BigQuery: Redact PII in Query Results
Scans the content returned by BigQuery's result-returning tools and rewrites high-confidence PII shapes to fixed, non-recoverable redaction tokens before the…
Scans the content returned by BigQuery's result-returning tools and rewrites high-confidence PII shapes to fixed, non-recoverable redaction tokens before the…
Blocks agent-initiated Microsoft 365 email sends when any recipient address falls outside a corporate-domain allowlist.
Denies Google Calendar event-write tool calls — create event / create-event, update event / update-event, and the consolidated manage event — whenever any…
google-calendarguard-external-sendingresscalendarsoc2hipaagdpr-ccpa
Stops a Zoom Team Chat agent from pulling external parties into the organization's chat surface.
Denies, by default, the Dropbox tools that turn an internal file into an internet-visible resource in a single call — before the request ever reaches Dropbox:
dropboxguard-share-linkssharingexternal-sharingingresssoc2hipaagdpr-ccpa
Clamps the bulk-export parameters on Glean search calls before they reach the Glean MCP server, so a single agent request cannot pull an entire indexed…
gleancap-bulk-exportdata-minimisationingresssoc2hipaagdpr-ccpa
Clamps the page size of Google Drive search and listing calls to a documented cap (25 results per call).
google-drivecap-bulk-exportdata-minimizationingresssoc2hipaagdpr-ccpa
caller is a CRM admin); clamp page size on everything else; allow the rest
intercomcap-bulk-exportcontact-enumerationdlpingresssoc2hipaapci-dssgdpr-ccpa
Scans the responses of Confluence page, comment, and search read tools and rewrites personally identifiable information to fixed redaction tokens before the…
confluenceatlassianredact-piipiidlpredactionegresssoc2hipaagdpr-ccpa
Scans the response payloads of the Databricks MCP tools that carry lakehouse data back to the agent and rewrites personally identifiable information to fixed…
Denies Gmail send-class tool calls when any recipient in to, cc, or bcc falls outside a documented corporate-domain allowlist.
Scans the responses of the Dropbox file-content read tools and sanitises the returned text before it reaches the agent.
dropboxredact-contentredact-piimask-pansecretspiidlpegresssoc2hipaagdpr-ccpa
Fences a configurable set of restricted Confluence spaces (placeholder keys: HR, LEGAL, SEC) out of the agent's read and search paths unless the caller's IdP…
confluenceatlassianfence-sensitive-scopesaccess-controlingresssoc2hipaagdpr-ccpa
Glean's search tool fans out across every system the tenant has indexed (Drive, Confluence, Slack, Jira, Gmail/Outlook, GitHub, Salesforce, Gong, HR…
gleanfence-sensitive-scopesaccess-controldatasourceingresssoc2hipaagdpr-ccpa
Gates Intercom's structured-PII read surface — customer contact and company profiles — by IdP group.
intercomfence-sensitive-scopescontact-readspiiingresssoc2hipaapci-dssgdpr-ccpa
Fences customer-designated regulated BigQuery data domains by data-domain IdP group, at ingress, before any statement or metadata lookup reaches BigQuery.
bigqueryfence-sensitive-scopesingressrbacsoc2hipaapci-dssgdpr-ccpa
Fences an admin-maintained denylist of restricted Google Drive file and folder IDs — HR records, M&A deal rooms, board packs, payroll — off the agent channel:
google-drivefence-restricted-folderssensitive-scopesingresssoc2hipaagdpr-ccpa
Fences pinned sensitive Box subtrees (HR, Finance, Legal, …) by ID.
Fences off the most sensitive lakehouse namespaces from agents on the read side of Databricks.
databricksfence-sensitive-scopesingresssoc2hipaapci-dssgdpr-ccpa
Fences protected Dropbox subtrees by path prefix . Dropbox addresses files and folders by a root-relative path (/Finance/2026/payroll.
