before an agent carries them into its context or a downstream app. Transform-only where marked — they clean, they don't deny. Reducing what reaches the model directly shrinks the "nonredacted PI exposed" surface that CCPA §1798.150 attaches statutory damages to.
| Policy | App | Direction | Purpose |
|---|---|---|---|
| redact-pii-egress | ms365 | egress | Redact SSN, Luhn-validated PAN, IBAN, and US phone numbers from mail/Excel/SharePoint/transcript/Teams responses. |
| mask-pan-egress | gmail | egress | Mask payment-card numbers in Gmail mailbox-read responses (full-PAN group exempt). |
| redact-pii-egress | google-drive | egress | Redact email/SSN/national-ID/phone from Drive content responses. |
| redact-attendee-pii | google-calendar | egress | Redact attendee PII/PHI and meeting join links from calendar reads. |
| mask-pan-egress | slack | egress | Luhn-validated PAN masking to BIN+last4 in Slack read/search responses. |
| redact-profile-pii | slack | egress | Redact email/phone/custom-field PII from Slack user-lookup responses. |
| redact-sensitive-info | slack | ingress | Redact PII/secrets/card numbers from outbound Slack message args. |
| redact-pii | salesforce | egress | Redact contact PII fields and PAN/SSN/phone/email patterns in responses. |
| redact-pii-egress | box | egress | Redact SSN/PAN/bank/email/phone PII from Box content responses (group-exempt). |
| redact-pii | hubspot | egress | Redact contact PII (phone/email/SSN) in tool responses. |
| redact-sensitive-info | jira | egress | Redact PII/secrets/PAN from Jira issue-view responses. |
| redact-pii-egress | confluence | egress | Redact SSN/email/US-phone PII from Confluence page/comment/search reads (group-exempt). |
| redact-tab-values-egress | docusign | egress | Redact SSN and bank routing/account numbers and mask card PANs in envelope reads (hr/finance exempt). |
| mask-pan-egress | zapier | egress | Luhn-validated PAN masking to BIN+last4 in Zapier read responses. |
| redact-pii-egress | notion | egress | Redact email/phone PII from Notion reads for non-HR/legal callers. |
| redact-pii-egress-customer | stripe | egress | Mask customer email/phone/address/last4 in bulk Stripe read responses (finance exempt). |
| redact-pii-egress | snowflake | egress | Mask SSN/email/phone in result sets (pii-cleared group exempt). |
| redact-financial-pii | netsuite | egress | Redact SSN/TIN/IBAN and labelled bank-account numbers in NetSuite read responses. |
| redact-task-pii | asana | egress | Redact SSN/email/phone/IBAN in task/comment/status reads (privacy-officer exempt). |
| redact-board-pii-egress | monday | egress | Redact SSN/email/phone/national-ID on board/doc/update reads; non-admin deny of the directory tool. |
| redact-pii-egress | glean | egress | Redact SSN/PAN/IBAN from Glean read responses before they reach agent context. |
| mask-pan-egress | intercom | egress | Luhn-validated PAN masking to BIN+last4 in conversation responses. |
| redact-conversation-pii | intercom | egress | Redact SSN/national-ID/email/phone/credential shapes from conversation and contact reads. |
| redact-pii-egress-employee | quickbooks | egress | Mask SSN/address/pay/tax-ID/bank fields in QBO employee/vendor reads for non-HR/finance callers. |
| redact-content-egress | dropbox | egress | Mask card PANs and redact SSN/email/phone/secrets in file-content responses (pci carve-out). |
| redact-financial-ids-egress | gusto | egress | Mask US SSN and label-anchored bank-account/ABA-routing numbers in every Gusto response. |
| redact-pii-egress | airtable | egress | Redact SSN/email/phone/national-ID in record-read responses (data-privileged group exempt). |
| mask-pan-egress | databricks | egress | Luhn-validated PAN masking to BIN+last4 in SQL/Genie/AI-Search responses. |
| redact-pii-egress | databricks | egress | Redact SSN/email/phone in Databricks response payloads outside the data-privacy group. |
| redact-pii-egress | bigquery | egress | Redact SSN/Luhn-validated PAN/email in query results and optionally cap result rows (group exempt). |
| redact-pii-meeting-intelligence | zoom | egress | Redact email/phone/SSN in Zoom meeting-intelligence responses (transcripts, summaries, docs). |
| redact-pii-query-results | tableau | egress | Redact email/phone/SSN and mask card PANs in data-returning tool responses. |
| redact-pii-dax-results | power-bi | egress | Redact email/SSN/PAN in DAX/query/report-metadata results (fail-closed data-steward exemption). |
| redact-customer-pii-egress | linear | egress | Redact customer revenue, tier/segment, and contact email in Customers read responses. |
Role-based limits on where an agent can look. HR, payroll, legal, security, and other regulated scopes — folders, tables, schemas, boards, projects, spaces, datasets, channels, directories — are fenced to their owning IdP groups across reads, writes, and search. This keeps special-category data (Art. 9) and sensitive PI (§1798.121) away from agents whose purpose doesn't cover it.
