dtwo Policy Store

Policies tagged "fence-sensitive-scopes"

airtable · ingress

Confine Airtable Agent to Allowlisted Bases

An Airtable OAuth grant (or Personal Access Token) with the workspacesAndBases:read scope spans the entire workspace — every base the connected identity can…

airtablefence-sensitive-scopesingresssoc2gdpr-ccpa

confluence · ingress

Fence Confluence Reads & Search to Non-Restricted Spaces

Fences a configurable set of restricted Confluence spaces (placeholder keys: HR, LEGAL, SEC) out of the agent's read and search paths unless the caller's IdP…

confluenceatlassianfence-sensitive-scopesaccess-controlingresssoc2hipaagdpr-ccpa

github · ingress

Fence GitHub Access to the Company Org Allowlist

Denies any GitHub tool call whose arguments.owner (read from input.payload.args.

githubfence-sensitive-scopesorg-allowlistanti-exfilingresssoc2

glean · ingress

Fence Glean Search by Datasource

Glean's search tool fans out across every system the tenant has indexed (Drive, Confluence, Slack, Jira, Gmail/Outlook, GitHub, Salesforce, Gong, HR…

gleanfence-sensitive-scopesaccess-controldatasourceingresssoc2hipaagdpr-ccpa

intercom · ingress

Fence Intercom Contact & Company PII Reads

Gates Intercom's structured-PII read surface — customer contact and company profiles — by IdP group.

intercomfence-sensitive-scopescontact-readspiiingresssoc2hipaapci-dssgdpr-ccpa

netsuite · ingress

Fence NetSuite HR & Payroll SuiteQL Queries

Fences the single biggest exfiltration surface on the NetSuite MCP server — ns runCustomSuiteQL, which runs arbitrary read-only SuiteQL across the entire ERP.

netsuitefence-sensitive-scopesingressgdpr-ccpasoc2

notion · ingress

Fence Notion Member Directory to Admin & IT

Denies calls to the Notion member-directory tool (notion-get-users, matched by the -get-users suffix) unless the caller's IdP groups include an admin or IT…

notionfence-sensitive-scopesaccess-controlpiiingresssoc2gdpr-ccpa

bigquery · ingress

Fence Regulated BigQuery Datasets by Group

Fences customer-designated regulated BigQuery data domains by data-domain IdP group, at ingress, before any statement or metadata lookup reaches BigQuery.

bigqueryfence-sensitive-scopesingressrbacsoc2hipaapci-dssgdpr-ccpa

linear · egress

Fence Roadmap and Initiative Reads (Egress)

Fences the responses of Linear's roadmap, initiative, and strategy read tools.

linearfence-sensitive-scopesroadmapegresssoc2

box · ingress

Fence Sensitive Box Folders by IdP Group

Fences pinned sensitive Box subtrees (HR, Finance, Legal, …) by ID.

boxfence-sensitive-scopesingresssoc2hipaagdpr-ccpa

databricks · ingress

Fence Sensitive Databricks Schemas

Fences off the most sensitive lakehouse namespaces from agents on the read side of Databricks.

databricksfence-sensitive-scopesingresssoc2hipaapci-dssgdpr-ccpa

dropbox · ingress

Fence Sensitive Dropbox Paths by Team

Fences protected Dropbox subtrees by path prefix . Dropbox addresses files and folders by a root-relative path (/Finance/2026/payroll.

dropboxfence-sensitive-scopesingresssoc2hipaagdpr-ccpa

monday · ingress

Fence Sensitive monday Boards by IdP Group

monday boards are schemaless business databases: HR/recruiting boards (candidate PII), CRM/deal boards (financial), and IT/security trackers routinely live…

mondayfence-sensitive-scopesingresssoc2gdpr-ccpa

snowflake · ingress

Fence Snowflake Sensitive Schemas by Data Domain

Fences customer-designated sensitive data domains inside a Snowflake warehouse by inspecting the SQL text the agent is about to run — not by tool name, which…

snowflakefence-sensitive-scopesingresssoc2hipaapci-dssgdpr-ccpa

tableau · ingress

Fence Tableau Datasource Scope

Tableau's MCP server is a warehouse proxy: query-datasource runs a VizQL Data Service (VDS) query and returns raw row-level data — PII, PHI, payroll,…

tableaufence-sensitive-scopesaccess-controldatasourceingresssoc2gdpr-ccpa

asana · ingress

Fence Writes to Sensitive Asana Projects

Asana is routinely used for HR (hiring, performance, offboarding), legal, M&A, and incident work; those project bodies, comments, custom fields, and status…

asanafence-sensitive-scopesingresssoc2gdpr-ccpa