Fences off the most sensitive ServiceNow tables from two routes that reach them:
servicenowfence-sensitive-tablespiiingresssoc2hipaapci-dssgdpr-ccpa
Fences customer-designated sensitive data domains inside a Snowflake warehouse by inspecting the SQL text the agent is about to run — not by tool name, which…
snowflakefence-sensitive-scopesingresssoc2hipaapci-dssgdpr-ccpa
Gates retrieval of Zoom meeting transcripts, AI Companion summaries, and next-steps on the connector's core egress tools, enforcing minimum-necessary access:
Scans the responses of Glean's content-returning read tools and rewrites high-confidence PII to fixed redaction tokens before the response reaches the…
Throttles mass-harvesting of a mailbox by capping the per-call blast radius of the two Gmail MCP surfaces that return many full email bodies at once:
gmailcap-bulk-exportdata-minimisationingresssoc2hipaagdpr-ccpa
Scans the responses of the content-returning Google Drive tools — file reads, downloads, and Docs/Sheets/Slides content fetches — and rewrites personally…
google-driveredact-piipiidlpredactionegresssoc2hipaagdpr-ccpa
Blocks the externally-visible Box sharing surface — the riskiest Box surface an agent can touch — before the call ever reaches Box:
boxguard-share-linkssharingexternal-sharingingresssoc2hipaagdpr-ccpa
Stops agents from opening OneDrive/SharePoint files to the whole internet. It guards the two Microsoft 365 sharing tools:
ms365share-linkssharingingresssoc2iso27001-nisthipaagdpr-ccpa
Clamps the page size of HubSpot bulk-read tool calls before they reach the HubSpot MCP server, so a single agent request to a covered bulk-read tool can…
hubspotcap-bulk-exportpiidata-minimisationingresssoc2hipaapci-dssgdpr-ccpa
Scans the free-text returned by Intercom's conversation- and contact-read MCP tools and rewrites high-confidence personal identifiers and credential shapes…
Scans the responses of the highest-density PII read surfaces in Microsoft 365 — mail bodies, Excel ranges, SharePoint list items, meeting transcripts, and…
Scans the responses of the Notion hosted MCP server's content-returning read tools and rewrites personally identifiable information to fixed redaction tokens…
Scrubs sensitive fields from the responses of Google Calendar read tools before they reach the agent, for callers who lack the placeholder calendar-full-read…
google-calendarredact-piipiiphidlpredactionegresssoc2hipaagdpr-ccpa
Blocks bulk PII extraction through Salesforce query tools by inspecting the free-text query arguments that are the real policy surface for these servers.
salesforcecap-bulk-exportdata-minimizationdlpingresssoc2hipaapci-dssgdpr-ccpa
Redacts personal contact information from Salesforce tool responses before they reach the caller.
salesforcepiidlpredactionegresssoc2hipaagdpr-ccpaiso27001-nist
Denies Slack message-write calls whose destination is an externally shared Slack Connect channel.
slackguard-external-sendslack-connectexfiltrationingresssoc2gdpr-ccpahipaa
Blocks read, search, and summarize operations that target a configurable set of "sensitive" Slack channels.
slackaccess-controldata-protectioningresssoc2hipaagdpr-ccpaiso27001-nist
Scans the row content returned by the result-returning Snowflake MCP tools and rewrites personally identifiable information to fixed redaction tokens before…
Scans the responses of Zoom's meeting-intelligence read surfaces — AI summaries, verbatim transcripts, recording resources, and Zoom Docs content — and…
HIPAA governs how covered entities and their business associates use, disclose, and safeguard protected health information (PHI/ePHI) — the Privacy Rule (45 CFR Part 164, Subpart E) with its minimum-necessary standard, and the Security Rule (Subpart C) with its administrative and technical safeguards. This bundle is a starting posture for any organization that lets an AI agent reach PHI-bearing SaaS apps over the DTwo gateway. An agent that pulls broad context to answer a single question is in direct tension with minimum necessary, which applies per use and per disclosure — so the gateway is the natural place to scope each tool call, gate it by identity, and strip PHI on the way back out.
These policies support alignment with HIPAA (Privacy & Security Rules) on the MCP path only. They act on agent traffic that flows through the gateway; web-UI logins, native-API integrations, and in-app activity are outside their reach by design, and no policy or bundle makes an organization HIPAA compliant. Compliance is a property of your whole program.
