dtwo Policy Store

Policies tagged "airtable"

airtable · egress

Airtable: Redact PII in Record Reads

Scans the responses of the Airtable record-read tools — the calls that return row fields values — and rewrites high-confidence PII shapes to a fixed…

airtableredact-piipiidlpredactionegresssoc2gdpr-ccpa

airtable · ingress

Clamp Bulk Airtable Record Reads

Airtable bases routinely hold CRM contacts, applicant-tracking pipelines, customer/financial trackers, and — on HIPAA-eligible Enterprise plans — health-ops…

airtablecap-bulk-exportingresssoc2gdpr-ccpa

airtable · ingress

Confine Airtable Agent to Allowlisted Bases

An Airtable OAuth grant (or Personal Access Token) with the workspacesAndBases:read scope spans the entire workspace — every base the connected identity can…

airtablefence-sensitive-scopesingresssoc2gdpr-ccpa

airtable · ingress

Default-Deny Unaudited Airtable Tools

Maintains a per-tenant allowlist of audited Airtable tool-name suffixes and denies any call whose tool name does not end with an allowlisted entry.

airtabledefault-deny-unknown-toolsallowlistingresssoc2

airtable · ingress

Freeze Destructive Airtable Deletes

Denies every destructive Airtable tool call unless the caller's IdP token carries the placeholder group airtable-admins.

airtablefreeze-destructive-opsrecord-integrityingresssoc2