| Policy | App | Direction | Purpose |
|---|---|---|---|
| fence-restricted-folders | google-drive | ingress | Deny reads/writes/copies touching an admin denylist of restricted Drive IDs (HR, M&A, board, payroll). |
| deny-read-search-summarize-sensitive-channels | slack | ingress | Deny read/search/summarize of a configured set of sensitive channels. |
| guard-dm-privacy | slack | ingress | Deny agent read reach into DMs and private conversations (group-exempt). |
| fence-sensitive-tables | servicenow | ingress | Fence sys_user / HR / CMDB tables and user-directory reads behind owner IdP groups. |
| fence-sensitive-folders | box | ingress | Fence pinned sensitive Box folder/file IDs by IdP group (read/move/copy/search). |
| deny-view-search-sensitive-projects | jira | ingress | Fence configured sensitive projects out of direct views and JQL search. |
| deny-write-sensitive-projects | jira | ingress | Block writes against configured sensitive projects. |
| fence-restricted-spaces | confluence | ingress | Fence restricted spaces (HR/LEGAL/SEC) out of search, listing, and lookup unless the group grants access. |
| fence-user-directory | notion | ingress | Fence the member-directory tool (names/emails/IDs) to admin/IT IdP groups. |
| fence-sensitive-schemas | snowflake | ingress | Group-gate PII/PHI/HR/FINANCE schema references and block SELECT * on fenced schemas. |
| fence-hr-payroll-suiteql | netsuite | ingress | Deny HR/payroll SuiteQL and saved-search reads outside the hr IdP group. |
| fence-sensitive-projects | asana | ingress | Fence writes to sensitive project GIDs (HR/legal/M&A/incident) to mapped IdP groups. |
| fence-sensitive-boards | monday | ingress | Fence sensitive board/workspace IDs (HR, CRM, security) across reads, writes, and search. |
| fence-datasource-scope | glean | ingress | Restrict which indexed datasource a Glean search may target by IdP group. |
| fence-contact-reads | intercom | ingress | Role-gate the structured-PII contact/company read surface to support/CRM groups. |
| fence-sensitive-paths | dropbox | ingress | Fence protected path prefixes (HR/Finance/Legal/Customers) to mapped IdP team groups. |
| fence-comp-payroll-reads | gusto | ingress | Deny compensation, pay-register, contractor-payment, and employment-action reads outside hr-payroll-admins. |
| fence-base-allowlist | airtable | ingress | Confine base-scoped record/schema tools to an operator allowlist of sanctioned base IDs. |
| fence-sensitive-schemas | databricks | ingress | Deny SQL/metadata access to sensitive namespaces (hr/payroll/pii/phi/comp) outside the data-privacy group. |
| fence-sensitive-datasets | bigquery | ingress | Fence regulated dataset prefixes (phi_/finance_/pii_) by IdP group across SQL and metadata. |
| fence-agentic-search | zoom | ingress | Fence agentic search to Zoom-native corpora, stripping external Salesforce/Workday/ServiceNow entities. |
| guard-transcripts-by-group | zoom | ingress | Gate Zoom transcript/summary and recording-passcode retrieval by IdP group. |
| fence-datasource-scope | tableau | ingress | Per-datasource LUID allowlist on query and analyst-only gate on image-render tools. |
The default posture processes nothing an agent isn't explicitly cleared for. Per-app role gates open writes only to the matching IdP group; field-protection keeps regulated attributes (ownership, consent flags, PII) from silent agent edits. This is Art. 25(2) made concrete for the agent channel, and the technical confinement of an agent to the controller's standing instructions (Art. 29 / Art. 32(4)). By keeping the consequential write behind a human in the matching group, these gates also keep agent workflows from "solely automated" significant decisions (Art. 22; 11 CCR §7200 et seq. — ADMT).