42 policies across 18 apps, grouped below by the HIPAA control they support. Every policy is single-purpose and composes with the others on the same pipeline direction. Policy bodies live under apps/; this page only links to them — see the top-level README for the rationale.
The per-decision audit log that records every one of these calls — principal, action, resource, context, decision — is a property of the gateway beneath the bundle, not a policy in it. That record is what supports §164.312(b) audit controls, §164.308(a)(1)(ii)(D) activity review, and the §164.528 accounting of disclosures for the agent-mediated slice of traffic.
Clamp bulk reads, exports, and search fan-out so a single agent call can't harvest a mailbox, a table, or a directory. These caps hold agents to the narrowest surface that answers the question.
| Policy | App | Direction | Purpose |
|---|---|---|---|
| cap-bulk-export | gmail | ingress | Cap batch content reads and clamp search maxResults to throttle mass mailbox harvesting. |
| cap-bulk-export | google-drive | ingress | Clamp Drive search/listing page sizes to a ceiling (transform-only, never denies). |
| cap-bulk-export | salesforce | ingress | Cap SOQL row limits and gate org-wide SOSL search by IdP group. |
| cap-bulk-export | hubspot | ingress | Clamp bulk-read page sizes and batch-read arrays to 50 records. |
| cap-search-export | glean | ingress | Clamp bulk-export params (result ceiling, strip exhaustive) on Glean search. |
| cap-contact-enumeration | intercom | ingress | Deny bulk-enumeration query shapes on contact search and clamp page size. |
Egress redaction strips Safe-Harbor-class identifiers — names, contact info, SSNs, card and bank numbers — from responses before an agent carries them into its context or a downstream app. Transform-only where marked: they never deny, they clean.
| Policy | App | Direction | Purpose |
|---|---|---|---|
| redact-pii-egress | ms365 | egress | Redact SSN, Luhn-validated PAN, IBAN, and US phone numbers from mail/Excel/SharePoint/transcript/Teams responses. |
| redact-pii-egress | google-drive | egress | Redact email/SSN/national-ID/phone from Drive content responses. |
| redact-attendee-pii | google-calendar | egress | Redact attendee PII/PHI and meeting join links from calendar reads. |
| redact-pii | salesforce | egress | Redact contact PII fields and PAN/SSN/phone/email patterns in responses. |
| redact-pii | hubspot | egress | Redact contact PII (phone/email/SSN) in tool responses. |
| redact-pii-egress | box | egress | Redact SSN/PAN/bank/email/phone PII from Box content responses (group-exempt). |
| redact-pii-egress | confluence | egress | Redact SSN/email/US-phone PII from Confluence page/comment/search reads (group-exempt). |
| redact-pii-egress | notion | egress | Redact email/phone PII from Notion reads for non-HR/legal callers. |
| redact-pii-egress | snowflake | egress | Mask SSN/email/phone in result sets (pii-cleared group exempt). |
| redact-pii-egress | databricks | egress | Redact SSN/email/phone in response payloads outside the data-privacy group. |
| redact-pii-egress | bigquery | egress | Redact SSN/PAN/email in query results and optionally cap result rows (group exempt). |
| redact-pii-egress | glean | egress | Redact SSN/PAN/IBAN from Glean read responses before they reach agent context. |
| redact-conversation-pii | intercom | egress | Redact SSN/national-ID/email/phone/credential shapes from conversation and contact reads. |
| redact-content-egress | dropbox | egress | Mask card PANs and redact SSN/email/phone/secrets in file-content responses. |
| redact-pii-meeting-intelligence | zoom | egress | Redact email/phone/SSN in Zoom meeting-intelligence responses (transcripts, summaries, docs). |
| redact-sensitive-info | slack | ingress | Redact PII/secrets/card numbers from outbound Slack message args. |
Role-based limits on where an agent can look: HR, clinical, legal, and other regulated scopes are fenced to their owning IdP groups across reads, writes, and search. These are the agreed-to-restriction and least-privilege predicates that keep an agent out of a record class it has no business reaching.
