Solutions

One endpoint, one policy, every account.

The guard decides what an agent may run on this Mac. The policy engine decides what it may reach in your accounts — you link each account once, then say per agent what it can see and what it may do there.

The profile is the identity

An agent cannot prove which app it is, so each gets its own endpoint and key. If one key leaks, revoking that profile affects nothing else.

Hide, don't refuse

If a profile has no access to an account, that account's tools are never listed. An agent cannot ask for what it cannot see — safer and cheaper than refusing the call.

Everything is denied by default

A grant names the account, the service, a level, and a scope. Anything the policy does not match is denied, and the denial is logged with the step that failed.

Five levels, and the actions that need your OK

LevelFilesCalendarMailPages and channels
readsearch, readlist, readsearch, readread, search
draftcreate newcreate tentativecreate a draftcreate a page, post in scope
writeeditcreate and editsendedit, reply, direct message
destructivetrash, share externallydelete, invite externaldelete, forward externallyarchive, change sharing

A grant can be scoped to named folders, calendars, pages or channels; given an expiry date; and marked so that particular actions — deleting an event, inviting someone external, posting a message — ask you each time regardless of level. Profiles carry their own rate limit and a cap on how much content a single call can pull back.

Tool names carry the account

A tool is named for the account it acts on, so the model can see which one it is using and every audit line is unambiguous. Two accounts on the same service are two sets of tools, not one set with a parameter the model has to get right.

Everything coming back is marked untrusted

Mail and document text is the main route for prompt injection — a sentence written by somebody else, arriving as content, read as instruction. Responses are wrapped and marked before they reach the agent; the gateway never relays them as plain text.

What it lets the scan check

  • An agent holding a direct connector to a service that bypasses the gateway entirely.
  • A grant at write or above with no scope and no expiry.
  • A profile key that has not been rotated in ninety days.
  • The policy file changing with nobody at the keyboard — which is a drift event, not a finding.

Status

Built and in use: profiles and keys, catalogue filtering, the audit trail, the policy editor, and read paths for Google Calendar and Drive, Microsoft 365 through Graph — Outlook mail and calendar, OneDrive — Notion, Slack and Gmail.

Not yet: sending mail, and everything at the write and destructive levels. Those levels are expressible in the policy and have no action behind them, which is stated here rather than discovered.