| Policy | App | Direction | Purpose |
|---|---|---|---|
| role-gate-writes | ms365 | ingress | Reads pass for everyone; writes require the m365-writers IdP group. |
| role-gate-writes | gmail | ingress | Read-only by default; write/send/label/filter/delete tools require the writer group (fail-closed). |
| role-gate-writes | google-drive | ingress | Gate Drive write-class tools to the drive-writers IdP group; reads pass. |
| role-gate-writes | slack | ingress | Gate Slack write-class tools behind an IdP writers group. |
| role-gate-writes | salesforce | ingress | Reads for all; create/update gated to approved groups; unknown tools fail closed. |
| protect-contact-fields | salesforce | ingress | Block Contact updates that modify protected fields (ownership, PII, consent flags). |
| role-gate-writes | servicenow | ingress | Reads open; verified writes require the servicenow-writers group; unknown tools fail closed. |
| role-gate-writes | box | ingress | Read-only by default; gate all Box write/mutating tools behind a writer IdP group. |
| role-gate-writes | hubspot | ingress | Gate all HubSpot write tools behind the crm-writers IdP group. |
| role-gate-writes | jira | ingress | Gate all Jira write tools to the writer IdP group; reads open to everyone. |
| role-gate-writes | zapier | ingress | Read-only by default; deny all writes across the aggregator unless caller is in automation-writers. |
| role-gate-writes-billing | stripe | ingress | Read-only by default; gate named billing write/destructive tools to finance/billing-admin groups. |
| role-gate-writes | dropbox | ingress | Deny create/upload/copy/move/restore tools unless caller is in the dropbox-writers group. |
The disclosure line, enforced on the agent channel: deny sends and invites to external recipients, downgrade or deny anonymous share links, block warehouse export/unload, and stop org-wide or public publication of personal data. Blocking agent-initiated cross-app and external-domain flows is where the gateway touches Arts. 44/46 on the MCP path.
| Policy | App | Direction | Purpose |
|---|---|---|---|
| guard-external-send | ms365 | ingress | Deny agent email sends when any recipient is outside the corporate-domain allowlist. |
| guard-share-links | ms365 | ingress | Downgrade anonymous share links to org scope, inject expiry, deny anonymous-edit and external invites. |
| guard-external-send | gmail | ingress | Deny sends when any to/cc/bcc recipient is outside the corporate-domain allowlist; draft instead. |
| guard-external-attendees | google-calendar | ingress | Block calendar invites to attendees outside the corporate-domain allowlist. |
| guard-public-exposure | google-calendar | ingress | Block public visibility and guest-delegation flags on event create/update. |
| guard-external-send | slack | ingress | Deny agent posts to externally shared Slack Connect channels. |
| guard-share-links-external | box | ingress | Block external collaborations to non-corp domains and anonymous public share links. |
| guard-external-recipients | docusign | ingress | Deny envelope creation/recipient updates when any recipient domain is outside the counterparty allowlist. |
| guard-external-send | zapier | ingress | Deny writes naming a recipient outside corporate domains, including addresses hidden in free text. |
| guard-warehouse-export | snowflake | ingress | Deny COPY INTO external stage/URL, CREATE STAGE, share creation, and PUT/GET off-perimeter export. |
| guard-warehouse-export | bigquery | ingress | Block EXPORT DATA/MODEL, EXTERNAL_QUERY, cross-project writes, and out-of-allowlist project_id. |
| guard-share-links-external | dropbox | ingress | Deny public share links, download URLs, and file requests unless caller is in the dropbox-sharing group. |
| guard-external-chat-invites | zoom | ingress | Block external contact invites and external history exposure in Zoom Team Chat channels. |
| deny-public-publication | confluence | ingress | Deny org-wide and anonymous-public Confluence page/blog publication; scoped writes pass. |
Bundle membership is declared in each policy's policy.md frontmatter (the policy lists bundles: ["gdpr-ccpa"]). This page is a human-readable landing page; the generated manifest.json is the machine-readable source of truth. There is intentionally no separate bundle.json artifact — one source of metadata avoids drift.
The policies compose by direction. The egress redaction policies (theme 2, plus the docusign egress cap) attach to the response pipeline and are transform-only where marked, so they never deny and never collide with the ingress controls. The ingress policies are each single-purpose — a cap, a role gate, a fence, a disclosure guard — so several attach to the same app on the same direction without interfering. Pick a read-only posture or the narrow write controls for an app, not both; combining them is redundant but harmless.
These policies act only on agent traffic over MCP, and only some GDPR/CCPA requirements reduce to a gateway decision. Out of scope by design:
Compliance note. This bundle supports alignment with the cited framework controls on the MCP path only. No policy or bundle makes an organization compliant with any framework; web-UI, native-API, and in-app access are outside the gateway's reach by design. Validate against your own compliance program before relying on it.