| Policy | App | Direction | Purpose |
|---|---|---|---|
| fence-restricted-folders | google-drive | ingress | Deny reads/writes/copies touching an admin denylist of restricted Drive IDs (HR, M&A, board, payroll). |
| fence-sensitive-folders | box | ingress | Fence pinned sensitive Box folder/file IDs by IdP group (read/move/copy/search). |
| fence-sensitive-paths | dropbox | ingress | Fence protected path prefixes (HR/Finance/Legal/Customers) to mapped IdP team groups. |
| fence-restricted-spaces | confluence | ingress | Fence restricted spaces (HR/LEGAL/SEC) out of search, listing, and lookup unless the group grants access. |
| fence-sensitive-tables | servicenow | ingress | Fence sys_user / HR / CMDB tables and user-directory reads behind owner IdP groups. |
| fence-sensitive-schemas | snowflake | ingress | Group-gate PII/PHI/HR/FINANCE schema references and block SELECT * on fenced schemas. |
| fence-sensitive-schemas | databricks | ingress | Deny SQL/metadata access to sensitive namespaces (hr/payroll/pii/phi/comp) outside the data-privacy group. |
| fence-sensitive-datasets | bigquery | ingress | Fence regulated dataset prefixes (phi_/finance_/pii_) by IdP group across SQL and metadata. |
| fence-datasource-scope | glean | ingress | Restrict which indexed datasource a Glean search may target by IdP group. |
| fence-contact-reads | intercom | ingress | Role-gate the structured-PII contact/company read surface to support/CRM groups. |
| guard-transcripts-by-group | zoom | ingress | Gate Zoom transcript/summary and recording-passcode retrieval by IdP group. |
| deny-read-search-summarize-sensitive-channels | slack | ingress | Deny read/search/summarize of a configured set of sensitive channels. |
The Privacy Rule's disclosure line, enforced on the agent channel: deny external sends and downgrade anonymous share links so an agent can't route PHI past the corporate boundary — including to apps or recipients with no BAA behind them.
| Policy | App | Direction | Purpose |
|---|---|---|---|
| guard-external-send | ms365 | ingress | Deny agent email sends when any recipient is outside the corporate-domain allowlist. |
| guard-share-links | ms365 | ingress | Downgrade anonymous share links to org scope, inject expiry, deny anonymous-edit and external invites. |
| guard-external-send | gmail | ingress | Deny sends when any to/cc/bcc recipient is outside the corporate-domain allowlist; draft instead. |
| guard-external-send | slack | ingress | Deny agent posts to externally shared Slack Connect channels. |
| guard-external-attendees | google-calendar | ingress | Block calendar invites to attendees outside the corporate-domain allowlist. |
| guard-share-links-external | box | ingress | Block external collaborations to non-corp domains and anonymous public share links. |
| guard-share-links-external | dropbox | ingress | Deny public share links, download URLs, and file requests unless caller is in the dropbox-sharing group. |
| guard-external-chat-invites | zoom | ingress | Block external contact invites and external history exposure in Zoom Team Chat channels. |
Bundle membership is declared in each policy's policy.md frontmatter (the policy lists bundles: ["hipaa"]). This page is a human-readable landing page; the generated manifest.json is the machine-readable source of truth. There is intentionally no separate bundle.json artifact — one source of metadata avoids drift.
The policies compose by direction. The egress redaction policies (theme 2) attach to the response pipeline and are transform-only where marked, so they never deny and never collide with the ingress controls. The ingress policies are each single-purpose — a cap, a fence, a disclosure guard — so several attach to the same app on the same direction without interfering. Each policy is scoped to its own app, so cross-app members never collide.
These policies act only on agent traffic over MCP, and only some HIPAA requirements reduce to a gateway decision. Out of scope by design:
Compliance note. This bundle supports alignment with the cited framework controls on the MCP path only. No policy or bundle makes an organization compliant with any framework; web-UI, native-API, and in-app access are outside the gateway's reach by design. Validate against your own compliance program before relying on it.