Block Agent Email to External Recipients
Blocks agent-initiated Microsoft 365 email sends when any recipient address falls outside a corporate-domain allowlist.
Blocks agent-initiated Microsoft 365 email sends when any recipient address falls outside a corporate-domain allowlist.
Every Zapier MCP tool — in both the agentic and classic modes — accepts a free-text instructions string that Zapier's server-side AI uses to fill any…
Unconditionally denies the classic business-email-compromise (BEC) persistence surface in Microsoft 365: creating or updating Outlook mail rules, changing…
ms365guard-mailbox-persistenceingressbecemailfinserv-commssoc2
Denies Gmail send-class tool calls when any recipient in to, cc, or bcc falls outside a documented corporate-domain allowlist.
This policy stops a request if it contains an email address. If there's no email address, the request goes through as normal.
Masks payment-card-number (PAN) shapes in email content returned to agents by Gmail mailbox-read tools.
gmailmask-pan-egressegressemailcardholder-datadlpsoc2pci-dssgdpr-ccpa
This policy automatically masks email addresses in what a tool sends back, replacing each one with [REDACTED] before your agent ever sees it.